Total vulnerabilities in the database
The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive key information by reading the file.
Software | From | Fixed in |
---|---|---|
freebsd / freebsd | 10.0 | 10.0.x |
freebsd / freebsd | - | 10.1.x |
freebsd / freebsd | 10.1-rc4 | 10.1-rc4.x |
freebsd / freebsd | 10.1-rc2 | 10.1-rc2.x |
freebsd / freebsd | 10.1-rc3 | 10.1-rc3.x |
freebsd / freebsd | 10.0-rc1 | 10.0-rc1.x |
freebsd / freebsd | 10.1-rc1 | 10.1-rc1.x |
freebsd / freebsd | 10.0-rc2 | 10.0-rc2.x |