The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when running in recursive (-R) mode, follow symbolic links even when the --physical (aka -P) or -L option is specified, which might allow local users to modify the ACL for arbitrary files or directories via a symlink attack.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2009-12-24T16:00:00

Updated: 2017-08-16T14:57:01

Reserved: 2009-12-23T00:00:00


Link: CVE-2009-4411

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2009-12-24T16:30:00.343

Modified: 2017-08-17T01:31:34.367


Link: CVE-2009-4411

JSON object: View

cve-icon Redhat Information

No data.

CWE