CVE Vulnerabilities

CVE-2009-2904

Published: Oct 01, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.2 MODERATE
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 and Fedora 11, allows local users to gain privileges via hard links to setuid programs that use configuration files within the chroot directory, related to requirements for directory ownership.

Affected Software

NameVendorStart VersionEnd Version
OpensshOpenbsd4.3 (including)4.3 (including)
OpensshOpenbsd4.8 (including)4.8 (including)
Red Hat Enterprise Linux 5RedHatopenssh-0:4.3p2-36.el5_4.2*

References