A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11, allows local users to gain privileges via hard links to setuid programs that use configuration files within the chroot directory, related to requirements for directory ownership.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2009-10-01T15:00:00

Updated: 2024-08-07T06:07:37.284Z

Reserved: 2009-08-20T00:00:00

Link: CVE-2009-2904

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2009-10-01T15:30:00.233

Modified: 2017-09-19T01:29:20.907

Link: CVE-2009-2904

cve-icon Redhat

Severity : Moderate

Publid Date: 2009-09-30T00:00:00Z

Links: CVE-2009-2904 - Bugzilla