Logo
componentlibcap
Name
libcap
Version
2.78
Type
library
Description
Library for getting/setting POSIX.1e capabilities
Licenses
(BSD-3-Clause | GPL-2.0-only) & (BSD-3-Clause | LGPL-2.0-or-later)
PURL
-
CPE
cpe:2.3:*:libcap_project:libcap:2.78:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
2.66
scarthgap
2.69

Vulnerabilities#


Name
Analysis
Description
Not Affected
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.