The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fedora | Fedoraproject | 23 (including) | 23 (including) |
Fedora | Fedoraproject | 24 (including) | 24 (including) |
Fedora | Fedoraproject | 25 (including) | 25 (including) |
Mock | Ubuntu | artful | * |
Mock | Ubuntu | esm-apps/xenial | * |
Mock | Ubuntu | trusty | * |
Mock | Ubuntu | upstream | * |
Mock | Ubuntu | xenial | * |
Mock | Ubuntu | yakkety | * |
Mock | Ubuntu | zesty | * |