The capsh program in libcap before 2.22 does not change the current working directory when the --chroot option is specified, which allows local users to bypass the chroot restrictions via unspecified vectors.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:31
Type | Values Removed | Values Added |
---|---|---|
References | () http://rhn.redhat.com/errata/RHSA-2011-1694.html - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=722694 - Vendor Advisory | |
References | () https://sites.google.com/site/fullycapable/release-notes-for-libcap/releasenotesfor222 - |
Information
Published : 2014-02-08 00:55
Updated : 2025-04-11 00:51
NVD link : CVE-2011-4099
Mitre link : CVE-2011-4099
CVE.ORG link : CVE-2011-4099
JSON object : View
Products Affected
libcap
- libcap
CWE
CWE-264
Permissions, Privileges, and Access Controls