CVE-2025-0374 Details
Description
When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version does not preserve the mode of the input file, and is world-readable. This applies to files that would normally have restricted visibility, such as /etc/master.passwd. An unprivileged local user may be able to read encrypted root and user passwords from the temporary master.passwd file created in /var/db/etcupdate/conflicts. This is possible only when conflicts within the password file arise during an update, and the unprotected file is deleted when conflicts are resolved.
A vulnerability exists in the FreeBSD etcupdate utility, which is used to manage updates to system files. When etcupdate encounters conflicts while merging files, it creates a temporary version in /var/db/etcupdate/conflicts that contains conflict markers. This version is world-readable and does not preserve the original file permissions, potentially exposing sensitive information from files that typically have restricted access, such as /etc/master.passwd. An unprivileged local user could exploit this to read encrypted passwords for root and other users, but only if conflicts arise in the password file during an update, and the unprotected file is not deleted after the conflicts are resolved.
Users can upgrade to a supported FreeBSD stable or release branch dated after the correction date. Instructions for updating via the FreeBSD Update utility or applying a source code patch are available in the FreeBSD Security Advisory.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 30, 2025CISA-ADP
Assessed Feb 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.netapp.com/advisory/ntap-20250207-0007/ | CVE | AdvisoryVendor |
| https://security.freebsd.org/advisories/FreeBSD-SA-25:03.etcupdate.asc | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| FreeBSD | >= 14, < 14.2-RELEASE-p1 >= 14.1-RELEASE, < 14.1-RELEASE-p7 >= 13, < 13.4-RELEASE-p3 |
CPE
Remediation
| |
| NetApp ONTAP | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 7, 2025 | CVE Modified | CVE |
| Feb 5, 2025 | CVE Modified | CISA-ADP |
| Jan 30, 2025 | New CVE Received | [email protected] |
Volerion