CVE-2007-0166

Current Description

The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack.

Basic Data

PublishedJanuary 11, 2007
Last ModifiedNovember 15, 2008
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeNVD-CWE-Other
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:L/AC:M/Au:S/C:C/I:C/A:C
CVSS 2 - Access VectorLOCAL
CVSS 2 - Access ComplexityMEDIUM
CVSS 2 - AuthenticationSINGLE
CVSS 2 - Confidentiality ImpactCOMPLETE
CVSS 2 - Availability ImpactCOMPLETE
CVSS 2 - Base Score6.6
SeverityMEDIUM
Exploitability Score2.7
Impact Score10.0
Obtain All Privilegetrue
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3OSFreebsdFreebsd5.3*******
    2.3OSFreebsdFreebsd********6.2

Vulnerable Software List

VendorProductVersions
Freebsd Freebsd *, 5.3

References

NameSourceURLTags
32726http://osvdb.org/32726OSVDB
23730http://secunia.com/advisories/23730SECUNIA
FreeBSD-SA-07:01http://security.freebsd.org/advisories/FreeBSD-SA-07:01.jail.ascFREEBSDExploit Vendor Advisory
1017505http://securitytracker.com/id?1017505SECTRACK
22011http://www.securityfocus.com/bid/22011BID