CVE-2018-1063
4.4
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 1.8 / Impact: 2.5
Source: NVD
Description
Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a context with few restrictions. This only happens when the relabeling process is done, usually when taking SELinux state from disabled to enable (permissive or enforcing). The issue was found in policycoreutils 2.5-11.
Affected (2)
Products: Redhat: Enterprise Linux · Selinux Project: Selinux
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
References (4)
Source: secalert@redhat.com
Source: secalert@redhat.com
Issue TrackingMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationVendor Advisory
Timeline
No history available yet.