Re: Chroot bug

From: Miloslav Semler
Date: Tue Sep 25 2007 - 12:20:08 EST



So what? Just do this: chdir into the root after chroot.
I don't think so. His exploit just got me all the way out of a chroot within a
chroot within a chroot, inclusive of lots of chdirs.

Close all fds that point to directories outside the root ;-)

This does not help. Let's try:
chroot somewhere
mkdir foo
fd = open /
chroot foo
fchdir fd
chdir ".."
....
chdir ".."
chroot "."
so you are in root.


-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/