Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-4411

The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when running in recursive (-R) mode, follow symbolic links even when the --physical (aka -P) or -L option is specified, which might allow local users to modify the ACL for arbitrary files or directories via a symlink attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 21.3%
CVSS Severity
CVSS v2 Score 3.7
References
Products affected by CVE-2009-4411
  • Xfs » Acl » Version: 2.2.47
    cpe:2.3:a:xfs:acl:2.2.47


Contact Us

Shodan ® - All rights reserved