From owner-freebsd-security Sat Sep 30 18:46:43 2000 Delivered-To: freebsd-security@freebsd.org Received: from point.osg.gov.bc.ca (point.osg.gov.bc.ca [142.32.102.44]) by hub.freebsd.org (Postfix) with ESMTP id 88DA537B503; Sat, 30 Sep 2000 18:46:39 -0700 (PDT) Received: (from daemon@localhost) by point.osg.gov.bc.ca (8.8.7/8.8.8) id SAA11258; Sat, 30 Sep 2000 18:46:38 -0700 Received: from passer.osg.gov.bc.ca(142.32.110.29) via SMTP by point.osg.gov.bc.ca, id smtpda11256; Sat Sep 30 18:46:36 2000 Received: (from uucp@localhost) by passer.osg.gov.bc.ca (8.11.0/8.9.1) id e911kWv82969; Sat, 30 Sep 2000 18:46:32 -0700 (PDT) Received: from cwsys9.cwsent.com(10.2.2.1), claiming to be "cwsys.cwsent.com" via SMTP by passer9.cwsent.com, id smtpdD82967; Sat Sep 30 18:46:29 2000 Received: (from uucp@localhost) by cwsys.cwsent.com (8.11.0/8.9.1) id e911kSk03262; Sat, 30 Sep 2000 18:46:28 -0700 (PDT) Message-Id: <200010010146.e911kSk03262@cwsys.cwsent.com> Received: from localhost.cwsent.com(127.0.0.1), claiming to be "cwsys" via SMTP by localhost.cwsent.com, id smtpdTe3256; Sat Sep 30 18:45:51 2000 X-Mailer: exmh version 2.1.1 10/15/1999 Reply-To: Cy Schubert - ITSD Open Systems Group From: Cy Schubert - ITSD Open Systems Group X-OS: FreeBSD 4.1-RELEASE X-Sender: cy To: Robert Watson Cc: "Brian F. Feldman" , Mike Silbersack , security@FreeBSD.ORG Subject: Re: cvs commit: ports/mail/pine4 Makefile (fwd) In-reply-to: Your message of "Sat, 30 Sep 2000 18:34:06 EDT." Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Date: Sat, 30 Sep 2000 18:45:51 -0700 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org In message , Robe rt Watson writes: > > Using only chroot() and the ability to execute arbitrary code, it is easy > to break out of a user-initiated sandbox if any processes owned by the > same user are present outside of the sandbox. The last time I tried the chroot() breakout code under FreeBSD-4 it didn't work. I assume that someone had fixed FreeBSD. Regards, Phone: (250)387-8437 Cy Schubert Fax: (250)387-5766 Team Leader, Sun/DEC Team Internet: Cy.Schubert@osg.gov.bc.ca Open Systems Group, ITSD, ISTA Province of BC To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message