Title : Redhat Security Update Fixes X.Org XFS Script Privilege Escalation Vulnerability VUPEN ID : VUPEN/ADV-2007-2515 CVE ID : CVE-2007-3103
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2007-07-12
Technical Description
A vulnerability has been identified in Redhat, which could be exploited by local attackers to obtain elevated privileges. This issue is caused by a race condition in the way temporary files are handled when executing the X.Org X11 XFS script, which could be exploited by malicious users manipulate certain files and gain root privileges when a vulnerable system (or XFS) is rebooted.