« Volver al listado

CVE-2008-0216

Estado: ModificadaBaja (2.1)—

The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-0216",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secteam@freebsd.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-01-16T02:00:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/28498",
      "source": "secteam@freebsd.org"
    },
    {
      "url": "http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc",
      "tags": [
        "Patch"
      ],
      "source": "secteam@freebsd.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/27284",
      "source": "secteam@freebsd.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1019191",
      "source": "secteam@freebsd.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39667",
      "source": "secteam@freebsd.org"
    },
    {
      "url": "http://secunia.com/advisories/28498",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/27284",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1019191",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39667",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user."
    },
    {
      "lang": "es",
      "value": "La función ptsname en FreeBSD 6.0 hasta el 7.0-PRERELEASE no verifica de forma adecuada que una cierta porción de un nombre de dispositivo está asociado con un pty de un usuario quien está llamando a la función, la cual podría permitir a usuarios locales leer datos del pty desde otro usuario."
    }
  ],
  "lastModified": "2026-06-16T22:49:09.303",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D2C79D5-D27F-4B08-A8DF-3E3AAF4E16A5"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:6.0:release:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CCE4F2E6-2286-4D87-ADD7-7E999B4E5620"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:6.0:stable:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C07C3BEF-8D6A-4F23-96DE-AFE4369D08EF"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4416CBA-76B9-4051-B015-F1BE89517309"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:6.1:release:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C64EE9C-18E1-49C6-96DE-7E6F1607C0D7"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:6.1:release_p10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B36B3805-8A85-4357-ABC1-AB22C61E3381"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:6.1:stable:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "231B70A8-890A-4790-A33A-64228656BF0E"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:6.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9118B602-3FB6-4701-AC09-763DD48334BA"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:6.2:stable:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32FCB0B3-8FBE-49FA-B17E-0D5462C9E5B4"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F702C46F-CA02-4FA2-B7D6-C61C2C095679"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47E0A416-733A-4616-AE08-150D67FCEA70"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:7.0:current:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4E775BA-6DC1-4006-83A4-D30EA57417FC"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:7.0:pre-release:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42231BCC-2B90-4196-A1C2-408A353C1BEF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secteam@freebsd.org"
}