Vulnerability Name: | CVE-2008-0216 (CCN-39667) | ||||||||
Assigned: | 2008-01-14 | ||||||||
Published: | 2008-01-14 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user. | ||||||||
CVSS v3 Severity: | 4.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.1 Low (CCN Temporal CVSS v2 Vector: AV:A/AC:L/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-0216 Source: CCN Type: SA28498 FreeBSD pty Snooping Vulnerabilities Source: SECUNIA Type: UNKNOWN 28498 Source: CCN Type: FreeBSD-SA-08:01.pty pty snooping Source: FREEBSD Type: Patch FreeBSD-SA-08:01 Source: CCN Type: SECTRACK ID: 1019191 FreeBSD pty May Disclose Information to Local Users Source: CCN Type: OSVDB ID: 40812 FreeBSD ptsname Function Cross-User pty Information Disclosure Source: BID Type: UNKNOWN 27284 Source: CCN Type: BID-27284 FreeBSD pty Handling Multiple Local Information Disclosure Vulnerabilities Source: SECTRACK Type: UNKNOWN 1019191 Source: XF Type: UNKNOWN freebsd-ptsname-information-disclosure(39667) Source: XF Type: UNKNOWN freebsd-ptsname-information-disclosure(39667) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |