Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian: DSA 284-1 Critical Flaw In Xfsdump Unsecured File Generation

debian
Calendar Grey April 11, 2003
Debian Logo
Uncover the vulnerability in xfsdump regarding the risky file creation issue and learn how users of Debian can promptly update their systems to enhance security.
The manner in which the quota information file is created is unsafe.

Summary

Ethan Benson discovered a problem in xfsdump, that contains
administrative utilities for the XFS filesystem. When filesystem
quotas are enabled xfsdump runs xfsdq to save the quota information
into a file at the root of the filesystem being dumped. The manner in
which this file is created is unsafe.

While fixing this, a new option ``-f path' has been added to xfsdq(8)
to specify an output file instead of using the standard output stream.
This file is created by xfsdq and xfsdq will fail to run if it exists
already. The file is also created with a more appropriate mode than
whatever the umask happened to be when xfsdump(8) was run.

For the stable distribution (woody) this problem has been fixed in
version 2.0.1-2.

The old stable distribution (potato) is not affected since it doesn't
contain xfsdump packages.

For the unstable distribution (sid) this problem has been fixed in
version 2.2.8-1.

We recommend that you upgrade your lpr package immediately.


Upgrade Instructions
- --------------------

wget url
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: xfsdump

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here