Lucene search

K
redhatRedHatRHSA-2016:2702
HistoryNov 14, 2016 - 10:43 a.m.

(RHSA-2016:2702) Important: policycoreutils security update

2016-11-1410:43:01
access.redhat.com
28

EPSS

0

Percentile

5.1%

The policycoreutils packages contain the core policy utilities required to manage a SELinux environment.

Security Fix(es):

  • It was found that the sandbox tool provided in policycoreutils was vulnerable to a TIOCSTI ioctl attack. A specially crafted program executed via the sandbox command could use this flaw to execute arbitrary commands in the context of the parent shell, escaping the sandbox. (CVE-2016-7545)