Show plain JSON{"id": "CVE-2008-0217", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 6.9, "accessVector": "LOCAL", "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C", "authentication": "NONE", "integrityImpact": "COMPLETE", "accessComplexity": "MEDIUM", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 3.4, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2008-01-16T02:00:00.000", "references": [{"url": "http://secunia.com/advisories/28498", "source": "secteam@freebsd.org"}, {"url": "http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc", "tags": ["Patch"], "source": "secteam@freebsd.org"}, {"url": "http://www.securityfocus.com/bid/27284", "source": "secteam@freebsd.org"}, {"url": "http://www.securitytracker.com/id?1019191", "source": "secteam@freebsd.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39665", "source": "secteam@freebsd.org"}, {"url": "http://secunia.com/advisories/28498", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc", "tags": ["Patch"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/27284", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securitytracker.com/id?1019191", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39665", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-264"}]}], "descriptions": [{"lang": "en", "value": "The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script."}, {"lang": "es", "value": "La secuencia de comandos en FreeBSD 5.0 hasta 7.0-PRERELEASE llama a openpty, el cual crea un pseudo-terminal con permisos: lectura-todos y escritura-todos cuando no est\u00e1 funcionando como root, lo cual permite a usuarios locales leer datos desde el terminal del usuario ejecutando la secuencia de comandos."}], "lastModified": "2025-04-09T00:30:58.490", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:freebsd:freebsd:5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "61EBA52A-2D8B-4FB5-866E-AE67CE1842E7"}, {"criteria": "cpe:2.3:o:freebsd:freebsd:5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7752D43D-64AF-474F-BFBB-2625A29C1B88"}, {"criteria": "cpe:2.3:o:freebsd:freebsd:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D2C79D5-D27F-4B08-A8DF-3E3AAF4E16A5"}, {"criteria": "cpe:2.3:o:freebsd:freebsd:6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F4416CBA-76B9-4051-B015-F1BE89517309"}, {"criteria": "cpe:2.3:o:freebsd:freebsd:6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9118B602-3FB6-4701-AC09-763DD48334BA"}, {"criteria": "cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47E0A416-733A-4616-AE08-150D67FCEA70"}, {"criteria": "cpe:2.3:o:freebsd:freebsd:7.0:pre-release:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "42231BCC-2B90-4196-A1C2-408A353C1BEF"}], "operator": "OR"}]}], "sourceIdentifier": "secteam@freebsd.org"}