FreeBSD Security Advisory FreeBSD-SA-04:03.jail – A vulnerability has been found where jailed processes can attach to other jails. A programming error has been found in the jail_attach(2) system call which affects the way that system call verifies the privilege level of the calling process. Instead of failing immediately if the calling process was already jailed, the jail_attach(2) system call would fail only after changing the calling process’s root directory.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/32781/FreeBSD-SA-04%3A03.jail.txt
Source: https://packetstormsecurity.com/files/32781/FreeBSD-Security-Advisory-2004.3.html

