syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present.
CVE-2008-5110 (syslog-ng)
Leave a reply
410-897-9494
Receive RedZone Security Updates in Your InboxContact Us
syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present.
You must be logged in to post a comment.