The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafted filename, related to the commands.getoutput function.
CVSS Details
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade setroubleshoot-pluginsUpgrade setroubleshoot-serverUpgrade setroubleshootUpgrade setroubleshoot-doc | Jul 22, 2016 | Jun 21, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade setroubleshoot-pluginsUpgrade setroubleshoot-serverUpgrade setroubleshoot | Nov 30, 2017 | Apr 11, 2017 |
| Oracle_linux | — | Upgrade setroubleshootUpgrade setroubleshoot-docUpgrade setroubleshoot-serverUpgrade setroubleshoot-plugins | Jun 21, 2016 | Jun 21, 2016 |
| Redhat_linux | — | Upgrade setroubleshoot-docUpgrade setroubleshoot-pluginsUpgrade setroubleshoot-debuginfoUpgrade setroubleshootUpgrade setroubleshoot-server | Jul 30, 2016 | Jun 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub