CVE Vulnerabilities

CVE-2009-4358

Published: Dec 20, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.7 MEDIUM
AV:L/AC:M/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

freebsd-update in FreeBSD 8.0, 7.2, 7.1, 6.4, and 6.3 uses insecure permissions in its working directory (/var/db/freebsd-update by default), which allows local users to read copies of sensitive files after a (1) freebsd-update fetch (fetch) or (2) freebsd-update upgrade (upgrade) operation.

Affected Software

NameVendorStart VersionEnd Version
FreebsdFreebsd6.3 (including)6.3 (including)
FreebsdFreebsd6.4 (including)6.4 (including)
FreebsdFreebsd7.1 (including)7.1 (including)
FreebsdFreebsd7.2 (including)7.2 (including)
FreebsdFreebsd8.0 (including)8.0 (including)

References