vulnerability
Oracle Linux: CVE-2016-4989: ELSA-2016-1267: setroubleshoot and setroubleshoot-plugins security update (IMPORTANT) (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 6 | (AV:L/AC:H/Au:S/C:C/I:C/A:C) | Jun 21, 2016 | Jun 21, 2016 | Jan 7, 2025 |
Severity
6
CVSS
(AV:L/AC:H/Au:S/C:C/I:C/A:C)
Published
Jun 21, 2016
Added
Jun 21, 2016
Modified
Jan 7, 2025
Description
setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by (1) triggering an SELinux denial with a crafted file name, which is handled by the _set_tpath function in audit_data.py or via a crafted (2) local_id or (3) analysis_id field in a crafted XML document to the run_fix function in SetroubleshootFixit.py, related to the subprocess.check_output and commands.getstatusoutput functions, a different vulnerability than CVE-2016-4445.
Solutions
oracle-linux-upgrade-setroubleshootoracle-linux-upgrade-setroubleshoot-docoracle-linux-upgrade-setroubleshoot-pluginsoracle-linux-upgrade-setroubleshoot-server
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.