CVE-2025-0374
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 30, 2025
Updated: Feb 7, 2025
CWE ID 732
Summary
CVE-2025-0374 is a vulnerability affecting etcupdate's handling of file conflicts during system updates. When etcupdate encounters conflicts, it saves a version with conflict markers in a world-readable directory, potentially exposing encrypted root and user passwords from the temporary master.passwd file. This occurs only when conflicts arise within password files and are resolved, resulting in the deletion of the unprotected file.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- FreeBSD
Affected Vendors
- FreeBSD Project