Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.69390
Kategorie:Red Hat Local Security Checks
Titel:RedHat Security Advisory RHSA-2011:0414
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing updates announced in
advisory RHSA-2011:0414.

The policycoreutils packages contain the core utilities that are
required for the basic operation of a Security-Enhanced Linux (SELinux)
system and its policies.

It was discovered that the seunshare utility did not enforce proper file
permissions on the directory used as an alternate temporary directory
mounted as /tmp/. A local user could use this flaw to overwrite files or,
possibly, execute arbitrary code with the privileges of a setuid or
setgid application that relies on proper /tmp/ permissions, by running that
application via seunshare. (CVE-2011-1011)

Red Hat would like to thank Tavis Ormandy for reporting this issue.

This update also introduces the following changes:

* The seunshare utility was moved from the main policycoreutils subpackage
to the policycoreutils-sandbox subpackage. This utility is only required
by the sandbox feature and does not need to be installed by default.

* Updated selinux-policy packages that add the SELinux policy changes
required by the seunshare fixes.

All policycoreutils users should upgrade to these updated packages, which
correct this issue.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2011-0414.html

Risk factor : High

CVSS Score:
6.9

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-1011
BugTraq ID: 46510
http://www.securityfocus.com/bid/46510
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056227.html
http://archives.neohapsis.com/archives/fulldisclosure/2011-02/0585.html
http://openwall.com/lists/oss-security/2011/02/23/1
http://openwall.com/lists/oss-security/2011/02/23/2
http://www.redhat.com/support/errata/RHSA-2011-0414.html
http://www.securitytracker.com/id?1025291
http://secunia.com/advisories/43415
http://secunia.com/advisories/43844
http://secunia.com/advisories/44034
http://www.vupen.com/english/advisories/2011/0701
http://www.vupen.com/english/advisories/2011/0864
XForce ISS Database: policycoreutils-seunshare-symlink(65641)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65641
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.