Oval Definition:oval:com.redhat.rhsa:def:20110414
Revision Date:2011-04-04Version:638
Title:RHSA-2011:0414: policycoreutils security update (Important)
Description:The policycoreutils packages contain the core utilities that are required for the basic operation of a Security-Enhanced Linux (SELinux) system and its policies.

  • It was discovered that the seunshare utility did not enforce proper file permissions on the directory used as an alternate temporary directory mounted as /tmp/. A local user could use this flaw to overwrite files or, possibly, execute arbitrary code with the privileges of a setuid or setgid application that relies on proper /tmp/ permissions, by running that application via seunshare. (CVE-2011-1011)

    Red Hat would like to thank Tavis Ormandy for reporting this issue.

    This update also introduces the following changes:

    The seunshare utility was moved from the main policycoreutils subpackage to the policycoreutils-sandbox subpackage. This utility is only required by the sandbox feature and does not need to be installed by default.

    Updated selinux-policy packages that add the SELinux policy changes required by the seunshare fixes.

    All policycoreutils users should upgrade to these updated packages, which correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-1011
    CVE-2011-1011
    RHSA-2011:0414
    RHSA-2011:0414-01
    RHSA-2011:0414-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • selinux-policy is earlier than 0:3.7.19-54.el6_0.5
  • AND selinux-policy is signed with Red Hat redhatrelease2 key
  • selinux-policy-doc is earlier than 0:3.7.19-54.el6_0.5
  • AND selinux-policy-doc is signed with Red Hat redhatrelease2 key
  • selinux-policy-minimum is earlier than 0:3.7.19-54.el6_0.5
  • AND selinux-policy-minimum is signed with Red Hat redhatrelease2 key
  • selinux-policy-mls is earlier than 0:3.7.19-54.el6_0.5
  • AND selinux-policy-mls is signed with Red Hat redhatrelease2 key
  • selinux-policy-targeted is earlier than 0:3.7.19-54.el6_0.5
  • AND selinux-policy-targeted is signed with Red Hat redhatrelease2 key
  • policycoreutils is earlier than 0:2.0.83-19.8.el6_0
  • AND policycoreutils is signed with Red Hat redhatrelease2 key
  • policycoreutils-gui is earlier than 0:2.0.83-19.8.el6_0
  • AND policycoreutils-gui is signed with Red Hat redhatrelease2 key
  • policycoreutils-newrole is earlier than 0:2.0.83-19.8.el6_0
  • AND policycoreutils-newrole is signed with Red Hat redhatrelease2 key
  • policycoreutils-python is earlier than 0:2.0.83-19.8.el6_0
  • AND policycoreutils-python is signed with Red Hat redhatrelease2 key
  • policycoreutils-sandbox is earlier than 0:2.0.83-19.8.el6_0
  • AND policycoreutils-sandbox is signed with Red Hat redhatrelease2 key
  • BACK