The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELinux denial with a crafted file name, related to executing external commands with the commands.getstatusoutput function.
CVSS Details
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade setroubleshoot-serverUpgrade setroubleshootUpgrade setroubleshoot-pluginsUpgrade setroubleshoot-doc | Jul 22, 2016 | Jun 21, 2016 |
| Oracle_linux | — | Upgrade setroubleshoot-serverUpgrade setroubleshootUpgrade setroubleshoot-pluginsUpgrade setroubleshoot-doc | Jun 21, 2016 | Jun 21, 2016 |
| Redhat_linux | — | Upgrade setroubleshoot-docUpgrade setroubleshoot-serverUpgrade setroubleshoot-pluginsUpgrade setroubleshoot-debuginfoUpgrade setroubleshoot | Jul 30, 2016 | Jun 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub