...
Failing to follow this recommendation may lead to full-system compromise if a file system vulnerability is discovered and exploited.
Recommendation | Severity | Likelihood |
|---|
Detectable | Repairable | Priority | Level |
|---|---|---|---|
POS05-C | Medium | Probable |
No | No | P4 | L3 |
Automated Detection
| Tool | Version | Checker | Description | ||||||
|---|---|---|---|---|---|---|---|---|---|
| CodeSonar |
| BADFUNC.CHROOT MISC.CHROOT.NOCHDIR | Use of chroot | ||||||
| Klocwork |
| CERT.CHROOT CERT.CHROOT.CHDIR | |||||||
| Polyspace Bug Finder |
|
| CERT C: Rec. POS05-C | Checks for file |
manipulation after chroot() without chdir("/") |
chroot(rec. fully covered) |
Related Vulnerabilities
Search for vulnerabilities resulting from the violation of this rule on the CERT website.
Bibliography
...
...