The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freebsd | Freebsd | 5.5 (including) | 5.5 (including) |
Freebsd | Freebsd | 6.2 (including) | 6.2 (including) |
Freebsd | Freebsd | 6.3 (including) | 6.3 (including) |
Freebsd | Freebsd | 7.0 (including) | 7.0 (including) |
Kfreebsd-5 | Ubuntu | dapper | * |
Kfreebsd-5 | Ubuntu | edgy | * |
Kfreebsd-5 | Ubuntu | feisty | * |
Kfreebsd-5 | Ubuntu | gutsy | * |
Kfreebsd-5 | Ubuntu | hardy | * |
Kfreebsd-5 | Ubuntu | intrepid | * |