Updated libcap-ng packages fix CVE-2014-3215
Publication date: 06 Jun 2014Modification date: 06 Jun 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-3215
Description
Updated libcap-ng packages fix security vulnerability:
capng_lock() in libcap-ng before 0.7.4 sets securebits in an attempt to
prevent regaining capabilities using setuid-root programs. This allows a
user to run setuid programs, such as seunshare from policycoreutils, as
uid 0 but without capabilities, which is potentially dangerous
(CVE-2014-3215).
References
SRPMS
3/core
- libcap-ng-0.7.3-2.1.mga3
4/core
- libcap-ng-0.7.3-3.1.mga4