The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files.
Exploitability
AV:LAC:LAu:NImpact
C:CI:NA:N4.9/AV:L/AC:L/Au:N/C:C/I:N/A:N