PT-2008-2395 · Freebsd · Freebsd

Kostik Belousov

·

Publicado

2008-02-15

·

Atualizado

2008-09-05

·

CVE-2008-0777

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions FreeBSD versions 5.5 through 7.0
Description The issue concerns the sendfile system call, which does not properly check the access flags of the file descriptor used for sending a file. This allows local users to read the contents of files that are supposed to be write-only.
Recommendations For versions 5.5 through 7.0, update to a version that includes a fix for this issue, as the current version allows unauthorized access to file contents.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0777

Produtos afetados

Freebsd