First published: Wed Jan 16 2008(Updated: )
The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user.
Credit: secteam@freebsd.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD FreeBSD | =7.0-pre-release | |
FreeBSD FreeBSD | =6.1 | |
FreeBSD FreeBSD | =6.3 | |
FreeBSD FreeBSD | =6.1-stable | |
FreeBSD FreeBSD | =6.1-release | |
FreeBSD FreeBSD | =7.0 | |
FreeBSD FreeBSD | =6.1-release_p10 | |
FreeBSD FreeBSD | =6.0 | |
FreeBSD FreeBSD | =6.2-stable | |
FreeBSD FreeBSD | =6.2 | |
FreeBSD FreeBSD | =6.0-release | |
FreeBSD FreeBSD | =7.0-current | |
FreeBSD FreeBSD | =6.0-stable |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.