Bug 82336

Summary: Race condition in fileutils package
Product: Red Hat Enterprise Linux 2.1 Reporter: Mark J. Cox <mjc>
Component: fileutilsAssignee: Tim Waugh <twaugh>
Status: CLOSED ERRATA QA Contact: Mike McLean <mikem>
Severity: medium Docs Contact:
Priority: medium    
Version: 2.1   
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2003-02-20 18:40:14 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Mark J. Cox 2003-01-21 13:58:50 UTC
A race condition in recursive use of 'rm' and 'mv' in fileutils 4.1 and
earlier could allow local users to delete files and directories as the user
running fileutils if the user has write access to part of the tree being
moved or deleted.

Red Hat Linux Advanced Server shipped with versions of fileutils that are
vulnerable to this issue.

CAN-2002-0435

http://online.securityfocus.com/archive/1/260936
http://mail.gnu.org/archive/html/bug-fileutils/2002-03/msg00028.html

Comment 1 Mark J. Cox 2003-02-20 18:40:14 UTC
An errata has been issued which should help the problem described in this bug report. 
This report is therefore being closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files, please follow the link below. You may reopen 
this bug report if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2003-016.html