CVE-2010-2022

jail.c in jail in FreeBSD 8.0 and 8.1-PRERELEASE, when the "-l -U root" options are omitted, does not properly restrict access to the current working directory, which might allow local users to read, modify, or create arbitrary files via standard filesystem operations.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:freebsd:freebsd:8.0:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:8.1-prerelease:*:*:*:*:*:*:*

History

21 Nov 2024, 01:15

Type Values Removed Values Added
References () http://security.FreeBSD.org/advisories/FreeBSD-SA-10:04.jail.asc - Vendor Advisory () http://security.FreeBSD.org/advisories/FreeBSD-SA-10:04.jail.asc - Vendor Advisory
References () http://securitytracker.com/id?1024038 - () http://securitytracker.com/id?1024038 -
References () http://www.securityfocus.com/bid/40399 - () http://www.securityfocus.com/bid/40399 -
References () http://www.vupen.com/english/advisories/2010/1247 - Patch, Vendor Advisory () http://www.vupen.com/english/advisories/2010/1247 - Patch, Vendor Advisory

Information

Published : 2010-05-28 18:30

Updated : 2024-11-21 01:15


NVD link : CVE-2010-2022

Mitre link : CVE-2010-2022

CVE.ORG link : CVE-2010-2022


JSON object : View

Products Affected

freebsd

  • freebsd
CWE
CWE-264

Permissions, Privileges, and Access Controls