CVE detail
CVE-2009-4358 — CVE-2009-4358
Published 2009-12-20 · Modified 2026-06-16 · Vendor freebsd · Product freebsd · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0027
EPSS probability
exploitation probability, 30d
19.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
freebsd-update in FreeBSD 8.0, 7.2, 7.1, 6.4, and 6.3 uses insecure permissions in its working directory (/var/db/freebsd-update by default), which allows local users to read copies of sensitive files after a (1) freebsd-update fetch (fetch) or (2) freebsd-update upgrade (upgrade) operation.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References