---
title: "CVE-2007-4849\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2007-4849?format=md
keywords: index, follow
---

# CVE-2007-4849

Publication date 12 September 2007

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

JFFS2, as used on One Laptop Per Child (OLPC) build 542 and possibly other
Linux systems, when POSIX ACL support is enabled, does not properly store
permissions during (1) inode creation or (2) ACL setting, which might allow
local users to access restricted files or directories after a remount of a
filesystem, related to "legacy modes" and an inconsistency between dentry
permissions and inode permissions.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2007-4849?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| linux-source-2.6.15 | 6.06 LTS dapper | Not affected |
| linux-source-2.6.17 | 6.10 edgy | Fixed 2.6.17.1-12.42 |
| linux-source-2.6.20 | 7.04 feisty | Fixed 2.6.20-16.33 |
| linux-source-2.6.22 | 7.10 gutsy | Fixed 2.6.22-14.47 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

fix in DSA 1378-1 and 1378-2

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4849)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2007-4849)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2007-4849)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2007-4849)

### Related Ubuntu Security Notices (USN)

+ [USN-574-1](https://usn.ubuntu.com/USN-574-1)
+ Linux kernel vulnerabilities
+ 4 February 2008

+ [USN-558-1](https://usn.ubuntu.com/USN-558-1)
+ Linux kernel vulnerabilities
+ 19 December 2007

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2007-4849>
