Mageia alert MGASA-2014-0251 (libcap-ng)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2014-0251: Updated libcap-ng packages fix CVE-2014-3215 | |
| Date: | Fri, 6 Jun 2014 07:50:03 +0200 | |
| Message-ID: | <20140606055003.84F045C8CA@valstar.mageia.org> |
MGASA-2014-0251 - Updated libcap-ng packages fix CVE-2014-3215 Publication date: 06 Jun 2014 URL: http://advisories.mageia.org/MGASA-2014-0251.html Type: security Affected Mageia releases: 3, 4 CVE: CVE-2014-3215 Description: Updated libcap-ng packages fix security vulnerability: capng_lock() in libcap-ng before 0.7.4 sets securebits in an attempt to prevent regaining capabilities using setuid-root programs. This allows a user to run setuid programs, such as seunshare from policycoreutils, as uid 0 but without capabilities, which is potentially dangerous (CVE-2014-3215). References: - http://lists.opensuse.org/opensuse-updates/2014-05/msg000... - https://bugs.mageia.org/show_bug.cgi?id=13459 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3215 SRPMS: - 4/core/libcap-ng-0.7.3-3.1.mga4 - 3/core/libcap-ng-0.7.3-2.1.mga3
