The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/28498 | third party advisory |
http://www.securitytracker.com/id?1019191 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39665 | vdb entry |
http://www.securityfocus.com/bid/27284 | vdb entry |
http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc | patch vendor advisory |