LWN.net Logo

policycoreutils: privilege escalation

Package(s):policycoreutils CVE #(s):CVE-2011-1011
Created:March 21, 2011 Updated:April 5, 2011
Description: From the CVE entry:

The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterprise Linux (RHEL) 6 and earlier, and Fedora 14 and earlier, mounts a new directory on top of /tmp without assigning root ownership and the sticky bit to this new directory, which allows local users to replace or delete arbitrary /tmp files, and consequently cause a denial of service or possibly gain privileges, by running a setuid application that relies on /tmp, as demonstrated by the ksu application.

Alerts:
Red Hat RHSA-2011:0414-01 2011-04-04
Fedora FEDORA-2011-3043 2011-03-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds