The long road to a fix for CVE-2021-20316
The long road to a fix for CVE-2021-20316
Posted Feb 15, 2022 20:13 UTC (Tue) by Cyberax (✭ supporter ✭, #52523)In reply to: The long road to a fix for CVE-2021-20316 by jra
Parent article: The long road to a fix for CVE-2021-20316
Posted Feb 16, 2022 18:55 UTC (Wed)
by jra (subscriber, #55261)
[Link]
They actually change the view of the filesystem hierarchy in a way that symlinks don't. Symlinks are a point attack that can modify a specific path quickly and easily to anywhere on the filesystem if allowed or exposed over a network filesystem. IMHO they are much more dangerous.
The long road to a fix for CVE-2021-20316