First published: Wed Jan 16 2008(Updated: )
The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script.
Credit: secteam@freebsd.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD FreeBSD | =7.0-pre-release | |
FreeBSD FreeBSD | =6.1 | |
FreeBSD FreeBSD | =5.5 | |
FreeBSD FreeBSD | =7.0 | |
FreeBSD FreeBSD | =6.0 | |
FreeBSD FreeBSD | =6.2 | |
FreeBSD FreeBSD | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.