2.1
CVSSv2

CVE-2015-1415

Published: 10/04/2015 Updated: 09/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The bsdinstall installer in FreeBSD 10.x prior to 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive key information by reading the file.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 10.0

freebsd freebsd

freebsd freebsd 10.1

Exploits

FreeBSD 10x installer supports the installation of FreeBSD 10x on an encrypted ZFS filesystem by default When using the encryption system within ZFS during the installation of FreeBSD 100 and FreeBSD 101, the encryptionkey has wrong permissions which allow local users to read this file Even if the keyfile is passphrase-encrypted, it can pres ...