6.9

CVE-2008-0217

The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script.

Data is provided by the National Vulnerability Database (NVD)
FreebsdFreebsd Version5.0
FreebsdFreebsd Version5.5
FreebsdFreebsd Version6.0
FreebsdFreebsd Version6.1
FreebsdFreebsd Version6.2
FreebsdFreebsd Version7.0
FreebsdFreebsd Version7.0 Updatepre-release
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.068
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C