Bug 350421 (CVE-2007-3919) - CVE-2007-3919 xen xenmon.py / xenbaked insecure temporary file accesss
Summary: CVE-2007-3919 xen xenmon.py / xenbaked insecure temporary file accesss
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2007-3919
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 361981 361991 362001 362011 387161 387171
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-10-24 12:47 UTC by Tomas Hoger
Modified: 2021-11-12 19:42 UTC (History)
3 users (show)

Fixed In Version: 3.1.0-8.fc7
Clone Of:
Environment:
Last Closed: 2008-07-25 10:19:21 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2008:0397 0 normal SHIPPED_LIVE anaconda bug fix and enhancement update 2008-05-19 23:11:23 UTC
Red Hat Product Errata RHSA-2008:0194 0 normal SHIPPED_LIVE Important: xen security and bug fix update 2008-05-13 12:28:04 UTC

Description Tomas Hoger 2007-10-24 12:47:17 UTC
Steve Kemp reported following problem affecting xenmon tools shipped with xen:

The xenbaked daemon and xenmon utility communicate via a mmap'ed
shared file. Since this file is located in /tmp, unprivileged users
can cause arbitrary files to be truncated by creating a symlink from
the well-known /tmp filename to e.g., /etc/passwd.

The fix is to place the shared file in a directory to which only root
should have access (in this case /var/run/).

Fix has already been committed in upstream repository:
http://xenbits.xensource.com/xen-unstable.hg?rev/b28ae5f00553

Debian bug opened by Steve:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=447795

Comment 7 Tomas Hoger 2007-10-29 19:32:29 UTC
The Red Hat Security Response Team has rated this issue as having low security
impact.  It can only be exploited by attacker with access to Dom0.  Such access
should be restricted to trusted Xen host administrators.  Moreover, those tools
have very limited user base.

Comment 11 Fedora Update System 2007-11-01 21:13:22 UTC
xen-3.1.0-8.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 20 Red Hat Product Security 2008-07-25 10:19:21 UTC
This issue was addressed in:

Red Hat Enterprise Linux:
  http://rhn.redhat.com/errata/RHSA-2008-0194.html




Note You need to log in before you can comment on or make changes to this bug.