Updated libcap-ng packages fix CVE-2014-3215
Publication date: 06 Jun 2014Modification date: 06 Jun 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-3215
Description
Updated libcap-ng packages fix security vulnerability: capng_lock() in libcap-ng before 0.7.4 sets securebits in an attempt to prevent regaining capabilities using setuid-root programs. This allows a user to run setuid programs, such as seunshare from policycoreutils, as uid 0 but without capabilities, which is potentially dangerous (CVE-2014-3215).
References
SRPMS
3/core
- libcap-ng-0.7.3-2.1.mga3
4/core
- libcap-ng-0.7.3-3.1.mga4