4.7
CVSSv2

CVE-2009-4358

Published: 20/12/2009 Updated: 21/12/2009
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
VMScore: 418
Vector: AV:L/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

freebsd-update in FreeBSD 8.0, 7.2, 7.1, 6.4, and 6.3 uses insecure permissions in its working directory (/var/db/freebsd-update by default), which allows local users to read copies of sensitive files after a (1) freebsd-update fetch (fetch) or (2) freebsd-update upgrade (upgrade) operation.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 8.0

freebsd freebsd 7.2

freebsd freebsd 7.1

freebsd freebsd 6.4

freebsd freebsd 6.3