Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-0217
HistoryJan 16, 2008 - 12:00 a.m.

CVE-2008-0217

2008-01-1600:00:00
ubuntu.com
ubuntu.com
11

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

0.0004 Low

EPSS

Percentile

5.1%

The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty,
which creates a pseudo-terminal with world-readable and world-writable
permissions when it is not run as root, which allows local users to read
data from the terminal of the user running script.

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

0.0004 Low

EPSS

Percentile

5.1%