CVE-2025-0374 – Pi Viola etcupdate Etcupdate Version Preservation Vulnerability

The following table lists the changes that have been made to the
CVE-2025-0374 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 30, 2025

    Action Type Old Value New Value
    Added Description When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version does not preserve the mode of the input file, and is world-readable. This applies to files that would normally have restricted visibility, such as /etc/master.passwd.

    An unprivileged local user may be able to read encrypted root and user passwords from the temporary master.passwd file created in /var/db/etcupdate/conflicts. This is possible only when conflicts within the password file arise during an update, and the unprotected file is deleted when conflicts are resolved.

    Added CWE CWE-732
    Added Reference https://security.freebsd.org/advisories/FreeBSD-SA-25:03.etcupdate.asc
Share the Post:

Related Posts