The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial with a crafted binary filename, related to the commands.getstatusoutput function.
CVSS Details
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade setroubleshoot-docUpgrade setroubleshootUpgrade setroubleshoot-serverUpgrade setroubleshoot-plugins | Jul 22, 2016 | Jun 21, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade setroubleshootUpgrade setroubleshoot-serverUpgrade setroubleshoot-plugins | Nov 30, 2017 | Apr 11, 2017 |
| Oracle_linux | — | Upgrade setroubleshoot-docUpgrade setroubleshootUpgrade setroubleshoot-pluginsUpgrade setroubleshoot-server | Jun 21, 2016 | Jun 21, 2016 |
| Redhat_linux | — | Upgrade setroubleshoot-serverUpgrade setroubleshoot-debuginfoUpgrade setroubleshootUpgrade setroubleshoot-docUpgrade setroubleshoot-plugins | Jul 30, 2016 | Jun 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub