From Red Hat bugzilla : https://bugzilla.redhat.com/show_bug.cgi?id=722694 The capsh program has a --chroot commandline option. Inspecting the code shows that it does not do a chdir("/") after calling chroot. This means that '.' is outside the chroot. Patch available on RH bugzilla.
As there is no maintainer of this package I add the committers in CC.
CC: (none) => mageia, thierry.vignaud
Ping ?
i take a look
CC: (none) => dmorganec
it was already on the svn but not pushed on the BS. Just pushed.
Assignee: bugsquad => qa-bugs
Is this different from bug 3938 or a duplicate?
Indeed Claire same CVE. Can somebody from the sysadmin remove libcap-2.19-7.1.mga1.* from 1/core/updates_testing ? and then you can close as duplicate of bug 3938 thanks
Assignee: qa-bugs => sysadmin-bugs
cleaning done, closing as dupplicate *** This bug has been marked as a duplicate of bug 3938 ***
Status: NEW => RESOLVEDResolution: (none) => DUPLICATE