CVE Vulnerabilities

CVE-2008-0777

Published: Feb 15, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:L/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files.

Affected Software

NameVendorStart VersionEnd Version
FreebsdFreebsd5.5 (including)5.5 (including)
FreebsdFreebsd6.2 (including)6.2 (including)
FreebsdFreebsd6.3 (including)6.3 (including)
FreebsdFreebsd7.0 (including)7.0 (including)
Kfreebsd-5Ubuntudapper*
Kfreebsd-5Ubuntuedgy*
Kfreebsd-5Ubuntufeisty*
Kfreebsd-5Ubuntugutsy*
Kfreebsd-5Ubuntuhardy*
Kfreebsd-5Ubuntuintrepid*

References