distribution-gpg-keys: privilege escalation
| Package(s): | distribution-gpg-keys mock | CVE #(s): | CVE-2016-6299 | ||||||||||||||||
| Created: | September 19, 2016 | Updated: | September 21, 2016 | ||||||||||||||||
| Description: | From the Red Hat bugzilla:
It was found that mock's scm plug-in would parse a given spec file with root privileges. This could allow an attacker who is able to start a build of an rpm with a specially crafted spec file within mock's environment to elevate their privileges and escape the chroot. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
