First published: Fri Feb 15 2008(Updated: )
The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD FreeBSD | =6.3 | |
FreeBSD FreeBSD | =5.5 | |
FreeBSD FreeBSD | =7.0 | |
FreeBSD FreeBSD | =6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.