The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial with a crafted binary filename, related to the commands.getstatusoutput function.
CVSS Details
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade setroubleshootUpgrade setroubleshoot-docUpgrade setroubleshoot-pluginsUpgrade setroubleshoot-server | Jul 22, 2016 | Jun 21, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade setroubleshoot-pluginsUpgrade setroubleshoot-serverUpgrade setroubleshoot | Nov 30, 2017 | Apr 11, 2017 |
| Oracle_linux | — | Upgrade setroubleshoot-pluginsUpgrade setroubleshoot-docUpgrade setroubleshootUpgrade setroubleshoot-server | Jun 21, 2016 | Jun 21, 2016 |
| Redhat_linux | — | Upgrade setroubleshoot-serverUpgrade setroubleshoot-pluginsUpgrade setroubleshoot-docUpgrade setroubleshootUpgrade setroubleshoot-debuginfo | Jul 30, 2016 | Jun 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub