CVE-2014-3215

Public on 2014-05-08
Modified on 2015-06-16
Description
A flaw was found in the way seunshare, a utility for running executables under a different security context, used the capng_lock functionality of the libcap-ng library. The subsequent invocation of suid root binaries that relied on the fact that the setuid() system call, among others, also sets the saved set-user-ID when dropping the binaries' process privileges, could allow a local, unprivileged user to potentially escalate their privileges on the system. Note: the fix for this issue is the kernel part of the overall fix, and introduces the PR_SET_NO_NEW_PRIVS functionality and the related SELinux exec transitions support.
Severity
Important severity
Important
CVSS v3 Base Score
6.9
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 kernel 2015-06-16 ALAS-2015-544 Fixed
Amazon Linux 1 libcap-ng 2015-06-16 ALAS-2015-543 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 6.9 AV:L/AC:M/Au:N/C:C/I:C/A:C
NVD CVSSv2 6.9 AV:L/AC:M/Au:N/C:C/I:C/A:C