PT-2008-2395 · Freebsd · Freebsd
Kostik Belousov
·
Publicado
2008-02-15
·
Atualizado
2008-09-05
·
CVE-2008-0777
CVSS v2.0
4.9
Média
| Vetor | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions 5.5 through 7.0
Description
The issue concerns the sendfile system call, which does not properly check the access flags of the file descriptor used for sending a file. This allows local users to read the contents of files that are supposed to be write-only.
Recommendations
For versions 5.5 through 7.0, update to a version that includes a fix for this issue, as the current version allows unauthorized access to file contents.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Freebsd