The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/28498 | third party advisory |
http://www.securitytracker.com/id?1019191 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39667 | vdb entry |
http://www.securityfocus.com/bid/27284 | vdb entry |
http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc | patch vendor advisory |