FreeBSD is a freely available, open source clone of the Unix Operating System. It is maintained by the FreeBSD project. When pkg_add is executed, the directory the contents of the package are extracted to is created with permissions of 755. With this permission set, it is possible for a local user to descend the directory tree. In the event that any subdirectories have been created with world-writable permissions, the user could either remove the data in those directories, or trojan the files to later gain elevated privileges.
FreeBSD is a freely available, open source clone of the Unix Operating System. It is maintained by the FreeBSD project. When pkg_add is executed, the directory the contents of the package are extracted to is created with permissions of 755. With this permission set, it is possible for a local user to descend the directory tree. In the event that any subdirectories have been created with world-writable permissions, the user could either remove the data in those directories, or trojan the files to later gain elevated privileges.