FreeBSD ZFS ZIL Insecure File Permissions Vulnerability
BID:37657
Info
FreeBSD ZFS ZIL Insecure File Permissions Vulnerability
| Bugtraq ID: | 37657 |
| Class: | Design Error |
| CVE: |
CVE-2010-0318 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 06 2010 12:00AM |
| Updated: | Apr 13 2015 09:03PM |
| Credit: | Pawel Jakub Dawidek |
| Vulnerable: |
FreeBSD FreeBSD 8.0-STABLE FreeBSD FreeBSD 8.0-RELEASE FreeBSD FreeBSD 7.2-STABLE FreeBSD FreeBSD 7.1-STABLE FreeBSD FreeBSD 7.0-STABLE FreeBSD FreeBSD 6.4 -STABLE |
| Not Vulnerable: | |
Discussion
FreeBSD ZFS ZIL Insecure File Permissions Vulnerability
The ZFS Intent Log (ZIL) for FreeBSD is prone to a security vulnerability because it sets insecure file permissions.
An attacker can exploit this issue to obtain sensitive information or gain escalated privileges.
The ZFS Intent Log (ZIL) for FreeBSD is prone to a security vulnerability because it sets insecure file permissions.
An attacker can exploit this issue to obtain sensitive information or gain escalated privileges.
Exploit / POC
FreeBSD ZFS ZIL Insecure File Permissions Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
FreeBSD ZFS ZIL Insecure File Permissions Vulnerability
Solution:
Vendor patches are available. Please see the references for details.
Solution:
Vendor patches are available. Please see the references for details.