10816Third-party advisory
http://secunia.com/advisories/10816 CVE-2004-2073
Linux VServer Project 1.2x - Chroot Breakout
Record summary
CVE-2004-2073 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLinux VServer Project 1.2x - Chroot BreakoutExploitDB exploitby Markus MuellerNot analyzed1 file
References
7linux-vserver.orgConfirmation
http://www.linux-vserver.org/index.php?page=ChangeLog 3875vdb entry
http://www.osvdb.org/3875 20040206 Linux 2.4.24 with vserver 1.24 exploitmailing list
http://www.securityfocus.com/archive/1/353003 9596vdb entry
http://www.securityfocus.com/bid/9596 linux-vserver-gain-privileges(15073)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15073 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2073