FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

FreeBSD -- ZFS ZIL playback with insecure permissions

Affected packages
7.1 <= FreeBSD < 7.1_10
7.2 <= FreeBSD < 7.2_6
8.0 <= FreeBSD < 8.0_2

Details

VuXML ID 97f09f2f-ca3f-11df-aade-0050568f000c
Discovery 2010-01-06
Entry 2010-10-24
Modified 2016-08-09

Problem Description:

When replaying setattr transaction, the replay code would set the attributes with certain insecure defaults, when the logged transaction did not touch these attributes.

References

FreeBSD Advisory SA-10:03.zfs