Lucene search

K
cve[email protected]CVE-2008-0216
HistoryJan 16, 2008 - 2:00 a.m.

CVE-2008-0216

2008-01-1602:00:00
CWE-264
web.nvd.nist.gov
26
cve-2008-0216
ptsname function
freebsd
data security
local user access

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

5.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user.

Affected configurations

NVD
Node
freebsdfreebsdMatch6.0
OR
freebsdfreebsdMatch6.0release
OR
freebsdfreebsdMatch6.0stable
OR
freebsdfreebsdMatch6.1
OR
freebsdfreebsdMatch6.1release
OR
freebsdfreebsdMatch6.1release_p10
OR
freebsdfreebsdMatch6.1stable
OR
freebsdfreebsdMatch6.2
OR
freebsdfreebsdMatch6.2stable
OR
freebsdfreebsdMatch6.3
OR
freebsdfreebsdMatch7.0
OR
freebsdfreebsdMatch7.0current
OR
freebsdfreebsdMatch7.0pre-release

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

5.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%