CVE-2008-0217
Published Jan 16, 2008
Last updated 7 years ago
Overview
- Description
- The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script.
- Source
- secteam@freebsd.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.9
- Impact score
- 10
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:freebsd:freebsd:5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "61EBA52A-2D8B-4FB5-866E-AE67CE1842E7" }, { "criteria": "cpe:2.3:o:freebsd:freebsd:5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7752D43D-64AF-474F-BFBB-2625A29C1B88" }, { "criteria": "cpe:2.3:o:freebsd:freebsd:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D2C79D5-D27F-4B08-A8DF-3E3AAF4E16A5" }, { "criteria": "cpe:2.3:o:freebsd:freebsd:6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F4416CBA-76B9-4051-B015-F1BE89517309" }, { "criteria": "cpe:2.3:o:freebsd:freebsd:6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9118B602-3FB6-4701-AC09-763DD48334BA" }, { "criteria": "cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47E0A416-733A-4616-AE08-150D67FCEA70" }, { "criteria": "cpe:2.3:o:freebsd:freebsd:7.0:pre-release:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "42231BCC-2B90-4196-A1C2-408A353C1BEF" } ], "operator": "OR" } ] } ]