CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:M/Au:N/C:C/I:N/A:N
AI Score
Confidence
Low
EPSS
Percentile
5.1%
freebsd-update in FreeBSD 8.0, 7.2, 7.1, 6.4, and 6.3 uses insecure permissions in its working directory (/var/db/freebsd-update by default), which allows local users to read copies of sensitive files after a (1) freebsd-update fetch (fetch) or (2) freebsd-update upgrade (upgrade) operation.
Vendor | Product | Version | CPE |
---|---|---|---|
freebsd | freebsd | 6.3 | cpe:2.3:o:freebsd:freebsd:6.3:*:*:*:*:*:*:* |
freebsd | freebsd | 6.4 | cpe:2.3:o:freebsd:freebsd:6.4:*:*:*:*:*:*:* |
freebsd | freebsd | 7.1 | cpe:2.3:o:freebsd:freebsd:7.1:*:*:*:*:*:*:* |
freebsd | freebsd | 7.2 | cpe:2.3:o:freebsd:freebsd:7.2:*:*:*:*:*:*:* |
freebsd | freebsd | 8.0 | cpe:2.3:o:freebsd:freebsd:8.0:*:*:*:*:*:*:* |