CVE-2010-0318

FreeBSD 7.1, 7.2, and 8.0 - Unauthorized File Access via ZFS Intent Log Replay

Title source: llm
STIX 2.1

Description

The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and 8.0, when creating files during replay of a setattr transaction, uses 7777 permissions instead of the original permissions, which might allow local users to read or modify unauthorized files in opportunistic circumstances after a system crash or power failure.

References (4)

Core 4
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38124
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37657
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1023407
Patch, Vendor Advisory vendor-advisory x_refsource_freebsd
http://security.FreeBSD.org/advisories/FreeBSD-SA-10:03.zfs.asc

Scores

EPSS 0.0003
EPSS Percentile 10.3%

Details

CWE
CWE-264
Status published
Products (3)
freebsd/freebsd 7.1
freebsd/freebsd 7.2
freebsd/freebsd 8.0
Published Jan 15, 2010
Tracked Since Feb 18, 2026