Lucene search

K
redhatRedHatRHSA-2017:0536
HistoryMar 15, 2017 - 1:36 p.m.

(RHSA-2017:0536) Important: policycoreutils security update

2017-03-1513:36:15
access.redhat.com
53

EPSS

0

Percentile

5.1%

The policycoreutils packages contain the core policy utilities required to manage a SELinux environment.

Security Fix(es):

  • It was found that the sandbox tool provided in policycoreutils was vulnerable to a TIOCSTI ioctl attack. A specially crafted program executed via the sandbox command could use this flaw to execute arbitrary commands in the context of the parent shell, escaping the sandbox. (CVE-2016-7545)