FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems,...
Vulnerability Description
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2002-0572
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.iss.net/security_center/static/8920.php
- http://www.securityfocus.com/bid/4568
- http://www.kb.cert.org/vuls/id/809347
- http://www.osvdb.org/6095
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0033.html
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:23.stdio.asc
- http://www.ciac.org/ciac/bulletins/m-072.shtml
- http://online.securityfocus.com/archive/1/268970
- http://online.securityfocus.com/archive/1/269102
More from freebsd
View All →Affected Vendor
freebsd
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.