Vulnerability Details CVE-2004-0126
The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 21.2%
CVSS Severity
CVSS v2 Score 4.6
Products affected by CVE-2004-0126
-
cpe:2.3:o:freebsd:freebsd:5.1
-
cpe:2.3:o:freebsd:freebsd:5.2
-
cpe:2.3:o:freebsd:freebsd:5.2.1