Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-4099

Опубликовано: 08 фев. 2014
Источник: nvd
CVSS2: 4.6
EPSS Низкий

Описание

The capsh program in libcap before 2.22 does not change the current working directory when the --chroot option is specified, which allows local users to bypass the chroot restrictions via unspecified vectors.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:libcap:libcap:*:*:*:*:*:*:*:*
Версия до 2.21 (включая)
cpe:2.3:a:libcap:libcap:2.00:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.01:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.02:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.03:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.04:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.05:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.06:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.07:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.08:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.09:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.10:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.11:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.12:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.13:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.14:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.15:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.16:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.17:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.18:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.19:*:*:*:*:*:*:*
cpe:2.3:a:libcap:libcap:2.20:*:*:*:*:*:*:*

EPSS

Процентиль: 17%
0.00055
Низкий

4.6 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 11 лет назад

The capsh program in libcap before 2.22 does not change the current working directory when the --chroot option is specified, which allows local users to bypass the chroot restrictions via unspecified vectors.

redhat
около 14 лет назад

The capsh program in libcap before 2.22 does not change the current working directory when the --chroot option is specified, which allows local users to bypass the chroot restrictions via unspecified vectors.

debian
больше 11 лет назад

The capsh program in libcap before 2.22 does not change the current wo ...

github
больше 3 лет назад

The capsh program in libcap before 2.22 does not change the current working directory when the --chroot option is specified, which allows local users to bypass the chroot restrictions via unspecified vectors.

oracle-oval
больше 13 лет назад

ELSA-2011-1694: libcap security and bug fix update (LOW)

EPSS

Процентиль: 17%
0.00055
Низкий

4.6 Medium

CVSS2

Дефекты

CWE-264