CVE-2007-2654: Race Condition
xfsfsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2654?
The severity of CVE-2007-2654 is considered high due to insecure permissions in the .fsr temporary directory allowing local users to read or overwrite files.
How do I fix CVE-2007-2654?
To fix CVE-2007-2654, you should update the affected SUSE Linux versions to a patched release that resolves the permission issue.
Which systems are impacted by CVE-2007-2654?
CVE-2007-2654 affects several versions of SUSE Linux including 8.0, 9.0, 9.1, 9.2, 9.3, and 10.x.
What are the risks associated with CVE-2007-2654?
The risks of CVE-2007-2654 include potential data breaches or alteration of sensitive files by local users due to improper directory permissions.
Is there a workaround for CVE-2007-2654?
A temporary workaround for CVE-2007-2654 includes restricting user access to the xfs_fsr command until the system is updated.