CVE-2007-3919: Medium severity Debian Debian Linux vulnerability
Published Oct 28, 2007
·Updated
(1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm.
Affected Software
14 affected components
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Xensource Inc Xen=3.0.3_0_1
Xensource Inc Xen=3.0.3_0_3
Event History
Oct 28, 2007
CVE Published
05:08 PM
Data Sourced
05:08 PM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3919?
CVE-2007-3919 is classified as a moderate severity vulnerability due to the potential for local users to perform a symlink attack.
2
How do I fix CVE-2007-3919?
To fix CVE-2007-3919, update to a version of Xen later than 3.1 that addresses the symlink vulnerability.
3
Who is affected by CVE-2007-3919?
CVE-2007-3919 affects local users on systems running Xen versions 3.1 and earlier.
4
What exploit mechanism does CVE-2007-3919 use?
CVE-2007-3919 uses a symlink attack on the /tmp/xenq-shm file to truncate arbitrary files.
5
Can CVE-2007-3919 be exploited remotely?
No, CVE-2007-3919 can only be exploited locally by users with access to the vulnerable system.