retitle 499076 CVE-2009-4411: Physical walk no longer ignores all symlinks
tags 499076 security
severity 499076 serious
thanks

Hi,

this issue got a CVE id:

CVE-2009-4411[0]:
| The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when
| running in recursive (-R) mode, follow symbolic links even when the
| --physical (aka -P) or -L option is specified, which might allow local
| users to modify the ACL for arbitrary files or directories via a
| symlink attack.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4411
    http://security-tracker.debian.org/tracker/CVE-2009-4411

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to