Debian Policycoreutils vulnerabilities
2 known vulnerabilities affecting debian/policycoreutils.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2016-7545P3HIGHCVSS 8.8fixed in policycoreutils 2.5-3 (bookworm)2016
CVE-2016-7545 [HIGH] CVE-2016-7545: policycoreutils - SELinux policycoreutils allows local users to execute arbitrary commands outside...
SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
Scope: local
bookworm: resolved (fixed in 2.5-3)
bullseye: resolved (fixed in 2.5-3)
forky: resolved (fixed in 2.5-3)
sid: resolved (fixed in 2.5-3)
trixie: resolved (fixed in 2.5-3)
debian
CVE-2018-1063P4MEDIUMCVSS 4.4fixed in policycoreutils 2.7-1 (bookworm)2018
CVE-2018-1063 [MEDIUM] CVE-2018-1063: policycoreutils - Context relabeling of filesystems is vulnerable to symbolic link attack, allowin...
Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a context with few restrictions. This only happens when the relabeling process is done, usually when taking SELinux state from disabled to enable (permissive or enforcing). The issue wa
debian