The capsh program in libcap before 2.22 does not change the current working directory when the --chroot option is specified, which allows local users to bypass the chroot restrictions via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libcap2 | Jul 30, 2024 | Feb 8, 2014 |
| Oracle_linux | — | Upgrade libcap-develUpgrade libcap | Oct 16, 2024 | Feb 8, 2014 |
| Suse | — | Upgrade libcap2-x86Upgrade libcap2Upgrade libcap-develUpgrade libcap2-32bitUpgrade libcap-progs | Dec 12, 2013 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub