#1098499 libcap2/tests/exploit flagged as malicious by various scanning engines

Package:
libcap-dev
Source:
libcap-dev
Description:
POSIX 1003.1e capabilities (development)
Submitter:
Maciej Krakowiak
Date:
2025-02-25 10:48:04 UTC
Severity:
normal
#1098499#5
Date:
2025-02-21 13:21:11 UTC
From:
To:
Version: 1:2.66-4

Recently, I have observed that the file "exploit," which sits in the
"tests" catalog, has been flagged as malicious by different scanning
engines. I think this might be expected, but I was wondering if
anything has changed recently, as this file was not flagged before.

This has been flagged on different OS distributions.

Example of Virus Total report:
https://www.virustotal.com/gui/file/8c8d3b51fc454748ab8aea76a329cccca95e1e683d1a879a8b90aaa1d7158792


Kind regards,

Maciej Krakowiak

#1098499#10
Date:
2025-02-23 17:03:55 UTC
From:
To:
Hi Maciej,

yes, this can only be a false positive. The test is designed to attempt
an exploit, which is expected to fail.

Looking at tests/exploit.c, I assume this was flagged by name or
keywords, as it doesn't contain any operation that looks suspicious, at
least immediately.

There have been meaningful changes since the initial release with Debian
package version 1:2.45-1, see [1].

Unless you have a reasonable objection, I'd like to close this bug. In
any case, thanks for the report, better to be safe than sorry.

Best,
Christian

[1]: https://git.kernel.org/pub/scm/libs/libcap/libcap.git/log/tests/exploit.c

#1098499#15
Date:
2025-02-25 10:44:11 UTC
From:
To:
Hi Christian,

Thank you very much for your reply. Agree, we can close this bug.

Kind regards

*Maciej Krakowiak*

Application Security Engineer

pandadoc.com <https://www.pandadoc.com/>