Lucene search

K
cveMitreCVE-2004-0099
HistorySep 01, 2004 - 4:00 a.m.

CVE-2004-0099

2004-09-0104:00:00
mitre
web.nvd.nist.gov
35
cve-2004-0099
mksnap_ffs
freebsd
access restrictions
snapshot flags
security vulnerability
local user
nvd

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0

Percentile

5.1%

mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended access restrictions.

Affected configurations

Nvd
Node
freebsdfreebsdMatch5.1release
OR
freebsdfreebsdMatch5.2.1release
VendorProductVersionCPE
freebsdfreebsd5.1cpe:2.3:o:freebsd:freebsd:5.1:release:*:*:*:*:*:*
freebsdfreebsd5.2.1cpe:2.3:o:freebsd:freebsd:5.2.1:release:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0

Percentile

5.1%