jail.c in jail in FreeBSD 8.0 and 8.1-PRERELEASE, when the "-l -U root" options are omitted, does not properly restrict access to the current working directory, which might allow local users to read, modify, or create arbitrary files via standard filesystem operations.
References
| Link | Resource |
|---|---|
| http://security.FreeBSD.org/advisories/FreeBSD-SA-10:04.jail.asc | Vendor Advisory |
| http://securitytracker.com/id?1024038 | |
| http://www.securityfocus.com/bid/40399 | |
| http://www.vupen.com/english/advisories/2010/1247 | Patch Vendor Advisory |
| http://security.FreeBSD.org/advisories/FreeBSD-SA-10:04.jail.asc | Vendor Advisory |
| http://securitytracker.com/id?1024038 | |
| http://www.securityfocus.com/bid/40399 | |
| http://www.vupen.com/english/advisories/2010/1247 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2010-05-28 18:30
Updated : 2025-04-11 00:51
NVD link : CVE-2010-2022
Mitre link : CVE-2010-2022
CVE.ORG link : CVE-2010-2022
JSON object : View
Products Affected
freebsd
- freebsd
CWE
CWE-264
Permissions, Privileges, and Access Controls
