Tianjia Zhang discovered the libcap2 PAM module pam_cap incorrectly handled parsing group names in the configuration file. This could result in certain users being granted capabilities, contrary to expectations.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libcap-dev",
"binary_version": "1:2.32-1ubuntu0.2"
},
{
"binary_name": "libcap2",
"binary_version": "1:2.32-1ubuntu0.2"
},
{
"binary_name": "libcap2-bin",
"binary_version": "1:2.32-1ubuntu0.2"
},
{
"binary_name": "libpam-cap",
"binary_version": "1:2.32-1ubuntu0.2"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libcap-dev",
"binary_version": "1:2.44-1ubuntu0.22.04.2"
},
{
"binary_name": "libcap2",
"binary_version": "1:2.44-1ubuntu0.22.04.2"
},
{
"binary_name": "libcap2-bin",
"binary_version": "1:2.44-1ubuntu0.22.04.2"
},
{
"binary_name": "libpam-cap",
"binary_version": "1:2.44-1ubuntu0.22.04.2"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libcap-dev",
"binary_version": "1:2.66-5ubuntu2.2"
},
{
"binary_name": "libcap2",
"binary_version": "1:2.66-5ubuntu2.2"
},
{
"binary_name": "libcap2-bin",
"binary_version": "1:2.66-5ubuntu2.2"
},
{
"binary_name": "libpam-cap",
"binary_version": "1:2.66-5ubuntu2.2"
}
]
}