CVE-2010-2022

NameCVE-2010-2022
Descriptionjail.c in jail in FreeBSD 8.0 and 8.1-PRERELEASE, when the "-l -U root" options are omitted, does not properly restrict access to the current working directory, which might allow local users to read, modify, or create arbitrary files via standard filesystem operations.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kfreebsd-6source(unstable)(not affected)
kfreebsd-7source(unstable)(not affected)
kfreebsd-8source(unstable)(not affected)

Notes

- kfreebsd-6 <not-affected> (jail binary not yet provided, see bug #584930)
- kfreebsd-7 <not-affected> (jail binary not yet provided, see bug #584930)
- kfreebsd-8 <not-affected> (jail binary not yet provided, see bug #584930)

Search for package or bug name: Reporting problems