PT-2002-1622 · Freebsd · Freebsd

Publicado

2002-06-11

·

Atualizado

2018-10-30

·

CVE-2002-0572

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeBSD versions 4.5 and earlier
Description The issue allows local users to access restricted files by manipulating file descriptors. This is done by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which can then be reused by a setuid process. This process intended to perform input/output operations on normal files, but due to the file descriptor manipulation, it may end up accessing restricted files instead.
Recommendations For FreeBSD versions 4.5 and earlier, consider updating to a newer version to mitigate the risk, as the exact fix or patch details are not specified. As a temporary workaround, consider restricting the use of setuid processes or implementing additional access controls to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0572

Produtos afetados

Freebsd