First published: Thu Aug 27 2020(Updated: )
OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenZFS OpenZFS | <=0.8.4 | |
FreeBSD FreeBSD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24717 is a vulnerability in OpenZFS before version 2.0.0-rc1 when used on FreeBSD, where it misinterprets group permissions as user permissions.
CVE-2020-24717 affects OpenZFS before version 2.0.0-rc1 when used on FreeBSD by misinterpreting group permissions as user permissions.
The severity of CVE-2020-24717 is high with a CVSS score of 7.8.
To fix CVE-2020-24717, upgrade to OpenZFS version 2.0.0-rc1 or later.
You can find more information about CVE-2020-24717 at the following references: [1] [2] [3].