Wind River Support Network

HomeDefectsLIN7-253
Fixed

LIN7-253 : Security Advisory - policycoreutils - CVE-2014-3215

Created: Jul 20, 2014    Updated: Mar 4, 2016
Resolved Date: Nov 24, 2014
Found In Version: 7.0
Fix Version: 7.0.0.0.LB19
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

seunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions, and executes programs in a way that changes the relationship between the setuid system call and the getresuid saved set-user-ID value, which makes it easier for local users to gain privileges by leveraging a program that mistakenly expected that it could permanently drop privileges.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3215
Live chat
Online