Bug 3245 - CVE-2011-4099 capsh: does not chdir after chroot
Summary: CVE-2011-4099 capsh: does not chdir after chroot
Status: RESOLVED DUPLICATE of bug 3938
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Sysadmin Team
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-11-01 16:52 CET by Nicolas Vigier
Modified: 2012-01-02 01:53 CET (History)
3 users (show)

See Also:
Source RPM: libcap
CVE:
Status comment:


Attachments

Description Nicolas Vigier 2011-11-01 16:52:20 CET
From Red Hat bugzilla :
https://bugzilla.redhat.com/show_bug.cgi?id=722694

The capsh program has a --chroot commandline option. Inspecting the code shows
that it does not do a chdir("/") after calling chroot. This means that '.' is
outside the chroot.

Patch available on RH bugzilla.
Comment 1 Manuel Hiebel 2011-11-01 18:09:12 CET
As there is no maintainer of this package I add the committers in CC.

CC: (none) => mageia, thierry.vignaud

Comment 2 Manuel Hiebel 2011-11-18 00:03:01 CET
Ping ?
Comment 3 Manuel Hiebel 2011-12-06 01:56:28 CET
Ping ?
Comment 4 D Morgan 2012-01-01 23:17:44 CET
i take a look

CC: (none) => dmorganec

Comment 5 D Morgan 2012-01-01 23:21:05 CET
it was already on the svn but not pushed on the BS.

Just pushed.

Assignee: bugsquad => qa-bugs

Comment 6 claire robinson 2012-01-01 23:32:19 CET
Is this different from bug 3938 or a duplicate?
Comment 7 Manuel Hiebel 2012-01-02 01:45:00 CET
Indeed Claire same CVE.

Can somebody from the sysadmin remove libcap-2.19-7.1.mga1.* from 1/core/updates_testing ?

and then you can close as duplicate of bug 3938
thanks

Assignee: qa-bugs => sysadmin-bugs

Comment 8 D Morgan 2012-01-02 01:53:04 CET
cleaning done, closing as dupplicate

*** This bug has been marked as a duplicate of bug 3938 ***

Status: NEW => RESOLVED
Resolution: (none) => DUPLICATE


Note You need to log in before you can comment on or make changes to this bug.