[Bug 3428] chroot root 755] I wish there was an option to lower the chroot security. CVE-2009-2904
bugzilla-daemon at mindrot.org
bugzilla-daemon at mindrot.org
Mon May 2 09:58:25 AEST 2022
https://bugzilla.mindrot.org/show_bug.cgi?id=3428
Damien Miller <djm at mindrot.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
Status|NEW |RESOLVED
Resolution|--- |WONTFIX
CC| |djm at mindrot.org
--- Comment #1 from Damien Miller <djm at mindrot.org> ---
Sorry, but this has been discussed extensively in the past (e.g. this
thread https://marc.info/?t=122641302700006&r=1&w=2) and we do not
intend to make changes to ChrootDirectory permission requirements.
The CVE you mention occurred because Redhat ignored this and patched
their sshd to relax these requirements. It never affected the version
of OpenSSH that we ship.
--
You are receiving this mail because:
You are watching the assignee of the bug.
You are watching someone on the CC list of the bug.
More information about the openssh-bugs
mailing list