jail.c in jail in FreeBSD 8.0 and 8.1-PRERELEASE, when the "-l -U root" options are omitted, does not properly restrict access to the current working directory, which might allow local users to read, modify, or create arbitrary files via standard filesystem operations.
                
            References
                    | Link | Resource | 
|---|---|
| http://security.FreeBSD.org/advisories/FreeBSD-SA-10:04.jail.asc | Vendor Advisory | 
| http://securitytracker.com/id?1024038 | |
| http://www.securityfocus.com/bid/40399 | |
| http://www.vupen.com/english/advisories/2010/1247 | Patch Vendor Advisory | 
| http://security.FreeBSD.org/advisories/FreeBSD-SA-10:04.jail.asc | Vendor Advisory | 
| http://securitytracker.com/id?1024038 | |
| http://www.securityfocus.com/bid/40399 | |
| http://www.vupen.com/english/advisories/2010/1247 | Patch Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 01:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://security.FreeBSD.org/advisories/FreeBSD-SA-10:04.jail.asc - Vendor Advisory | |
| References | () http://securitytracker.com/id?1024038 - | |
| References | () http://www.securityfocus.com/bid/40399 - | |
| References | () http://www.vupen.com/english/advisories/2010/1247 - Patch, Vendor Advisory | 
Information
                Published : 2010-05-28 18:30
Updated : 2025-04-11 00:51
NVD link : CVE-2010-2022
Mitre link : CVE-2010-2022
CVE.ORG link : CVE-2010-2022
JSON object : View
Products Affected
                freebsd
- freebsd
 
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
