setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by (1) triggering an SELinux denial with a crafted file name, which is handled by the _set_tpath function in audit_data.py or via a crafted (2) local_id or (3) analysis_id field in a crafted XML document to the run_fix function in SetroubleshootFixit.py, related to the subprocess.check_output and commands.getstatusoutput functions, a different vulnerability than CVE-2016-4445.
CVSS Details
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | centos-upgrade-setroubleshootcentos-upgrade-setroubleshoot-doccentos-upgrade-setroubleshoot-pluginscentos-upgrade-setroubleshoot-server | Jul 22, 2016 | Jun 21, 2016 |
| Huawei Euleros 2_0_sp1 | huawei-euleros-2_0_sp1-upgrade-setroubleshoothuawei-euleros-2_0_sp1-upgrade-setroubleshoot-pluginshuawei-euleros-2_0_sp1-upgrade-setroubleshoot-server | Nov 30, 2017 | Apr 11, 2017 | |
| Oracle_linux | — | oracle-linux-upgrade-setroubleshootoracle-linux-upgrade-setroubleshoot-docoracle-linux-upgrade-setroubleshoot-pluginsoracle-linux-upgrade-setroubleshoot-server | Jun 21, 2016 | Jun 21, 2016 |
| Redhat_linux | — | redhat-upgrade-setroubleshootredhat-upgrade-setroubleshoot-debuginforedhat-upgrade-setroubleshoot-docredhat-upgrade-setroubleshoot-pluginsredhat-upgrade-setroubleshoot-server | Jul 30, 2016 | Jun 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub