LWN.net Logo

acl: symlink attack

Package(s):acl CVE #(s):CVE-2009-4411
Created:December 29, 2009 Updated:April 19, 2011
Description: From the Mandriva advisory: The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when running in recursive (-R) mode, follow symbolic links even when the --physical (aka -P) or -L option is specified, which might allow local users to modify the ACL for arbitrary files or directories via a symlink attack.
Alerts:
Slackware SSA:2011-108-01 2011-04-19
SuSE SUSE-SR:2010:002 2010-02-01
Mandriva MDVSA-2009:345 2009-12-28

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds