PT-2002-2393 · Freebsd · Freebsd
Published
2002-12-31
·
Updated
2017-07-11
·
CVE-2002-1669
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions 4.2 through 4.4
Description
The issue allows local users to potentially modify world-writable parts of a package during installation due to the creation of a temporary directory with world-searchable permissions by
pkg add.Recommendations
For FreeBSD versions 4.2 through 4.4, consider restricting access to the temporary directory created by
pkg add to prevent local users from modifying package contents during installation. As a temporary workaround, ensure that the installation process is closely monitored and that packages are installed from trusted sources to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd