CVE Database
/

CVE-2011-1011

Back to search

CVE-2011-1011

Published: Feb 24, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterprise Linux (RHEL) 6 and earlier, and Fedora 14 and earlier, mounts a new directory on top of /tmp without assigning root ownership and the sticky bit to this new directory, which allows local users to replace or delete arbitrary /tmp files, and consequently cause a denial of service or possibly gain privileges, by running a setuid application that relies on /tmp, as demonstrated by the ksu application.

VendorProductVersions

n/a

n/a

affected
n/a

References

44034
third-party-advisory
x_refsource_SECUNIA
1025291
vdb-entry
x_refsource_SECTRACK
43844
third-party-advisory
x_refsource_SECUNIA
ADV-2011-0701
vdb-entry
x_refsource_VUPEN
FEDORA-2011-3043
vendor-advisory
x_refsource_FEDORA
RHSA-2011:0414
vendor-advisory
x_refsource_REDHAT
ADV-2011-0864
vdb-entry
x_refsource_VUPEN
46510
vdb-entry
x_refsource_BID
[oss-security] 20110222 CVE Request
mailing-list
x_refsource_MLIST
43415
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20110223 Re: CVE Request
mailing-list
x_refsource_MLIST

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now