Bug 1346461 (CVE-2016-4989)
| Summary: | CVE-2016-4989 setroubleshoot: command injection issues | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | lvrabec, mgrepl, mmalik, plautrba, security-response-team, ssekidde |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | setroubleshoot 3.2.27.1, setroubleshoot 3.3.9.1 | Doc Type: | If docs needed, set a value |
| Doc Text: |
Shell command injection flaws were found in the way the setroubleshoot executed external commands. A local attacker able to trigger certain SELinux denials could use these flaws to execute arbitrary code with root privileges.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2016-06-23 10:55:56 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1339375, 1339377, 1346462, 1346463, 1348526 | ||
| Bug Blocks: | 1332645 | ||
|
Description
Tomas Hoger
2016-06-14 21:41:39 UTC
Acknowledgments: Name: Red Hat Product Security Note that this issue was independently reported by Sebastian Krahmer (SuSE Security Team). The impact of this issue on Red Hat Enterprise Linux 7.2 and later is reduced, as setroubleshootd does not run with root privileges, but with privileges of a dedicated non-root user setroubleshoot. The SetroubleshootFixit service runs with root privileges but, as noted in comment 0, there are currently no known attacks against the service. Note that this issue was originally handled as part of the CVE-2016-4445 (bug 1339183), but was later split out because of different fixed-in versions. Public now via: http://seclists.org/oss-sec/2016/q2/574 Sebastian Krahmer's exploit: https://github.com/stealth/troubleshooter/blob/master/straight-shooter.c Created setroubleshoot tracking bugs for this issue: Affects: fedora-all [bug 1348526] Upstream commits: https://github.com/fedora-selinux/setroubleshoot/commit/e69378d7e82a503534d29c5939fa219341e8f2ad https://github.com/fedora-selinux/setroubleshoot/commit/dda55aa50db95a25f0d919c3a0d5871827cdc40f This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2016:1267 https://access.redhat.com/errata/RHSA-2016:1267 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:1293 https://access.redhat.com/errata/RHSA-2016:1293 |