The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fedora_core | Fedoraproject | 6.0 (including) | 6.0 (including) |
Enterprise_linux | Redhat | 4.0 (including) | 4.0 (including) |
Enterprise_linux_desktop | Redhat | 4.0 (including) | 4.0 (including) |
Linux | Redhat | * | * |
Red Hat Enterprise Linux 4 | RedHat | xorg-x11-0:6.8.2-1.EL.19 | * |
Red Hat Enterprise Linux 5 | RedHat | xorg-x11-xfs-1:1.0.2-4 | * |
Xfs | Ubuntu | dapper | * |
Xfs | Ubuntu | devel | * |
Xfs | Ubuntu | edgy | * |
Xfs | Ubuntu | feisty | * |
Xfs | Ubuntu | gutsy | * |
Xfs | Ubuntu | hardy | * |
Xfs | Ubuntu | intrepid | * |
Xfs | Ubuntu | jaunty | * |
Xfs | Ubuntu | karmic | * |