Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-3103

25
FAUCET Score

CVE-2007-3103 describes a local privilege escalation vulnerability in the X.Org X11 xfs font server's init.d script, affecting various Linux distributions including Fedora and Red Hat Enterprise Linux. An attacker could exploit a symlink race condition on the /tmp/.font-unix temporary file to arbitrarily change file permissions. This vulnerability has a CVSS score of 6.2, indicating high impact on confidentiality, integrity, and availability, but requires high attack complexity and local access. While no active exploitation or Metasploit modules are reported, an ExploitDB entry exists, and there is minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
6.0CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora_core:6.0:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:4.0:*:as:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:4.0:*:es:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:4.0:*:ws:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_desktop:4.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.2MEDIUM

AV:L/AC:H/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
1.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.90%
Probability of exploitation in next 30 days
EPSS Percentile
56.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-5167 · Feb 21, 2008
This CVE's current EPSS score of 0.0090 is in the 89th percentile among its peer group of 1,595 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: xorg-x11-0:6.8.2-1.EL.19
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: xorg-x11-xfs-1:1.0.2-4
View patch

Vendor Advisories (1)

redhatCVE-2007-3103Moderate

security flaw

Jul 11, 2007

References

bugs.gentoo.org / show_bug.cgi
bugzilla.redhat.com / 242903
labs.idefense.com / intelligence/vulnerabilities/display.php
Patch
osvdb.org / 40945
secunia.com / advisories/26056
Vendor Advisory
secunia.com / advisories/26081
Vendor Advisory
secunia.com / advisories/26282
Vendor Advisory
secunia.com / advisories/27240
Vendor Advisory
secunia.com / advisories/35674
Vendor Advisory
security.gentoo.org / glsa/glsa-200710-11.xml
exchange.xforce.ibmcloud.com / vulnerabilities/35375
issues.rpath.com / browse/RPL-1485
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10802
exploit-db.com / exploits/5167
redhat.com / archives/fedora-package-announce/2009-July/msg00095.html
redhat.com / archives/fedora-package-announce/2009-July/msg00096.html
debian.org / security/2007/dsa-1342
redhat.com / support/errata/RHSA-2007-0519.html
redhat.com / support/errata/RHSA-2007-0520.html
securityfocus.com / archive/1/473869/100/0/threaded
securityfocus.com / bid/24888
securitytracker.com / id