** Changed in: linux-armadaxp (Ubuntu Precise)
       Status: New => Invalid
** Changed in: linux-ec2 (Ubuntu Lucid)
       Status: New => Invalid

** Changed in: linux (Ubuntu Precise)
       Status: New => Invalid

** Changed in: linux (Ubuntu Lucid)
       Status: New => Invalid

** Changed in: linux-ti-omap4 (Ubuntu Precise)
       Status: New => Invalid

** Description changed:

  The capabilities implementation in the Linux kernel before 3.14.8 does
  not properly consider that namespaces are inapplicable to inodes, which
  allows local users to bypass intended chmod restrictions by first
  creating a user namespace, as demonstrated by setting the setgid bit on
  a file with group ownership of root.
  
- Break-Fix: - 23adbe12ef7d3d4195e80800ab36b37bee28cd03
+ Break-Fix: 1a48e2ac034d47ed843081c4523b63c46b46888b
+ 23adbe12ef7d3d4195e80800ab36b37bee28cd03

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1329103

Title:
  CVE-2014-4014

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1329103/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to