Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m26g-j89h-78px

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack.

The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack.

EPSS

Процентиль: 16%
0.00053
Низкий

Связанные уязвимости

nvd
почти 19 лет назад

The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack.

debian
почти 19 лет назад

The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathname ...

EPSS

Процентиль: 16%
0.00053
Низкий