First published: Mon Aug 12 2002(Updated: )
The rc system startup script for FreeBSD 4 through 4.5 allows local users to delete arbitrary files via a symlink attack on X Windows lock files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =4.5-stable | |
FreeBSD Kernel | =4.5-release |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0795 is considered to be a moderate severity vulnerability.
To fix CVE-2002-0795, upgrade to FreeBSD version 4.6 or later where the issue is resolved.
CVE-2002-0795 affects FreeBSD versions 4.5-release and 4.5-stable.
A symlink attack in this context allows local users to exploit vulnerabilities in file permission settings to delete arbitrary files.
CVE-2002-0795 can be exploited by local users on the FreeBSD system.