FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

Revision:  374986
Date:      2014-12-20
Time:      00:21:30Z
Committer: delphij

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
75f2382e-b586-11dd-95f9-00e0815b8da8syslog-ng2 -- startup directory leakage in the chroot environment

Florian Grandel reports:

I have not had the time to analyze all of syslog-ng code. But by reading the code section near the chroot call and looking at strace results I believe that syslog-ng does not chdir to the chroot jail's location before chrooting into it.

This opens up ways to work around the chroot jail.


Discovery 2008-11-15
Entry 2008-11-18
Modified 2009-07-01
syslog-ng2
lt 2.0.9_2

syslog-ng
le 1.6.12_1

CVE-2008-5110
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505791
http://www.openwall.com/lists/oss-security/2008/11/17/3
75f2382e-b586-11dd-95f9-00e0815b8da8syslog-ng2 -- startup directory leakage in the chroot environment

Florian Grandel reports:

I have not had the time to analyze all of syslog-ng code. But by reading the code section near the chroot call and looking at strace results I believe that syslog-ng does not chdir to the chroot jail's location before chrooting into it.

This opens up ways to work around the chroot jail.


Discovery 2008-11-15
Entry 2008-11-18
Modified 2009-07-01
syslog-ng2
lt 2.0.9_2

syslog-ng
le 1.6.12_1

CVE-2008-5110
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505791
http://www.openwall.com/lists/oss-security/2008/11/17/3