CVE Vulnerabilities

CVE-2007-3919

Improper Link Resolution Before File Access ('Link Following')

Published: Oct 28, 2007 | Modified: Sep 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:L/AC:M/Au:S/C:N/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

(1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm.

Weakness

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Software

Name Vendor Start Version End Version
Debian_linux Debian 4.0 (including) 4.0 (including)
Red Hat Enterprise Linux 5 RedHat xen-0:3.0.3-41.el5_1.5 *
Xen Ubuntu dapper *
Xen-3.0 Ubuntu edgy *
Xen-3.0 Ubuntu feisty *
Xen-3.1 Ubuntu gutsy *
Xen-3.1 Ubuntu hardy *
Xen-3.1 Ubuntu intrepid *

Potential Mitigations

  • Follow the principle of least privilege when assigning access rights to entities in a software system.
  • Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.

References