Advisories ยป MGASA-2014-0251

Updated libcap-ng packages fix CVE-2014-3215

Publication date: 06 Jun 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-3215

Description

Updated libcap-ng packages fix security vulnerability:

capng_lock() in libcap-ng before 0.7.4 sets securebits in an attempt to
prevent regaining capabilities using setuid-root programs. This allows a
user to run setuid programs, such as seunshare from policycoreutils, as
uid 0 but without capabilities, which is potentially dangerous
(CVE-2014-3215).
                

References

SRPMS

3/core

4/core