CVE-2016-4446

CWE-77Command Injection6 documents5 sources
Severity
7.0HIGH
EPSS
0.1%
top 77.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11
Latest updateMay 17

Description

The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafted filename, related to the commands.getoutput function.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-chj8-3w35-5698: The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafte2022-05-17
CVEList
CVE-2016-4446: The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafte2017-04-11

📋Vendor Advisories

1
Red Hat
setroubleshoot-plugins: insecure commands.getoutput use in the allow_execstack plugin2016-06-21

💬Community

2
Bugzilla
CVE-2016-4446 setroubleshoot-plugins: insecure commands.getoutput use in the allow_execstack plugin [fedora-all]2016-06-21
Bugzilla
CVE-2016-4446 setroubleshoot-plugins: insecure commands.getoutput use in the allow_execstack plugin2016-05-24