CVE-2011-1011

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
24/02/2011
Last modified:
11/04/2025

Description

The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterprise Linux (RHEL) 6 and earlier, and Fedora 14 and earlier, mounts a new directory on top of /tmp without assigning root ownership and the sticky bit to this new directory, which allows local users to replace or delete arbitrary /tmp files, and consequently cause a denial of service or possibly gain privileges, by running a setuid application that relies on /tmp, as demonstrated by the ksu application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:policycoreutils:*:*:*:*:*:*:*:* 2.0.83 (including)
cpe:2.3:a:redhat:policycoreutils:1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:policycoreutils:1.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:policycoreutils:1.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:policycoreutils:1.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:policycoreutils:1.6:*:*:*:*:*:*:*
cpe:2.3:a:redhat:policycoreutils:1.8:*:*:*:*:*:*:*
cpe:2.3:a:redhat:policycoreutils:1.10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:policycoreutils:1.12:*:*:*:*:*:*:*
cpe:2.3:a:redhat:policycoreutils:1.14:*:*:*:*:*:*:*
cpe:2.3:a:redhat:policycoreutils:1.16:*:*:*:*:*:*:*
cpe:2.3:a:redhat:policycoreutils:1.18:*:*:*:*:*:*:*
cpe:2.3:a:redhat:policycoreutils:1.20:*:*:*:*:*:*:*
cpe:2.3:a:redhat:policycoreutils:1.21.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:policycoreutils:1.21.2:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools