]> git.ipfire.org Git - thirdparty/man-pages.git/commit
chroot.2: chroot() is not intended for security; document attack
authorJann Horn <jann@thejh.net>
Sun, 14 Jun 2015 11:25:04 +0000 (13:25 +0200)
committerMichael Kerrisk <mtk.manpages@gmail.com>
Tue, 16 Jun 2015 08:00:14 +0000 (10:00 +0200)
commit614e269a806b8c861df5cb673a80c2907078de3c
tree099603f81c5ad341a4898d7975277cec4a5277ea
parent0326cdf21e663421bcdc6be69ab0be0e08340cd3
chroot.2: chroot() is not intended for security; document attack

It is unfortunate that this discourages this use of chroot(2)
without pointing out alternative solutions - for example,
OpenSSH and vsftpd both still rely on chroot(2) for security.

Bind mounts should theoretically be usable as a replacement, but
currently, they have a similar problem (CVE-2015-2925) that hasn't
been fixed in ~6 months, so I'd rather not add it to the manpage
as a solution before a fix lands.

Signed-off-by: Michael Kerrisk <mtk.manpages@gmail.com>
man2/chroot.2