search menu icon-carat-right cmu-wordmark

CERT Coordination Center

SGI IRIX "xfsdump" creates quota information files insecurely

Vulnerability Note VU#111673

Original Release Date: 2003-04-10 | Last Revised: 2003-06-16

Overview

A vulnerability exists in xfsdump on SGI IRIX. Exploitation of this vulnerability may allow a local attacker to gain root privileges. Because other operating systems ship with xfsdump, vendors other than SGI may be affected.

Description

From the xfsdump man page:

xfsdump backs up files and their attributes in a filesystem. The files are dumped to storage media, a regular file, or standard output. Options allow the operator to have all files dumped, just files that have changed since a previous dump, or just files contained in a list of pathnames.
xfsdump does not create quota files in a secure manner. As a result, a local attacker may be able to gain superuser privileges on a vulnerable system. For more details, please see SGI Security Advisory 20030404-01-P.

Impact

A local attacker may be able to gain superuser privileges.

Solution

Apply a patch from your vendor.

Vendor Information

111673
 

View all 55 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was discovered by Ethan Benson.

This document was written by Ian A Finlay.

Other Information

CVE IDs: CVE-2003-0173
Severity Metric: 6.75
Date Public: 2003-04-10
Date First Published: 2003-04-10
Date Last Updated: 2003-06-16 19:42 UTC
Document Revision: 5

Sponsored by CISA.