The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting, which allows context-dependent attackers to bypass intended restrictions by leveraging a jailed device node process.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1030171 | vdb entry |
http://www.securityfocus.com/bid/67158 | vdb entry |
http://www.freebsd.org/security/advisories/FreeBSD-SA-14:07.devfs.asc | vendor advisory |