VulnerabilityModified
CVE-2008-0777
The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files.
MEDIUM 4.9EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files.
- CVSS 2.0
- 4.9 MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
- EPSS
- 0.41% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- freebsd/freebsd
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/28928Vendor Advisory
- http://security.freebsd.org/advisories/FreeBSD-SA-08:03.sendfile.ascPatch
- http://securitytracker.com/id?1019416
- http://www.securityfocus.com/bid/27789Exploit, Patch
- http://secunia.com/advisories/28928Vendor Advisory
- http://security.freebsd.org/advisories/FreeBSD-SA-08:03.sendfile.ascPatch
- http://securitytracker.com/id?1019416
- http://www.securityfocus.com/bid/27789Exploit, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.