Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.69390
Categoría:Red Hat Local Security Checks
Título:RedHat Security Advisory RHSA-2011:0414
Resumen:NOSUMMARY
Descripción:Description:
The remote host is missing updates announced in
advisory RHSA-2011:0414.

The policycoreutils packages contain the core utilities that are
required for the basic operation of a Security-Enhanced Linux (SELinux)
system and its policies.

It was discovered that the seunshare utility did not enforce proper file
permissions on the directory used as an alternate temporary directory
mounted as /tmp/. A local user could use this flaw to overwrite files or,
possibly, execute arbitrary code with the privileges of a setuid or
setgid application that relies on proper /tmp/ permissions, by running that
application via seunshare. (CVE-2011-1011)

Red Hat would like to thank Tavis Ormandy for reporting this issue.

This update also introduces the following changes:

* The seunshare utility was moved from the main policycoreutils subpackage
to the policycoreutils-sandbox subpackage. This utility is only required
by the sandbox feature and does not need to be installed by default.

* Updated selinux-policy packages that add the SELinux policy changes
required by the seunshare fixes.

All policycoreutils users should upgrade to these updated packages, which
correct this issue.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2011-0414.html

Risk factor : High

CVSS Score:
6.9

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-1011
BugTraq ID: 46510
http://www.securityfocus.com/bid/46510
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056227.html
http://archives.neohapsis.com/archives/fulldisclosure/2011-02/0585.html
http://openwall.com/lists/oss-security/2011/02/23/1
http://openwall.com/lists/oss-security/2011/02/23/2
http://www.redhat.com/support/errata/RHSA-2011-0414.html
http://www.securitytracker.com/id?1025291
http://secunia.com/advisories/43415
http://secunia.com/advisories/43844
http://secunia.com/advisories/44034
http://www.vupen.com/english/advisories/2011/0701
http://www.vupen.com/english/advisories/2011/0864
XForce ISS Database: policycoreutils-seunshare-symlink(65641)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65641
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.