"value":"The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when running in recursive (-R) mode, follow symbolic links even when the --physical (aka -P) or -L option is specified, which might allow local users to modify the ACL for arbitrary files or directories via a symlink attack."
},
{
"lang":"es",
"value":"Los comandos (1) setfacl y (2) getfacl en XFS acl v2.2.47, cuando corre en modo recursivo (-R), sigue enlaces simb\u00f3licos incluso cuando la opci\u00f3n f\u00edsica -- (como -P) o -L est\u00e1 especificada,lo que puede permitir a usuarios locales modificar el ACL por ficheros o directorios de su elecci\u00f3n a trav\u00e9s de un ataque sumlink."
}
],
"vendorComments":[
{
"organization":"Red Hat",
"comment":"Not vulnerable. This issue did not affect the versions of acl as shipped with Red Hat Enterprise Linux 3, 4, or 5.",