4.4
CVE-2007-4849
- EPSS 0.34%
- Veröffentlicht 12.09.2007 20:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:54
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
JFFS2, as used on One Laptop Per Child (OLPC) build 542 and possibly other Linux systems, when POSIX ACL support is enabled, does not properly store permissions during (1) inode creation or (2) ACL setting, which might allow local users to access restricted files or directories after a remount of a filesystem, related to "legacy modes" and an inconsistency between dentry permissions and inode permissions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
One Laptop Per Child ≫ Olpc Linux Versionbuild_542
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.259 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.4 | 3.4 | 6.4 |
AV:L/AC:M/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/28170
http://secunia.com/advisories/28706
http://www.ubuntu.com/usn/usn-558-1
http://www.ubuntu.com/usn/usn-574-1
http://dev.laptop.org/ticket/2732
http://git.infradead.org/?p=mtd-2.6.git%3Ba=commitdiff%3Bh=9ed437c50d89eabae763dd422579f73fdebf288d
http://lists.infradead.org/pipermail/linux-mtd-cvs/2007-August/005897.html
http://secunia.com/advisories/26978
http://www.debian.org/security/2007/dsa-1378
http://www.securityfocus.com/bid/25838