Bug 722694 (CVE-2011-4099) - CVE-2011-4099 capsh: does not chdir after chroot
Summary: CVE-2011-4099 capsh: does not chdir after chroot
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2011-4099
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: Unspecified
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 734217
TreeView+ depends on / blocked
 
Reported: 2011-07-16 16:51 UTC by Steve Grubb
Modified: 2019-09-29 12:45 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-12-07 09:09:41 UTC
Embargoed:


Attachments (Terms of Use)
Patch fixing bug (1.06 KB, patch)
2011-07-16 16:59 UTC, Steve Grubb
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:1694 0 normal SHIPPED_LIVE Low: libcap security and bug fix update 2011-12-06 01:02:34 UTC

Description Steve Grubb 2011-07-16 16:51:54 UTC
Description of problem:
The capsh program has a --chroot commandline option. Inspecting the code shows that it does not do a chdir("/") after calling chroot. This means that '.' is outside the chroot.

Additional info:
http://cwe.mitre.org/data/definitions/243.html

Comment 3 Steve Grubb 2011-07-16 16:59:43 UTC
Created attachment 513490 [details]
Patch fixing bug

The attached patch will be sent upstream.

Comment 4 Steve Grubb 2011-07-26 16:43:05 UTC
Upstream said they included the fix in 2.22. Its now public:

http://www.kernel.org/pub/linux/libs/security/linux-privs/libcap2/libcap-2.22.tar.gz

So, I would say we should push fixes out in Fedora at least.

Comment 12 Huzaifa S. Sidhpurwala 2011-11-18 06:04:59 UTC
This issue does not affect the version of libcap as shipped with Red Hat Enterprise Linux 4 and 5.

Comment 13 errata-xmlrpc 2011-12-06 17:12:51 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2011:1694 https://rhn.redhat.com/errata/RHSA-2011-1694.html


Note You need to log in before you can comment on or make changes to this bug.