CVE-2008-0777
The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files.
Date published : 2008-02-14
http://www.securityfocus.com/bid/27789
http://security.freebsd.org/advisories/FreeBSD-SA-08:03.sendfile.asc