CVE-2004-0126
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/03/2004
Last modified:
03/04/2025
Description
The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail.
Impact
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:freebsd:freebsd:5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:5.1:release:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:5.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:5.2.1:release:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:03.jail.asc
- http://www.osvdb.org/4101
- http://www.securityfocus.com/bid/9762
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15344
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:03.jail.asc
- http://www.osvdb.org/4101
- http://www.securityfocus.com/bid/9762
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15344



