CVE Vulnerabilities

CVE-2008-0216

Published: Jan 16, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user.

Affected Software

NameVendorStart VersionEnd Version
FreebsdFreebsd6.0 (including)6.0 (including)
FreebsdFreebsd6.0-release (including)6.0-release (including)
FreebsdFreebsd6.0-stable (including)6.0-stable (including)
FreebsdFreebsd6.1 (including)6.1 (including)
FreebsdFreebsd6.1-release (including)6.1-release (including)
FreebsdFreebsd6.1-release_p10 (including)6.1-release_p10 (including)
FreebsdFreebsd6.1-stable (including)6.1-stable (including)
FreebsdFreebsd6.2 (including)6.2 (including)
FreebsdFreebsd6.2-stable (including)6.2-stable (including)
FreebsdFreebsd6.3 (including)6.3 (including)
FreebsdFreebsd7.0 (including)7.0 (including)
FreebsdFreebsd7.0-current (including)7.0-current (including)
FreebsdFreebsd7.0-pre-release (including)7.0-pre-release (including)
Kfreebsd-5Ubuntudapper*
Kfreebsd-5Ubuntuedgy*
Kfreebsd-5Ubuntufeisty*
Kfreebsd-5Ubuntugutsy*
Kfreebsd-5Ubuntuhardy*
Kfreebsd-5Ubuntuintrepid*

References