CVE-2009-4358 - CERT CVE
ID CVE-2009-4358
Sažetak freebsd-update in FreeBSD 8.0, 7.2, 7.1, 6.4, and 6.3 uses insecure permissions in its working directory (/var/db/freebsd-update by default), which allows local users to read copies of sensitive files after a (1) freebsd-update fetch (fetch) or (2) freebsd-update upgrade (upgrade) operation.
Reference
CVSS
Base: 4.7
Impact: 6.9
Exploitability:3.4
Pristup
VektorSloženostAutentikacija
LOCAL MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE NONE NONE
CVSS vektor AV:L/AC:M/Au:N/C:C/I:N/A:N
Zadnje važnije ažuriranje 21-12-2009 - 05:00
Objavljeno 20-12-2009 - 02:30