SB2014061809 - Permissions, Privileges, and Access Controls in libcap-ng (Alpine package)
Published: June 18, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2014-3215)
The vulnerability allows a local non-authenticated attacker to execute arbitrary code.
seunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions, and executes programs in a way that changes the relationship between the setuid system call and the getresuid saved set-user-ID value, which makes it easier for local users to gain privileges by leveraging a program that mistakenly expected that it could permanently drop privileges.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=ca45f4a87ee9f6f19c839d69474332bc8888e24c
- https://git.alpinelinux.org/aports/commit/?id=09667d2fb33c78602017b0cb73c895e27459f76b
- https://git.alpinelinux.org/aports/commit/?id=88a25f5aabc145f8e2063a3200ef0a8f4194eee3
- https://git.alpinelinux.org/aports/commit/?id=f202c41cce97650c6c9077d80fc60590a22350de