FreeBSD pty Handling Multiple Local Information Disclosure Vulnerabilities
BID:27284
Info
FreeBSD pty Handling Multiple Local Information Disclosure Vulnerabilities
| Bugtraq ID: | 27284 |
| Class: | Design Error |
| CVE: |
CVE-2008-0216 CVE-2008-0217 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 14 2008 12:00AM |
| Updated: | Jan 15 2008 06:48PM |
| Credit: | John Baldwin is credited with the discovery of these issues. |
| Vulnerable: |
FreeBSD FreeBSD 6.0 .x FreeBSD FreeBSD 6.0 -STABLE FreeBSD FreeBSD 6.0 -RELEASE FreeBSD FreeBSD 5.5 -STABLE FreeBSD FreeBSD 5.5 -RELEASE FreeBSD FreeBSD 5.4 -RELENG FreeBSD FreeBSD 5.4 -RELEASE FreeBSD FreeBSD 5.4 -PRERELEASE FreeBSD FreeBSD 5.3 -STABLE FreeBSD FreeBSD 5.3 -RELENG FreeBSD FreeBSD 5.3 -RELEASE FreeBSD FreeBSD 5.3 FreeBSD FreeBSD 5.2.1 -RELEASE FreeBSD FreeBSD 5.2 -RELENG FreeBSD FreeBSD 5.2 -RELEASE FreeBSD FreeBSD 5.2 FreeBSD FreeBSD 5.1 -RELENG FreeBSD FreeBSD 5.1 -RELEASE/Alpha FreeBSD FreeBSD 5.1 -RELEASE-p5 FreeBSD FreeBSD 5.1 -RELEASE FreeBSD FreeBSD 5.1 FreeBSD FreeBSD 5.0 -RELENG FreeBSD FreeBSD 5.0 -RELEASE-p14 FreeBSD FreeBSD 5.0 FreeBSD FreeBSD 7.0 -RELENG FreeBSD FreeBSD 7.0 -PRERELEASE FreeBSD FreeBSD 6.3 -RELENG FreeBSD FreeBSD 6.3 FreeBSD FreeBSD 6.2 -STABLE FreeBSD FreeBSD 6.2 -RELENG FreeBSD FreeBSD 6.2 FreeBSD FreeBSD 6.1 -STABLE FreeBSD FreeBSD 6.1 -RELEASE-p10 FreeBSD FreeBSD 6.1 -RELEASE FreeBSD FreeBSD 6.0 -RELEASE-p5 FreeBSD FreeBSD 5.4-STABLE |
| Not Vulnerable: | |
Discussion
FreeBSD pty Handling Multiple Local Information Disclosure Vulnerabilities
FreeBSD is prone to multiple local information-disclosure vulnerabilities due to errors in the pty-handling mechanisms.
Local attackers may exploit these issues to capture text from other users' terminals and gain access to potentially sensitive information.
The issues affect FreeBSD 5.0 and higher versions.
FreeBSD is prone to multiple local information-disclosure vulnerabilities due to errors in the pty-handling mechanisms.
Local attackers may exploit these issues to capture text from other users' terminals and gain access to potentially sensitive information.
The issues affect FreeBSD 5.0 and higher versions.
Exploit / POC
FreeBSD pty Handling Multiple Local Information Disclosure Vulnerabilities
Attackers can exploit these issues using standard tools.
Attackers can exploit these issues using standard tools.
Solution / Fix
FreeBSD pty Handling Multiple Local Information Disclosure Vulnerabilities
Solution:
The vendor released updates to address these issues. Please see the references for more information.
Solution:
The vendor released updates to address these issues. Please see the references for more information.
References
FreeBSD pty Handling Multiple Local Information Disclosure Vulnerabilities
References:
References:
- FreeBSD Homepage (FreeBSD)