Re: Chroot bug

From: David Newall
Date: Tue Sep 25 2007 - 11:41:37 EST


Jan Engelhardt wrote:
On Sep 26 2007 00:40, David Newall wrote:
Miloslav Semler pointed out that a root process can chdir("..") out of its
chroot.
So what? Just do this: chdir into the root after chroot.

I don't think so. His exploit just got me all the way out of a chroot within a chroot within a chroot, inclusive of lots of chdirs.
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/