The redirectstderr function in xnbdcommon.c in xnbd-server and xndb-wrapper in xNBD 0.1.0 allow local users to overwrite arbitrary files via a symlink attack on /tmp/xnbd.log.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "xnbd-client",
"binary_version": "0.2.0~rc2-hg1-abf8cc7a1ab0-2"
},
{
"binary_name": "xnbd-common",
"binary_version": "0.2.0~rc2-hg1-abf8cc7a1ab0-2"
},
{
"binary_name": "xnbd-server",
"binary_version": "0.2.0~rc2-hg1-abf8cc7a1ab0-2"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "xnbd-client",
"binary_version": "0.3.0-1ubuntu1"
},
{
"binary_name": "xnbd-client-dbgsym",
"binary_version": "0.3.0-1ubuntu1"
},
{
"binary_name": "xnbd-common",
"binary_version": "0.3.0-1ubuntu1"
},
{
"binary_name": "xnbd-common-dbgsym",
"binary_version": "0.3.0-1ubuntu1"
},
{
"binary_name": "xnbd-server",
"binary_version": "0.3.0-1ubuntu1"
},
{
"binary_name": "xnbd-server-dbgsym",
"binary_version": "0.3.0-1ubuntu1"
}
]
}