CVE-2008-0777 Information

Description

The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file which allows local users to read the contents of write-only files.

Reference

http://secunia.com/advisories/28928 http://security.freebsd.org/advisories/FreeBSD-SA-08:03.sendfile.asc http://securitytracker.com/id?1019416 http://www.securityfocus.com/bid/27789

Share on: