CVE-2010-0318: Medium severity freebsd kernel vulnerability
The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and 8.0, when creating files during replay of a setattr transaction, uses 7777 permissions instead of the original permissions, which might allow local users to read or modify unauthorized files in opportunistic circumstances after a system crash or power failure.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0318?
CVE-2010-0318 is rated as a medium severity vulnerability that could allow unauthorized file access due to improper permission handling.
How do I fix CVE-2010-0318?
To fix CVE-2010-0318, users should upgrade to a patched version of FreeBSD that addresses the ZFS Intent Log permission issue.
What versions of FreeBSD are affected by CVE-2010-0318?
CVE-2010-0318 affects FreeBSD versions 7.1, 7.2, and 8.0.
What does CVE-2010-0318 exploit?
CVE-2010-0318 exploits the replay functionality in the ZFS Intent Log, leading to inappropriate file permissions being set.
Who can be impacted by CVE-2010-0318?
Local users on affected FreeBSD systems may be impacted, as they could gain unauthorized access to files.