Description

When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version does not preserve the mode of the input file, and is world-readable. This applies to files that would normally have restricted visibility, such as /etc/master.passwd. An unprivileged local user may be able to read encrypted root and user passwords from the temporary master.passwd file created in /var/db/etcupdate/conflicts. This is possible only when conflicts within the password file arise during an update, and the unprotected file is deleted when conflicts are resolved.

INFO

Published Date :

2025-01-30T04:49:07.687Z

Last Modified :

2025-02-07T17:02:52.274Z

Source :

freebsd
AFFECTED PRODUCTS

The following products are affected by CVE-2025-0374 vulnerability.

Vendors Products
Freebsd
  • Freebsd
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-0374.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact