跳转到帖子

FreeBSD: VID-FA9AE646-DEBC-11EF-87BA-002590C1F29C (CVE-2025-0374): FreeBSD -- Unprivileged access to system files

recommended_posts

发布于
  • Members

FreeBSD: VID-FA9AE646-DEBC-11EF-87BA-002590C1F29C (CVE-2025-0374): FreeBSD -- Unprivileged access to system files

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
01/29/2025
Created
02/04/2025
Added
01/31/2025
Modified
01/31/2025

Description

When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts.This version does not preserve the mode of the input file, and is world-readable.This applies to files that would normally have restricted visibility, such as /etc/master.passwd.

An unprivileged local user may be able to read encrypted root and user passwords from the temporary master.passwd file created in /var/db/etcupdate/conflicts.This is possible only when conflicts within the password file arise during an update, and the unprotected file is deleted when conflicts are resolved.

Solution(s)

  • freebsd-upgrade-base-13_4-release-p3
  • freebsd-upgrade-base-14_1-release-p7
  • freebsd-upgrade-base-14_2-release-p1

References

  • CVE-2025-0374
  • 查看数 723
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…