The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafted filename, related to the commands.getoutput function.
CPE | Name | Operator | Version |
---|---|---|---|
enterprise_linux_desktop | eq | 7.0 | |
enterprise_linux_hpc_node | eq | 7.0 | |
enterprise_linux_server | eq | 7.0 | |
enterprise_linux_workstation | eq | 7.0 |
seclists.org/oss-sec/2016/q2/575
www.securityfocus.com/bid/91427
www.securitytracker.com/id/1036144
access.redhat.com/errata/RHSA-2016:1293
bugzilla.redhat.com/show_bug.cgi?id=1339250
github.com/fedora-selinux/setroubleshoot/commit/eaccf4c0d20a27d3df5ff6de8c9dcc80f6f40718
rhn.redhat.com/errata/RHSA-2016-1267.html