CWEBaseDraft3 recent CVEs

CWE-403Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')

Description

A process does not close sensitive file descriptors before invoking a child process, which allows the child to perform unauthorized I/O operations using those descriptors.

When a new process is forked or executed, the child process inherits any open file descriptors. When the child process has fewer privileges than the parent process, this might introduce a vulnerability if the child process can access the file descriptor but does not have the privileges to access the associated file.

Common consequences

Related CWEs

Recent CVEs classified under this CWE