Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 17 Nov 2008 16:43:36 -0500 (EST)
From: "Steven M. Christey" <>
To: oss-security <>
Subject: Re: CVE Request (syslog-ng)

On Mon, 17 Nov 2008, Josh Bressers wrote:

> syslog-ng doesn't call chdir() before calling chroot().

This falls under the notion of "protection mechanism works less securely
than advertised" so is a clear case for inclusion in CVE.  Use

Also - is the chdir supposed to come BEFORE or AFTER?  The CERT secure
coding rules here:

suggest it might be safer AFTER, not before, due to some race condition

- Steve

Name: CVE-2008-5110
Status: Candidate
Reference: CONFIRM:
Reference: MLIST:[oss-security] 20081117 CVE Request (syslog-ng)
Reference: URL:

syslog-ng does not call chdir before it calls chroot, which might
allow attackers to escape the intended jail.  NOTE: this is only a
vulnerability when a separate vulnerability is present.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.