First published: Fri Jan 15 2010(Updated: )
The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and 8.0, when creating files during replay of a setattr transaction, uses 7777 permissions instead of the original permissions, which might allow local users to read or modify unauthorized files in opportunistic circumstances after a system crash or power failure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =7.1 | |
FreeBSD Kernel | =7.2 | |
FreeBSD Kernel | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0318 is rated as a medium severity vulnerability that could allow unauthorized file access due to improper permission handling.
To fix CVE-2010-0318, users should upgrade to a patched version of FreeBSD that addresses the ZFS Intent Log permission issue.
CVE-2010-0318 affects FreeBSD versions 7.1, 7.2, and 8.0.
CVE-2010-0318 exploits the replay functionality in the ZFS Intent Log, leading to inappropriate file permissions being set.
Local users on affected FreeBSD systems may be impacted, as they could gain unauthorized access to files.