Executive brief
A vulnerability in the FreeBSD operating system's file handling mechanism could allow a local user to modify files they should not have access to. This issue affects the core system function used to open files, potentially allowing an attacker to corrupt system data or alter configuration files. While the impact is limited to users who already have access to the system, it represents a breakdown in the security boundaries intended to protect sensitive data.
Technical details
A vulnerability exists in the FreeBSD implementation of the open() system call. Due to improper validation or handling within the kernel-level file opening routine, a local attacker with existing system access can bypass standard permission checks to write data to arbitrary files. This is classified as an improper file access or permission bypass issue. Exploitation requires local access to the system and can result in unauthorized data modification or system instability, though it does not inherently grant elevated privileges or remote access.
Affected products
- FreeBSD FreeBSD
Timeline
- 1997-10-29: disclosed: Initial publication date in NVD.