2.1

CVE-2008-0216

The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user.

Data is provided by the National Vulnerability Database (NVD)
FreebsdFreebsd Version6.0
FreebsdFreebsd Version6.0 Updaterelease
FreebsdFreebsd Version6.0 Updatestable
FreebsdFreebsd Version6.1
FreebsdFreebsd Version6.1 Updaterelease
FreebsdFreebsd Version6.1 Updaterelease_p10
FreebsdFreebsd Version6.1 Updatestable
FreebsdFreebsd Version6.2
FreebsdFreebsd Version6.2 Updatestable
FreebsdFreebsd Version6.3
FreebsdFreebsd Version7.0
FreebsdFreebsd Version7.0 Updatecurrent
FreebsdFreebsd Version7.0 Updatepre-release
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.186
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N