CVE Vulnerabilities

CVE-2008-0777

Published: Feb 15, 2008 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:L/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 5.5 (including) 5.5 (including)
Freebsd Freebsd 6.2 (including) 6.2 (including)
Freebsd Freebsd 6.3 (including) 6.3 (including)
Freebsd Freebsd 7.0 (including) 7.0 (including)
Kfreebsd-5 Ubuntu dapper *
Kfreebsd-5 Ubuntu edgy *
Kfreebsd-5 Ubuntu feisty *
Kfreebsd-5 Ubuntu gutsy *
Kfreebsd-5 Ubuntu hardy *
Kfreebsd-5 Ubuntu intrepid *

References