Vulnerability Name:

CVE-2009-4411 (CCN-55004)

Assigned:2009-06-22
Published:2009-06-22
Updated:2017-08-17
Summary:The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when running in recursive (-R) mode, follow symbolic links even when the --physical (aka -P) or -L option is specified, which might allow local users to modify the ACL for arbitrary files or directories via a symlink attack.
CVSS v3 Severity:5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:3.7 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P)
3.3 Low (Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P/E:H/RL:TF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
3.3 Low (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:TF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-264
Vulnerability Consequences:File Manipulation
References:Source: CONFIRM
Type: UNKNOWN
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499076

Source: MITRE
Type: CNA
CVE-2009-4411

Source: CCN
Type: acl.git repository
Make sure that getfacl -R only calls stat(2) on symlinks when it needs to

Source: CONFIRM
Type: UNKNOWN
http://git.savannah.gnu.org/cgit/acl.git/commit/?id=63451a0

Source: SUSE
Type: UNKNOWN
SUSE-SR:2010:002

Source: CCN
Type: SGI Bugzilla Bug 790
getfacl 2.2.47 follows symlinks, even without -L

Source: CONFIRM
Type: UNKNOWN
http://oss.sgi.com/bugzilla/show_bug.cgi?id=790

Source: OSVDB
Type: UNKNOWN
61302

Source: CCN
Type: SA37907
XFS Acl Recursive Symlink Processing Security Issue

Source: SECUNIA
Type: Vendor Advisory
37907

Source: SECUNIA
Type: UNKNOWN
38420

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2009:345

Source: MLIST
Type: UNKNOWN
[oss-security] 20091223 CVE request: acl 2.2.47 always follows symlinks

Source: CCN
Type: OSVDB ID: 61302
XFS Acl Multiple Operation Recursive Symlink Handling Local Privilege Escalation

Source: BID
Type: Patch
37455

Source: CCN
Type: BID-37455
XFS ACL 'setfacl' and 'getfacl' Symbolic Link Handling Security Bypass Vulnerability

Source: CCN
Type: XFS Web site
XFS

Source: XF
Type: UNKNOWN
acl-setfacl-getfacl-symlink(55004)

Source: XF
Type: UNKNOWN
acl-setfacl-getfacl-symlink(55004)

Source: SUSE
Type: SUSE-SR:2010:002
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:xfs:acl:2.2.47:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:xfs:acl:2.2.47:*:*:*:*:*:*:*
  • AND
  • cpe:/o:mandriva:linux:2009.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandriva:linux:2009.0:-:x86_64:*:*:*:*:*
  • OR cpe:/o:mandriva:linux:2009.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandriva:linux:2009.1:*:*:*:x86_64:*:*:*
  • OR cpe:/o:mandriva:enterprise_server:5:*:*:*:*:*:*:*
  • OR cpe:/o:mandriva:enterprise_server:5:*:*:*:x86_64:*:*:*
  • OR cpe:/o:mandriva:linux:2010:*:*:*:x86_64:*:*:*
  • OR cpe:/o:mandriva:linux:2010:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20094411
    V
    CVE-2009-4411
    2022-05-20
    oval:org.opensuse.security:def:32235
    P
    Security update for openssh (Important)
    2021-12-06
    oval:org.opensuse.security:def:32142
    P
    Security update for systemd (Important)
    2021-07-21
    oval:org.opensuse.security:def:29370
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:32008
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP3) (Important)
    2020-12-07
    oval:org.opensuse.security:def:32591
    P
    pam_mount on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28259
    P
    Security update for lynx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31934
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:32679
    P
    gstreamer-0_10-plugins-good on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28495
    P
    Recommended update for openldap2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27913
    P
    Security update for xen (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32745
    P
    lvm2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28597
    P
    Security update for Python
    2020-12-01
    oval:org.opensuse.security:def:32292
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27988
    P
    Security update for MozillaFirefox, mozilla-nss, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:33422
    P
    Security update for acl and libacl
    2020-12-01
    oval:org.opensuse.security:def:28652
    P
    Security update for curl
    2020-12-01
    oval:org.opensuse.security:def:32535
    P
    kdebase3-runtime on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28202
    P
    Security update for libid3tag (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31923
    P
    Security update for ghostscript-library (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29334
    P
    Security update for lighttpd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32640
    P
    bzip2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28343
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27912
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:32701
    P
    libQtWebKit4-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28548
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:27924
    P
    Security update for Botan (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33383
    P
    Security update for compat-openssl097g (Important)
    2020-12-01
    oval:org.opensuse.security:def:28636
    P
    Security update for bash
    2020-12-01
    oval:org.opensuse.security:def:32379
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28118
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31922
    P
    Security update for ghostscript-library (Important)
    2020-12-01
    oval:org.opensuse.security:def:28696
    P
    Security update for glibc
    2020-12-01
    oval:com.ubuntu.precise:def:20094411000
    V
    CVE-2009-4411 on Ubuntu 12.04 LTS (precise) - low.
    2009-12-24
    BACK
    xfs acl 2.2.47
    xfs acl 2.2.47
    mandriva linux 2009.0
    mandriva linux 2009.0 -
    mandriva linux 2009.1
    mandriva linux 2009.1
    mandriva enterprise server 5
    mandriva enterprise server 5
    mandriva linux 2010
    mandriva linux 2010