From owner-freebsd-bugs Wed Jan 3 8:40: 6 2001 From owner-freebsd-bugs@FreeBSD.ORG Wed Jan 3 08:40:03 2001 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from freefall.freebsd.org (freefall.FreeBSD.org [216.136.204.21]) by hub.freebsd.org (Postfix) with ESMTP id 7633937B404 for ; Wed, 3 Jan 2001 08:40:03 -0800 (PST) Received: (from gnats@localhost) by freefall.freebsd.org (8.11.1/8.11.1) id f03Ge3Y76093; Wed, 3 Jan 2001 08:40:03 -0800 (PST) (envelope-from gnats) Date: Wed, 3 Jan 2001 08:40:03 -0800 (PST) Message-Id: <200101031640.f03Ge3Y76093@freefall.freebsd.org> To: freebsd-bugs@FreeBSD.org Cc: From: Daniel Hagan Subject: Re: misc/24034: "CWD" discloses the full "real" path in a chroot environment (freebsd 4.2-stable aprox december 11th) Reply-To: Daniel Hagan Sender: gnats@FreeBSD.org Sender: owner-freebsd-bugs@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org The following reply was made to PR misc/24034; it has been noted by GNATS. From: Daniel Hagan To: freebsd-gnats-submit@FreeBSD.org Cc: danny@FreeBSD.org, des@FreeBSD.org Subject: Re: misc/24034: "CWD" discloses the full "real" path in a chroot environment (freebsd 4.2-stable aprox december 11th) Date: Wed, 03 Jan 2001 11:31:55 -0500 It looks to me like this was fixed in r. 1.18 of ftpcmd.y (2000/11/26). I can't test it to be sure, but the log messages indicate something to that effect, and the code doesn't look like it should leak anymore. Perhaps someone should roll this back into STABLE as well (r. 1.16.x.x I think)? Daniel To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-bugs" in the body of the message