VDB
CVE-2011-1011
CVE-2011-1011
PUBLISHED
CVSS 6.900000095367432 MEDIUM
The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterprise Linux (RHEL) 6 and earlier, and Fedora 14 and earlier, mounts a new directory on top of /tmp without assigning root ownership and the sticky bit to this new directory, which allows local users to replace or delete arbitrary /tmp files, and consequently cause a denial of service or possibly gain privileges, by running a setuid application that relies on /tmp, as demonstrated by the ksu application.
EPSS 0.04% · 14.0th percentile
Risk Scores
CVSS 2.0
6.900000095367432
EPSS Score
0.04%
14.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | fedora | 14, 6, 7 |
| n/a | n/a | n/a |
| redhat | enterprise_linux | 3, 4, 5 |
| redhat | policycoreutils | 1.21.2, 1.21.3, 1.21.5 |
Timeline
- Feb 24, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- http://openwall.com/lists/oss-security/2011/02/23/1 url
- http://openwall.com/lists/oss-security/2011/02/23/2 url
- http://www.redhat.com/support/errata/RHSA-2011-0414.html technical
- http://www.securityfocus.com/bid/46510 technical
- https://bugzilla.redhat.com/show_bug.cgi?id=633544 url
- 44034 third-party-advisory
- 20110222 Developers should not rely on the stickiness of /tmp on Red Hat Linux mailing-list
- 1025291 vdb
- http://pkgs.fedoraproject.org/gitweb/?p=policycoreutils.git%3Ba=blob%3Bf=policycoreutils-rhat.patch%3Bh=d4db5bc06027de23d12a4b3f18fa6f9b1517df27%3Bhb=HEAD#l2197 url
- policycoreutils-seunshare-symlink(65641) vdb
- 43844 third-party-advisory
- ADV-2011-0701 vdb
- FEDORA-2011-3043 vendor-advisory
- ADV-2011-0864 vdb
- 43415 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-1011 advisory
- http://pkgs.fedoraproject.org/gitweb/?p=policycoreutils.git;a=blob;f=policycoreutils-rhat.patch;h=d4db5bc06027de23d12a4b3f18fa6f9b1517df27;hb=HEAD#l2197 url