PT-2002-2393 · Freebsd · Freebsd
Publicado
2002-12-31
·
Atualizado
2017-07-11
·
CVE-2002-1669
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions 4.2 through 4.4
Description
The issue allows local users to potentially modify world-writable parts of a package during installation due to the creation of a temporary directory with world-searchable permissions by
pkg add.Recommendations
For FreeBSD versions 4.2 through 4.4, consider restricting access to the temporary directory created by
pkg add to prevent local users from modifying package contents during installation. As a temporary workaround, ensure that the installation process is closely monitored and that packages are installed from trusted sources to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Freebsd