- Description
- The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack.
- Source
- secteam@freebsd.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 6.6
- Impact score
- 10
- Exploitability score
- 2.7
- Vector string
- AV:L/AC:M/Au:S/C:C/I:C/A:C
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9946D111-48AA-4467-88E2-45BDC951FD52",
"versionEndIncluding": "6.2"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:5.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D8A80E6A-6502-4A33-83BA-7DCC606D79AA"
}
],
"operator": "OR"
}
]
}
]