[Bug 3428] chroot root 755] I wish there was an option to lower the chroot security. CVE-2009-2904

bugzilla-daemon at mindrot.org bugzilla-daemon at mindrot.org
Mon May 2 09:58:25 AEST 2022


https://bugzilla.mindrot.org/show_bug.cgi?id=3428

Damien Miller <djm at mindrot.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |RESOLVED
         Resolution|---                         |WONTFIX
                 CC|                            |djm at mindrot.org

--- Comment #1 from Damien Miller <djm at mindrot.org> ---
Sorry, but this has been discussed extensively in the past (e.g. this
thread https://marc.info/?t=122641302700006&r=1&w=2) and we do not
intend to make changes to ChrootDirectory permission requirements.

The CVE you mention occurred because Redhat ignored this and patched
their sshd to relax these requirements. It never affected the version
of OpenSSH that we ship.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
You are watching someone on the CC list of the bug.


More information about the openssh-bugs mailing list