CVE-2007-3919 Information

Description

(1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm.

Reference

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=447795 http://osvdb.org/41342 http://osvdb.org/41343 http://secunia.com/advisories/27389 http://secunia.com/advisories/27408 http://secunia.com/advisories/27486 http://secunia.com/advisories/27497 http://secunia.com/advisories/29963 http://www.debian.org/security/2007/dsa-1395 http://www.mandriva.com/security/advisories?name=MDKSA-2007:203 http://www.redhat.com/support/errata/RHSA-2008-0194.html http://www.securityfocus.com/bid/26190 http://www.securitytracker.com/id?1018859 http://www.vupen.com/english/advisories/2007/3621 https://exchange.xforce.ibmcloud.com/vulnerabilities/37403 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A9913 https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00004.html https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00075.html

Share on: