The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterprise Linux (RHEL) 6 and earlier, and Fedora 14 and earlier, mounts a new directory on top of /tmp without assigning root ownership and the sticky bit to this new directory, which allows local users to replace or delete arbitrary /tmp files, and consequently cause a denial of service or possibly gain privileges, by running a setuid application that relies on /tmp, as demonstrated by the ksu application.
2011-02-24T21:00:18.253
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.9 (MEDIUM)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | policycoreutils | ≤ 2.0.83 | Yes |
Application | redhat | policycoreutils | 1.0 | Yes |
Application | redhat | policycoreutils | 1.1 | Yes |
Application | redhat | policycoreutils | 1.2 | Yes |
Application | redhat | policycoreutils | 1.4 | Yes |
Application | redhat | policycoreutils | 1.6 | Yes |
Application | redhat | policycoreutils | 1.8 | Yes |
Application | redhat | policycoreutils | 1.10 | Yes |
Application | redhat | policycoreutils | 1.12 | Yes |
Application | redhat | policycoreutils | 1.14 | Yes |
Application | redhat | policycoreutils | 1.16 | Yes |
Application | redhat | policycoreutils | 1.18 | Yes |
Application | redhat | policycoreutils | 1.20 | Yes |
Application | redhat | policycoreutils | 1.21.1 | Yes |
Application | redhat | policycoreutils | 1.21.2 | Yes |
Application | redhat | policycoreutils | 1.21.3 | Yes |
Application | redhat | policycoreutils | 1.21.4 | Yes |
Application | redhat | policycoreutils | 1.21.5 | Yes |
Application | redhat | policycoreutils | 1.21.6 | Yes |
Application | redhat | policycoreutils | 1.21.7 | Yes |
Application | redhat | policycoreutils | 1.21.8 | Yes |
Application | redhat | policycoreutils | 1.21.9 | Yes |
Application | redhat | policycoreutils | 1.21.10 | Yes |
Application | redhat | policycoreutils | 1.21.11 | Yes |
Application | redhat | policycoreutils | 1.21.12 | Yes |
Application | redhat | policycoreutils | 1.21.13 | Yes |
Application | redhat | policycoreutils | 1.21.14 | Yes |
Application | redhat | policycoreutils | 1.21.15 | Yes |
Application | redhat | policycoreutils | 1.21.16 | Yes |
Application | redhat | policycoreutils | 1.21.17 | Yes |
Application | redhat | policycoreutils | 1.21.18 | Yes |
Application | redhat | policycoreutils | 1.21.19 | Yes |
Application | redhat | policycoreutils | 1.21.20 | Yes |
Application | redhat | policycoreutils | 1.21.21 | Yes |
Application | redhat | policycoreutils | 1.21.22 | Yes |
Application | redhat | policycoreutils | 1.22 | Yes |
Application | redhat | policycoreutils | 1.23.1 | Yes |
Application | redhat | policycoreutils | 1.23.2 | Yes |
Application | redhat | policycoreutils | 1.23.3 | Yes |
Application | redhat | policycoreutils | 1.23.4 | Yes |
Application | redhat | policycoreutils | 1.23.5 | Yes |
Application | redhat | policycoreutils | 1.23.6 | Yes |
Application | redhat | policycoreutils | 1.23.7 | Yes |
Application | redhat | policycoreutils | 1.23.8 | Yes |
Application | redhat | policycoreutils | 1.23.9 | Yes |
Application | redhat | policycoreutils | 1.23.10 | Yes |
Application | redhat | policycoreutils | 1.23.11 | Yes |
Application | redhat | policycoreutils | 1.24 | Yes |
Application | redhat | policycoreutils | 1.25.1 | Yes |
Application | redhat | policycoreutils | 1.25.2 | Yes |
Application | redhat | policycoreutils | 1.25.3 | Yes |
Application | redhat | policycoreutils | 1.25.4 | Yes |
Application | redhat | policycoreutils | 1.25.5 | Yes |
Application | redhat | policycoreutils | 1.25.6 | Yes |
Application | redhat | policycoreutils | 1.25.7 | Yes |
Application | redhat | policycoreutils | 1.25.8 | Yes |
Application | redhat | policycoreutils | 1.25.9 | Yes |
Application | redhat | policycoreutils | 1.26 | Yes |
Application | redhat | policycoreutils | 1.27.1 | Yes |
Application | redhat | policycoreutils | 1.27.2 | Yes |
Application | redhat | policycoreutils | 1.27.3 | Yes |
Application | redhat | policycoreutils | 1.27.4 | Yes |
Application | redhat | policycoreutils | 1.27.5 | Yes |
Application | redhat | policycoreutils | 1.27.6 | Yes |
Application | redhat | policycoreutils | 1.27.7 | Yes |
Application | redhat | policycoreutils | 1.27.8 | Yes |
Application | redhat | policycoreutils | 1.27.9 | Yes |
Application | redhat | policycoreutils | 1.27.10 | Yes |
Application | redhat | policycoreutils | 1.27.11 | Yes |
Application | redhat | policycoreutils | 1.27.12 | Yes |
Application | redhat | policycoreutils | 1.27.13 | Yes |
Application | redhat | policycoreutils | 1.27.14 | Yes |
Application | redhat | policycoreutils | 1.27.15 | Yes |
Application | redhat | policycoreutils | 1.27.16 | Yes |
Application | redhat | policycoreutils | 1.27.17 | Yes |
Application | redhat | policycoreutils | 1.27.18 | Yes |
Application | redhat | policycoreutils | 1.27.19 | Yes |
Application | redhat | policycoreutils | 1.27.20 | Yes |
Application | redhat | policycoreutils | 1.27.21 | Yes |
Application | redhat | policycoreutils | 1.27.22 | Yes |
Application | redhat | policycoreutils | 1.27.23 | Yes |
Application | redhat | policycoreutils | 1.27.24 | Yes |
Application | redhat | policycoreutils | 1.27.25 | Yes |
Application | redhat | policycoreutils | 1.27.26 | Yes |
Application | redhat | policycoreutils | 1.27.27 | Yes |
Application | redhat | policycoreutils | 1.27.28 | Yes |
Application | redhat | policycoreutils | 1.27.29 | Yes |
Application | redhat | policycoreutils | 1.27.30 | Yes |
Application | redhat | policycoreutils | 1.27.31 | Yes |
Application | redhat | policycoreutils | 1.27.32 | Yes |
Application | redhat | policycoreutils | 1.27.33 | Yes |
Application | redhat | policycoreutils | 1.27.34 | Yes |
Application | redhat | policycoreutils | 1.27.35 | Yes |
Application | redhat | policycoreutils | 1.27.36 | Yes |
Application | redhat | policycoreutils | 1.27.37 | Yes |
Application | redhat | policycoreutils | 1.28 | Yes |
Application | redhat | policycoreutils | 1.29.1 | Yes |
Application | redhat | policycoreutils | 1.29.2 | Yes |
Application | redhat | policycoreutils | 1.29.3 | Yes |
Application | redhat | policycoreutils | 1.29.4 | Yes |
Application | redhat | policycoreutils | 1.29.5 | Yes |
Application | redhat | policycoreutils | 1.29.6 | Yes |
Application | redhat | policycoreutils | 1.29.7 | Yes |
Application | redhat | policycoreutils | 1.29.8 | Yes |
Application | redhat | policycoreutils | 1.29.9 | Yes |
Application | redhat | policycoreutils | 1.29.10 | Yes |
Application | redhat | policycoreutils | 1.29.11 | Yes |
Application | redhat | policycoreutils | 1.29.12 | Yes |
Application | redhat | policycoreutils | 1.29.13 | Yes |
Application | redhat | policycoreutils | 1.29.14 | Yes |
Application | redhat | policycoreutils | 1.29.15 | Yes |
Application | redhat | policycoreutils | 1.29.16 | Yes |
Application | redhat | policycoreutils | 1.29.17 | Yes |
Application | redhat | policycoreutils | 1.29.18 | Yes |
Application | redhat | policycoreutils | 1.29.19 | Yes |
Application | redhat | policycoreutils | 1.29.20 | Yes |
Application | redhat | policycoreutils | 1.29.21 | Yes |
Application | redhat | policycoreutils | 1.29.22 | Yes |
Application | redhat | policycoreutils | 1.29.23 | Yes |
Application | redhat | policycoreutils | 1.29.24 | Yes |
Application | redhat | policycoreutils | 1.29.25 | Yes |
Application | redhat | policycoreutils | 1.29.26 | Yes |
Application | redhat | policycoreutils | 1.29.27 | Yes |
Application | redhat | policycoreutils | 1.29.28 | Yes |
Application | redhat | policycoreutils | 1.30 | Yes |
Application | redhat | policycoreutils | 1.30.1 | Yes |
Application | redhat | policycoreutils | 1.30.2 | Yes |
Application | redhat | policycoreutils | 1.30.3 | Yes |
Application | redhat | policycoreutils | 1.30.4 | Yes |
Application | redhat | policycoreutils | 1.30.5 | Yes |
Application | redhat | policycoreutils | 1.30.6 | Yes |
Application | redhat | policycoreutils | 1.30.7 | Yes |
Application | redhat | policycoreutils | 1.30.8 | Yes |
Application | redhat | policycoreutils | 1.30.9 | Yes |
Application | redhat | policycoreutils | 1.30.10 | Yes |
Application | redhat | policycoreutils | 1.30.11 | Yes |
Application | redhat | policycoreutils | 1.30.12 | Yes |
Application | redhat | policycoreutils | 1.30.13 | Yes |
Application | redhat | policycoreutils | 1.30.14 | Yes |
Application | redhat | policycoreutils | 1.30.15 | Yes |
Application | redhat | policycoreutils | 1.30.16 | Yes |
Application | redhat | policycoreutils | 1.30.17 | Yes |
Application | redhat | policycoreutils | 1.30.18 | Yes |
Application | redhat | policycoreutils | 1.30.19 | Yes |
Application | redhat | policycoreutils | 1.30.20 | Yes |
Application | redhat | policycoreutils | 1.30.21 | Yes |
Application | redhat | policycoreutils | 1.30.22 | Yes |
Application | redhat | policycoreutils | 1.30.23 | Yes |
Application | redhat | policycoreutils | 1.30.24 | Yes |
Application | redhat | policycoreutils | 1.30.25 | Yes |
Application | redhat | policycoreutils | 1.30.26 | Yes |
Application | redhat | policycoreutils | 1.30.27 | Yes |
Application | redhat | policycoreutils | 1.30.28 | Yes |
Application | redhat | policycoreutils | 1.30.29 | Yes |
Application | redhat | policycoreutils | 1.30.30 | Yes |
Application | redhat | policycoreutils | 1.30.31 | Yes |
Application | redhat | policycoreutils | 1.32 | Yes |
Application | redhat | policycoreutils | 1.33.1 | Yes |
Application | redhat | policycoreutils | 1.33.2 | Yes |
Application | redhat | policycoreutils | 1.33.3 | Yes |
Application | redhat | policycoreutils | 1.33.4 | Yes |
Application | redhat | policycoreutils | 1.33.5 | Yes |
Application | redhat | policycoreutils | 1.33.6 | Yes |
Application | redhat | policycoreutils | 1.33.7 | Yes |
Application | redhat | policycoreutils | 1.33.8 | Yes |
Application | redhat | policycoreutils | 1.33.9 | Yes |
Application | redhat | policycoreutils | 1.33.10 | Yes |
Application | redhat | policycoreutils | 1.33.11 | Yes |
Application | redhat | policycoreutils | 1.33.12 | Yes |
Application | redhat | policycoreutils | 1.33.13 | Yes |
Application | redhat | policycoreutils | 1.33.14 | Yes |
Application | redhat | policycoreutils | 1.33.15 | Yes |
Application | redhat | policycoreutils | 1.33.16 | Yes |
Application | redhat | policycoreutils | 1.34.0 | Yes |
Application | redhat | policycoreutils | 1.34.1 | Yes |
Application | redhat | policycoreutils | 2.0.0 | Yes |
Application | redhat | policycoreutils | 2.0.1 | Yes |
Application | redhat | policycoreutils | 2.0.2 | Yes |
Application | redhat | policycoreutils | 2.0.3 | Yes |
Application | redhat | policycoreutils | 2.0.4 | Yes |
Application | redhat | policycoreutils | 2.0.5 | Yes |
Application | redhat | policycoreutils | 2.0.6 | Yes |
Application | redhat | policycoreutils | 2.0.7 | Yes |
Application | redhat | policycoreutils | 2.0.8 | Yes |
Application | redhat | policycoreutils | 2.0.9 | Yes |
Application | redhat | policycoreutils | 2.0.10 | Yes |
Application | redhat | policycoreutils | 2.0.11 | Yes |
Application | redhat | policycoreutils | 2.0.12 | Yes |
Application | redhat | policycoreutils | 2.0.13 | Yes |
Application | redhat | policycoreutils | 2.0.14 | Yes |
Application | redhat | policycoreutils | 2.0.15 | Yes |
Application | redhat | policycoreutils | 2.0.16 | Yes |
Application | redhat | policycoreutils | 2.0.17 | Yes |
Application | redhat | policycoreutils | 2.0.18 | Yes |
Application | redhat | policycoreutils | 2.0.19 | Yes |
Application | redhat | policycoreutils | 2.0.20 | Yes |
Application | redhat | policycoreutils | 2.0.21 | Yes |
Application | redhat | policycoreutils | 2.0.22 | Yes |
Application | redhat | policycoreutils | 2.0.23 | Yes |
Application | redhat | policycoreutils | 2.0.24 | Yes |
Application | redhat | policycoreutils | 2.0.25 | Yes |
Application | redhat | policycoreutils | 2.0.26 | Yes |
Application | redhat | policycoreutils | 2.0.27 | Yes |
Application | redhat | policycoreutils | 2.0.28 | Yes |
Application | redhat | policycoreutils | 2.0.29 | Yes |
Application | redhat | policycoreutils | 2.0.30 | Yes |
Application | redhat | policycoreutils | 2.0.31 | Yes |
Application | redhat | policycoreutils | 2.0.32 | Yes |
Application | redhat | policycoreutils | 2.0.33 | Yes |
Application | redhat | policycoreutils | 2.0.34 | Yes |
Application | redhat | policycoreutils | 2.0.35 | Yes |
Application | redhat | policycoreutils | 2.0.36 | Yes |
Application | redhat | policycoreutils | 2.0.37 | Yes |
Application | redhat | policycoreutils | 2.0.38 | Yes |
Application | redhat | policycoreutils | 2.0.39 | Yes |
Application | redhat | policycoreutils | 2.0.40 | Yes |
Application | redhat | policycoreutils | 2.0.41 | Yes |
Application | redhat | policycoreutils | 2.0.42 | Yes |
Application | redhat | policycoreutils | 2.0.43 | Yes |
Application | redhat | policycoreutils | 2.0.44 | Yes |
Application | redhat | policycoreutils | 2.0.45 | Yes |
Application | redhat | policycoreutils | 2.0.46 | Yes |
Application | redhat | policycoreutils | 2.0.47 | Yes |
Application | redhat | policycoreutils | 2.0.48 | Yes |
Application | redhat | policycoreutils | 2.0.49 | Yes |
Application | redhat | policycoreutils | 2.0.50 | Yes |
Application | redhat | policycoreutils | 2.0.51 | Yes |
Application | redhat | policycoreutils | 2.0.52 | Yes |
Application | redhat | policycoreutils | 2.0.53 | Yes |
Application | redhat | policycoreutils | 2.0.54 | Yes |
Application | redhat | policycoreutils | 2.0.55 | Yes |
Application | redhat | policycoreutils | 2.0.56 | Yes |
Application | redhat | policycoreutils | 2.0.57 | Yes |
Application | redhat | policycoreutils | 2.0.58 | Yes |
Application | redhat | policycoreutils | 2.0.59 | Yes |
Application | redhat | policycoreutils | 2.0.60 | Yes |
Application | redhat | policycoreutils | 2.0.61 | Yes |
Application | redhat | policycoreutils | 2.0.62 | Yes |
Application | redhat | policycoreutils | 2.0.63 | Yes |
Application | redhat | policycoreutils | 2.0.64 | Yes |
Application | redhat | policycoreutils | 2.0.65 | Yes |
Application | redhat | policycoreutils | 2.0.66 | Yes |
Application | redhat | policycoreutils | 2.0.67 | Yes |
Application | redhat | policycoreutils | 2.0.68 | Yes |
Application | redhat | policycoreutils | 2.0.69 | Yes |
Application | redhat | policycoreutils | 2.0.70 | Yes |
Application | redhat | policycoreutils | 2.0.71 | Yes |
Application | redhat | policycoreutils | 2.0.72 | Yes |
Application | redhat | policycoreutils | 2.0.73 | Yes |
Application | redhat | policycoreutils | 2.0.74 | Yes |
Application | redhat | policycoreutils | 2.0.75 | Yes |
Application | redhat | policycoreutils | 2.0.76 | Yes |
Application | redhat | policycoreutils | 2.0.77 | Yes |
Application | redhat | policycoreutils | 2.0.78 | Yes |
Application | redhat | policycoreutils | 2.0.79 | Yes |
Application | redhat | policycoreutils | 2.0.80 | Yes |
Application | redhat | policycoreutils | 2.0.81 | Yes |
Application | redhat | policycoreutils | 2.0.82 | Yes |
Operating System | redhat | enterprise_linux | 3 | Yes |
Operating System | redhat | enterprise_linux | 4 | Yes |
Operating System | redhat | enterprise_linux | 5 | Yes |
Operating System | redhat | enterprise_linux | 6.0 | Yes |
Operating System | redhat | fedora | 6 | Yes |
Operating System | redhat | fedora | 7 | Yes |
Operating System | redhat | fedora | 8 | Yes |
Operating System | redhat | fedora | 9 | Yes |
Operating System | redhat | fedora | 10 | Yes |
Operating System | redhat | fedora | 12 | Yes |
Operating System | redhat | fedora | 13 | Yes |
Operating System | redhat | fedora | 14 | Yes |