Back

MEDIUM

policycoreutils: insecure temporary directory handling in seunshare

Published Feb 24, 2011

Description

The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterprise Linux (RHEL) 6 and earlier, and Fedora 14 and earlier, mounts a new directory on top of /tmp without assigning root ownership and the sticky bit to this new directory, which allows local users to replace or delete arbitrary /tmp files, and consequently cause a denial of service or possibly gain privileges, by running a setuid application that relies on /tmp, as demonstrated by the ksu application.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 24, 2011
Updated Aug 6, 2024
Reserved Feb 14, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Feb 22, 2011