CVE-2007-4849

N/A Unknown
Published: September 12, 2007 Modified: April 23, 2026
View on NVD

Description

JFFS2, as used on One Laptop Per Child (OLPC) build 542 and possibly other Linux systems, when POSIX ACL support is enabled, does not properly store permissions during (1) inode creation or (2) ACL setting, which might allow local users to access restricted files or directories after a remount of a filesystem, related to "legacy modes" and an inconsistency between dentry permissions and inode permissions.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://dev.laptop.org/ticket/2732
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26978
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/28170
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/28706
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2007/dsa-1378
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/25838
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-558-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-574-1
Source: af854a3a-2127-422b-91ae-364da2661108

20 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.3%
26th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

one_laptop_per_child