USN-7287-1: libcap2 vulnerability
Tianjia Zhang discovered the libcap2 PAM module pamcap incorrectly handled parsing group names in the configuration file. This could result in certain users being granted capabilities, contrary to expectations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7287-1?
USN-7287-1 is classified as a medium severity vulnerability due to improper handling of group names in libcap2 PAM module.
How do I fix USN-7287-1?
To resolve USN-7287-1, update the libpam-cap package to versions 1:2.66-5ubuntu3.1, 1:2.66-5ubuntu2.2, 1:2.44-1ubuntu0.22.04.2, or 1:2.32-1ubuntu0.2 depending on your Ubuntu version.
Who discovered the vulnerability identified as USN-7287-1?
The vulnerability USN-7287-1 was discovered by Tianjia Zhang.
What systems are affected by USN-7287-1?
USN-7287-1 affects Ubuntu versions 20.04, 22.04, 24.04, and 24.10 using the libpam-cap package.
Why is USN-7287-1 a concern for system administrators?
USN-7287-1 is a concern for system administrators because it could lead to unauthorized users being granted capabilities, potentially compromising system security.