Red Hat Bugzilla – Bug 242907
CVE-2007-3103 init.d xfs script chown race condition vulnerability
Last modified: 2007-11-30 17:07:29 EST
From iDefense: Local exploitation of a race condition vulnerability in init.d XFS (X Font Server) script allows an attacker to elevate their privileges to root. The XFS script is vulnerable to a race condition when it is started by init, or by a system administrator. Specifically, it insecurely changes the file permissions of a temporary file. This allows an attacker to make any file on the system world writable. Successful exploitation of this vulnerability results in an attacker gaining root privileges on the affected system. However, in order to exploit this, it is necessary for either the system to be rebooted, or for the administrator to manually restart the XFS.
removing embargo
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2007-0519.html