FreeBSD 'sendfile(2)' Write-Only File Permission Security Bypass Vulnerability
BID:27789
Info
FreeBSD 'sendfile(2)' Write-Only File Permission Security Bypass Vulnerability
| Bugtraq ID: | 27789 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-0777 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 14 2008 12:00AM |
| Updated: | Feb 14 2008 10:26PM |
| Credit: | Kostik Belousov is credited with the discovery of this vulnerability. |
| Vulnerable: |
FreeBSD FreeBSD 7.0 FreeBSD FreeBSD 6.3 FreeBSD FreeBSD 6.2 FreeBSD FreeBSD 5.5 |
| Not Vulnerable: | |
Discussion
FreeBSD 'sendfile(2)' Write-Only File Permission Security Bypass Vulnerability
FreeBSD is prone to a security-bypass vulnerability because the kernel fails to validate file permissions.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
FreeBSD is prone to a security-bypass vulnerability because the kernel fails to validate file permissions.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
Exploit / POC
FreeBSD 'sendfile(2)' Write-Only File Permission Security Bypass Vulnerability
To exploit this issue, an attacker would only need to create a program that invokes the 'sendfile(2)' system call.
To exploit this issue, an attacker would only need to create a program that invokes the 'sendfile(2)' system call.
Solution / Fix
FreeBSD 'sendfile(2)' Write-Only File Permission Security Bypass Vulnerability
Solution:
The vendor released patches and an advisory to address this issue. Please see the references for more information.
FreeBSD FreeBSD 6.2
FreeBSD FreeBSD 5.5
FreeBSD FreeBSD 6.3
FreeBSD FreeBSD 7.0
Solution:
The vendor released patches and an advisory to address this issue. Please see the references for more information.
FreeBSD FreeBSD 6.2
-
FreeBSD SA-08:03/sendfile.patch
http://security.FreeBSD.org/patches/SA-08:03/sendfile.patch
FreeBSD FreeBSD 5.5
-
FreeBSD SA-08:03/sendfile55.patch
http://security.FreeBSD.org/patches/SA-08:03/sendfile55.patch
FreeBSD FreeBSD 6.3
-
FreeBSD SA-08:03/sendfile.patch
http://security.FreeBSD.org/patches/SA-08:03/sendfile.patch
FreeBSD FreeBSD 7.0
-
FreeBSD SA-08:03/sendfile.patch
http://security.FreeBSD.org/patches/SA-08:03/sendfile.patch
References
FreeBSD 'sendfile(2)' Write-Only File Permission Security Bypass Vulnerability
References:
References:
- FreeBSD Homepage (FreeBSD)