PT-2004-1317 · Freebsd · Freebsd
Published
2004-03-29
·
Updated
2017-10-10
·
CVE-2004-0126
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions 5.1 through 5.2
Description
The issue allows local users to gain read/write privileges to files and directories within another jail by exploiting the jail attach system call, which changes the directory of a calling process even without proper permission.
Recommendations
For FreeBSD versions 5.1 through 5.2, update to a version where this issue is fixed to prevent unauthorized access to files and directories within another jail.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd