CVE-2008-0216: Low severity freebsd kernel vulnerability
Published Jan 16, 2008
·Updated
The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the ptchown function, which might allow local users to read data from the pty from another user.
Affected Software
13 affected components
FreeBSD FreeBSD=6.0
FreeBSD FreeBSD=6.0-release
FreeBSD FreeBSD=6.0-stable
FreeBSD FreeBSD=6.1
FreeBSD FreeBSD=6.1-release
FreeBSD FreeBSD=6.1-release_p10
FreeBSD FreeBSD=6.1-stable
FreeBSD FreeBSD=6.2
FreeBSD FreeBSD=6.2-stable
FreeBSD FreeBSD=6.3
FreeBSD FreeBSD=7.0
FreeBSD FreeBSD=7.0-current
FreeBSD FreeBSD=7.0-pre-release
Remediation
Event History
Jan 16, 2008
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0216?
CVE-2008-0216 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2008-0216?
To fix CVE-2008-0216, you should update your FreeBSD system to a version that has addressed this vulnerability.
3
Who is affected by CVE-2008-0216?
CVE-2008-0216 affects local users of FreeBSD versions 6.0 through 7.0-PRERELEASE.
4
What type of vulnerability is CVE-2008-0216?
CVE-2008-0216 is a local privilege escalation vulnerability in the ptsname function.
5
Can CVE-2008-0216 be exploited remotely?
No, CVE-2008-0216 can only be exploited by local users on affected FreeBSD systems.