FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
http://www.ciac.org/ciac/bulletins/i-057.shtml | third party advisory government resource broken link |
http://www.osvdb.org/6090 | vdb entry broken link |