The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and 8.0, when creating files during replay of a setattr transaction, uses 7777 permissions instead of the original permissions, which might allow local users to read or modify unauthorized files in opportunistic circumstances after a system crash or power failure.
                
            References
                    | Link | Resource | 
|---|---|
| http://secunia.com/advisories/38124 | Vendor Advisory | 
| http://security.FreeBSD.org/advisories/FreeBSD-SA-10:03.zfs.asc | Patch Vendor Advisory | 
| http://www.securityfocus.com/bid/37657 | |
| http://www.securitytracker.com/id?1023407 | |
| http://secunia.com/advisories/38124 | Vendor Advisory | 
| http://security.FreeBSD.org/advisories/FreeBSD-SA-10:03.zfs.asc | Patch Vendor Advisory | 
| http://www.securityfocus.com/bid/37657 | |
| http://www.securitytracker.com/id?1023407 | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 01:11
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://secunia.com/advisories/38124 - Vendor Advisory | |
| References | () http://security.FreeBSD.org/advisories/FreeBSD-SA-10:03.zfs.asc - Patch, Vendor Advisory | |
| References | () http://www.securityfocus.com/bid/37657 - | |
| References | () http://www.securitytracker.com/id?1023407 - | 
Information
                Published : 2010-01-15 18:30
Updated : 2025-04-09 00:30
NVD link : CVE-2010-0318
Mitre link : CVE-2010-0318
CVE.ORG link : CVE-2010-0318
JSON object : View
Products Affected
                freebsd
- freebsd
 
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
