Lucene search

K
cveMitreCVE-2009-4358
HistoryDec 20, 2009 - 2:30 a.m.

CVE-2009-4358

2009-12-2002:30:00
CWE-264
mitre
web.nvd.nist.gov
33
freebsd
freebsd-update
cve-2009-4358
security
vulnerability
nvd

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

5.1%

freebsd-update in FreeBSD 8.0, 7.2, 7.1, 6.4, and 6.3 uses insecure permissions in its working directory (/var/db/freebsd-update by default), which allows local users to read copies of sensitive files after a (1) freebsd-update fetch (fetch) or (2) freebsd-update upgrade (upgrade) operation.

Affected configurations

Nvd
Node
freebsdfreebsdMatch6.3
OR
freebsdfreebsdMatch6.4
OR
freebsdfreebsdMatch7.1
OR
freebsdfreebsdMatch7.2
OR
freebsdfreebsdMatch8.0
VendorProductVersionCPE
freebsdfreebsd6.3cpe:2.3:o:freebsd:freebsd:6.3:*:*:*:*:*:*:*
freebsdfreebsd6.4cpe:2.3:o:freebsd:freebsd:6.4:*:*:*:*:*:*:*
freebsdfreebsd7.1cpe:2.3:o:freebsd:freebsd:7.1:*:*:*:*:*:*:*
freebsdfreebsd7.2cpe:2.3:o:freebsd:freebsd:7.2:*:*:*:*:*:*:*
freebsdfreebsd8.0cpe:2.3:o:freebsd:freebsd:8.0:*:*:*:*:*:*:*

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2009-4358