The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterprise Linux (RHEL) 6 and earlier, and Fedora 14 and earlier, mounts a new directory on top of /tmp without assigning root ownership and the sticky bit to this new directory, which allows local users to replace or delete arbitrary /tmp files, and consequently cause a denial of service or possibly gain privileges, by running a setuid application that relies on /tmp, as demonstrated by the ksu application.
CVSS Details
- CVSS 3.1 Base Score: 7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade policycoreutils-newroleUpgrade policycoreutilsUpgrade selinux-policy-mlsUpgrade policycoreutils-guiUpgrade policycoreutils-pythonUpgrade selinux-policy-minimumUpgrade selinux-policy-docUpgrade selinux-policy-targetedUpgrade policycoreutils-sandboxUpgrade selinux-policy | Oct 16, 2024 | Feb 24, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub