Heap-based buffer overflow in the parsecgroupspec function in tools/tools-common.c in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 allows local users to gain privileges via a crafted controller list on the command line of an application. NOTE: it is not clear whether this issue crosses privilege boundaries.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "0.38-1ubuntu2",
"binary_name": "cgroup-bin"
},
{
"binary_version": "0.38-1ubuntu2",
"binary_name": "libcgroup-dev"
},
{
"binary_version": "0.38-1ubuntu2",
"binary_name": "libcgroup1"
},
{
"binary_version": "0.38-1ubuntu2",
"binary_name": "libpam-cgroup"
}
]
}