Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7545

Опубликовано: 22 сент. 2016
Источник: redhat
CVSS3: 8.6
CVSS2: 6.8
EPSS Низкий

Описание

SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.

It was found that the sandbox tool provided in policycoreutils was vulnerable to a TIOCSTI ioctl attack. A specially crafted program executed via the sandbox command could use this flaw to execute arbitrary commands in the context of the parent shell, escaping the sandbox.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5policycoreutilsNot affected
Red Hat Enterprise Linux 6policycoreutilsFixedRHSA-2016:270214.11.2016
Red Hat Enterprise Linux 7policycoreutilsFixedRHSA-2016:270214.11.2016
Red Hat Enterprise Linux 7.1 Extended Update SupportpolicycoreutilsFixedRHSA-2017:053615.03.2017
Red Hat Enterprise Linux 7.2 Extended Update SupportpolicycoreutilsFixedRHSA-2017:053515.03.2017

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1378577policycoreutils: SELinux sandbox escape via TIOCSTI ioctl

EPSS

Процентиль: 10%
0.00036
Низкий

8.6 High

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 9 лет назад

SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.

CVSS3: 8.8
nvd
почти 9 лет назад

SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.

CVSS3: 8.8
debian
почти 9 лет назад

SELinux policycoreutils allows local users to execute arbitrary comman ...

suse-cvrf
почти 9 лет назад

Security update for policycoreutils

suse-cvrf
почти 9 лет назад

Security update for policycoreutils

EPSS

Процентиль: 10%
0.00036
Низкий

8.6 High

CVSS3

6.8 Medium

CVSS2