LWN.net Logo

libcap: insecure chroot

Package(s):libcap CVE #(s):
Created:August 8, 2011 Updated:August 10, 2011
Description: From the CWE entry:

Improper use of chroot() may allow attackers to escape from the chroot jail. The chroot() function call does not change the process's current working directory, so relative paths may still refer to file system resources outside of the chroot jail after chroot() has been called.

Alerts:
Fedora FEDORA-2011-9844 2011-07-31

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds