(1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm.
2007-10-28T17:08:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 6.0 (MEDIUM)
AV:L/AC:M/Au:S/C:N/I:C/A:C
2.7
9.2
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | debian | debian_linux | 4.0 | No |
Operating System | debian | debian_linux | 4.0 | No |
Operating System | debian | debian_linux | 4.0 | No |
Operating System | debian | debian_linux | 4.0 | No |
Operating System | debian | debian_linux | 4.0 | No |
Operating System | debian | debian_linux | 4.0 | No |
Operating System | debian | debian_linux | 4.0 | No |
Operating System | debian | debian_linux | 4.0 | No |
Operating System | debian | debian_linux | 4.0 | No |
Operating System | debian | debian_linux | 4.0 | No |
Operating System | debian | debian_linux | 4.0 | No |
Operating System | debian | debian_linux | 4.0 | No |
Application | xensource_inc | xen | 3.0.3_0_1 | Yes |
Application | xensource_inc | xen | 3.0.3_0_3 | Yes |