---
title: "CVE-2009-2904\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2009-2904?format=md
keywords: index, follow
---

# CVE-2009-2904

Publication date 1 October 2009

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

A certain Red Hat modification to the ChrootDirectory feature in OpenSSH
4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4
and Fedora 11, allows local users to gain privileges via hard links to
setuid programs that use configuration files within the chroot directory,
related to requirements for directory ownership.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2009-2904?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openssh | 9.04 jaunty | Not affected |
| 8.10 intrepid | Not affected |
| 8.04 LTS hardy | Not affected |
| 6.06 LTS dapper | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [kees](https://launchpad.net/~kees)

RedHat-specific

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2904)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2009-2904)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2009-2904)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2009-2904)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2009-2904>
