Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

FreeBSD jail() Process Unauthorized Routing Table Modification Vulnerability

FreeBSD improperly allows routing updates from superuser processes inside jail() environments.

An attacker that gains superuser privileges inside of a jailed process can send routing table changes. An attacker could corrupt the routing table of the server, denying network services to legitimate users. Attackers may also be able to perform connection-hijacking and redirection attacks, such as the SSH man-in-the-middle attack.







 

Privacy Statement
Copyright 2009, SecurityFocus