2.1

CVE-2008-0216

The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freebsd ≫ Freebsd Version 6.0
Freebsd ≫ Freebsd Version 6.0 Update release
Freebsd ≫ Freebsd Version 6.0 Update stable
Freebsd ≫ Freebsd Version 6.1
Freebsd ≫ Freebsd Version 6.1 Update release
Freebsd ≫ Freebsd Version 6.1 Update release_p10
Freebsd ≫ Freebsd Version 6.1 Update stable
Freebsd ≫ Freebsd Version 6.2
Freebsd ≫ Freebsd Version 6.2 Update stable
Freebsd ≫ Freebsd Version 6.3
Freebsd ≫ Freebsd Version 7.0
Freebsd ≫ Freebsd Version 7.0 Update current
Freebsd ≫ Freebsd Version 7.0 Update pre-release
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.228
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/28498
http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc
Patch
http://www.securityfocus.com/bid/27284
http://www.securitytracker.com/id?1019191
https://exchange.xforce.ibmcloud.com/vulnerabilities/39667