First published: Fri May 28 2010(Updated: )
jail.c in jail in FreeBSD 8.0 and 8.1-PRERELEASE, when the "-l -U root" options are omitted, does not properly restrict access to the current working directory, which might allow local users to read, modify, or create arbitrary files via standard filesystem operations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | =8.0 | |
FreeBSD Kernel | =8.1-prerelease | |
=8.0 | ||
=8.1-prerelease |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2022 is considered a moderate severity vulnerability that can allow local users to access unauthorized files.
To fix CVE-2010-2022, ensure the use of the "-l -U root" options when configuring jail in FreeBSD.
CVE-2010-2022 affects FreeBSD versions 8.0 and 8.1-PRERELEASE when specific jail options are omitted.
CVE-2010-2022 is a local privilege escalation vulnerability in the FreeBSD jail implementation.
CVE-2010-2022 cannot be exploited remotely as it specifically affects local users operating within the system.