The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: freebsd
Published: 2008-01-16T01:00:00
Updated: 2017-08-07T12:57:01
Reserved: 2008-01-10T00:00:00
Link: CVE-2008-0217
JSON object: View
NVD Information
Status : Modified
Published: 2008-01-16T02:00:00.000
Modified: 2017-08-08T01:29:24.320
Link: CVE-2008-0217
JSON object: View
Redhat Information
No data.
CWE