#VU42540 Permissions, Privileges, and Access Controls in FreeBSD - CVE-2013-5710
Published: September 23, 2013 / Updated: August 10, 2020
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The nullfs implementation in sys/fs/nullfs/null_vnops.c in the kernel in FreeBSD 8.3 through 9.2 allows local users with certain permissions to bypass access restrictions via a hardlink in a nullfs instance to a file in a different instance.