CVE-2010-2022
N/A
N/A
Summary
jail.c in jail in FreeBSD 8.0 and 8.1-PRERELEASE, when the "-l -U root" options are omitted, does not properly restrict access to the current working directory, which might allow local users to read, modify, or create arbitrary files via standard filesystem operations.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.vupen.com/english/advisories/2010/1247
- http://security.FreeBSD.org/advisories/FreeBSD-SA-10:04.jail.asc
- http://www.securityfocus.com/bid/40399
- http://securitytracker.com/id?1024038
References
- http://www.vupen.com/english/advisories/2010/1247
- http://security.FreeBSD.org/advisories/FreeBSD-SA-10:04.jail.asc
- http://www.securityfocus.com/bid/40399
- http://securitytracker.com/id?1024038
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.