CVE-2008-0217
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
16/01/2008
Last modified:
09/04/2025
Description
The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script.
Impact
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:freebsd:freebsd:5.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:5.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:6.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:6.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:6.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:7.0:pre-release:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/28498
- http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc
- http://www.securityfocus.com/bid/27284
- http://www.securitytracker.com/id?1019191=
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39665
- http://secunia.com/advisories/28498
- http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc
- http://www.securityfocus.com/bid/27284
- http://www.securitytracker.com/id?1019191=
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39665



