PT-2002-1840 · Freebsd · Freebsd Kernel

Published

2002-08-02

·

Updated

2016-10-18

·

CVE-2002-0820

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: FreeBSD kernel version 4.6 and earlier
Description: The issue allows local users to potentially reuse file descriptors in a setuid or setgid program, which could lead to modifying critical data and gaining privileges. This occurs because the FreeBSD kernel closes the file descriptors 0, 1, and 2 after they have been assigned to /dev/null when the descriptors reference procfs or linprocfs.
Recommendations: For FreeBSD kernel version 4.6 and earlier, consider restricting access to setuid or setgid programs that utilize file descriptors referencing procfs or linprocfs until a patch is available. As a temporary workaround, avoid using setuid or setgid programs that could be exploited through this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0820

Affected Products

Freebsd Kernel