PT-2002-2393 · Freebsd · Freebsd

Published

2002-12-31

·

Updated

2017-07-11

·

CVE-2002-1669

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FreeBSD versions 4.2 through 4.4
Description The issue allows local users to potentially modify world-writable parts of a package during installation due to the creation of a temporary directory with world-searchable permissions by pkg add.
Recommendations For FreeBSD versions 4.2 through 4.4, consider restricting access to the temporary directory created by pkg add to prevent local users from modifying package contents during installation. As a temporary workaround, ensure that the installation process is closely monitored and that packages are installed from trusted sources to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1669

Affected Products

Freebsd