VulnerabilityModified
CVE-2005-4351
The securelevels implementation in FreeBSD 7.0 and earlier, OpenBSD up to 3.8, DragonFly up to 1.2, and Linux up to 2.6.15 allows root users to bypass immutable settings for files by mounting another filesystem that masks the immutable files while the…
MEDIUM 4.3EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
The securelevels implementation in FreeBSD 7.0 and earlier, OpenBSD up to 3.8, DragonFly up to 1.2, and Linux up to 2.6.15 allows root users to bypass immutable settings for files by mounting another filesystem that masks the immutable files while the system is running.
- CVSS 2.0
- 4.3 MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Affected
- dragonfly/dragonfly · freebsd/freebsd · linux/linux kernel · openbsd/openbsd
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/openbsd/2005-10/1523.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041177.htmlExploit, Vendor Advisory
- http://www.redteam-pentesting.de/advisories/rt-sa-2005-015.txtExploit, Vendor Advisory
- http://www.redteam-pentesting.de/advisories/rt-sa-2005-15.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24037
- http://archives.neohapsis.com/archives/openbsd/2005-10/1523.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041177.htmlExploit, Vendor Advisory
- http://www.redteam-pentesting.de/advisories/rt-sa-2005-015.txtExploit, Vendor Advisory
- http://www.redteam-pentesting.de/advisories/rt-sa-2005-15.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24037
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.