CVE-2007-4849
JFFS2, as used on One Laptop Per Child (OLPC) build 542 and possibly other Linux systems, when POSIX ACL support is enabled, does not properly store permissions during (1) inode creation or (2) ACL setting, which might allow local users to access…
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
JFFS2, as used on One Laptop Per Child (OLPC) build 542 and possibly other Linux systems, when POSIX ACL support is enabled, does not properly store permissions during (1) inode creation or (2) ACL setting, which might allow local users to access restricted files or directories after a remount of a filesystem, related to "legacy modes" and an inconsistency between dentry permissions and inode permissions.
- CVSS 2.0
- 4.4 MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- one laptop per child/olpc linux
- Source
- cve@mitre.org
References
- http://dev.laptop.org/ticket/2732
- http://git.infradead.org/?p=mtd-2.6.git%3Ba=commitdiff%3Bh=9ed437c50d89eabae763dd422579f73fdebf288d
- http://lists.infradead.org/pipermail/linux-mtd-cvs/2007-August/005897.html
- http://secunia.com/advisories/26978
- http://secunia.com/advisories/28170
- http://secunia.com/advisories/28706
- http://www.debian.org/security/2007/dsa-1378
- http://www.securityfocus.com/bid/25838
- http://www.ubuntu.com/usn/usn-558-1
- http://www.ubuntu.com/usn/usn-574-1
- http://dev.laptop.org/ticket/2732
- http://git.infradead.org/?p=mtd-2.6.git%3Ba=commitdiff%3Bh=9ed437c50d89eabae763dd422579f73fdebf288d
- http://lists.infradead.org/pipermail/linux-mtd-cvs/2007-August/005897.html
- http://secunia.com/advisories/26978
- http://secunia.com/advisories/28170
- http://secunia.com/advisories/28706
- http://www.debian.org/security/2007/dsa-1378
- http://www.securityfocus.com/bid/25838
- http://www.ubuntu.com/usn/usn-558-1
- http://www.ubuntu.com/usn/usn-574-1
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.