« Volver al listado

CVE-2025-0374

Estado: AplazadaMedia (6.5)—

When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version does not preserve the mode of the input file, and is world-readable. This applies to files that would normally have restricted visibility, such as /etc/master.passwd.

An unprivileged local user may be able to read encrypted root and user passwords from the temporary master.passwd file created in /var/db/etcupdate/conflicts. This is possible only when conflicts within the password file arise during an update, and the unprotected file is deleted when conflicts are resolved.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-0374",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-0374",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-05T15:41:16.838358Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "secteam@freebsd.org",
      "affectedData": [
        {
          "vendor": "FreeBSD",
          "modules": [
            "etcupdate"
          ],
          "product": "FreeBSD",
          "versions": [
            {
              "status": "affected",
              "version": "14.2-RELEASE",
              "lessThan": "p1",
              "versionType": "release"
            },
            {
              "status": "affected",
              "version": "14.1-RELEASE",
              "lessThan": "p7",
              "versionType": "release"
            },
            {
              "status": "affected",
              "version": "13.4-RELEASE",
              "lessThan": "p3",
              "versionType": "release"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2025-01-30T05:15:10.527",
  "references": [
    {
      "url": "https://security.freebsd.org/advisories/FreeBSD-SA-25:03.etcupdate.asc",
      "source": "secteam@freebsd.org"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20250207-0007/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secteam@freebsd.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts.  This version does not preserve the mode of the input file, and is world-readable.  This applies to files that would normally have restricted visibility, such as /etc/master.passwd.\n\nAn unprivileged local user may be able to read encrypted root and user passwords from the temporary master.passwd file created in /var/db/etcupdate/conflicts.  This is possible only when conflicts within the password file arise during an update, and the unprotected file is deleted when conflicts are resolved."
    },
    {
      "lang": "es",
      "value": "Cuando etcupdate encuentra conflictos al fusionar archivos, guarda una versión que contiene marcadores de conflicto en /var/db/etcupdate/conflicts. Esta versión no conserva el modo del archivo de entrada y es legible por todo el mundo. Esto se aplica a archivos que normalmente tendrían visibilidad restringida, como /etc/master.passwd. Un usuario local sin privilegios puede leer contraseñas de usuario y raíz cifradas desde el archivo temporal master.passwd manipulado en /var/db/etcupdate/conflicts. Esto es posible solo cuando surgen conflictos dentro del archivo de contraseñas durante una actualización y el archivo desprotegido se elimina cuando se resuelven los conflictos."
    }
  ],
  "lastModified": "2026-06-17T08:26:22.460",
  "sourceIdentifier": "secteam@freebsd.org"
}