20020207 AtheOS: escaping from a chroot jailmailing list
http://marc.info/?l=bugtraq&m=101310622531303&w=2 CVE-2002-0244
AtheOS 0.3.7 - Change Root Directory Escaping
Record summary
CVE-2002-0244 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAtheOS 0.3.7 - Change Root Directory EscapingExploitDB exploitby Jedi/SectorNot analyzed1 file
References
44051vdb entry
http://www.securityfocus.com/bid/4051 atheos-dot-directory-traversal(8108)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/8108 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0244