ZeroHour

CVE-2016-4445

PoC
CVSS 3.0
7.0 high
EPSS
<1%p40
Published
()
Modified
Description

The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELinux denial with a crafted file name, related to executing external commands with the commands.getstatusoutput function.

Vendors
setroubleshoot projectredhat
Products
setroubleshoot, enterprise linux desktop, enterprise linux hpc node, enterprise linux server, enterprise linux workstation
Weakness
CWE-77
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.