Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.60958
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2008:0061
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2008:0061.

The setroubleshoot packages provide tools to help diagnose SELinux
problems. When AVC messages occur, an alert is generated that gives
information about the problem, and how to create a resolution.

A flaw was found in the way sealert wrote diagnostic messages to a
temporary file. A local unprivileged user could perform a symbolic link
attack, and cause arbitrary files, writable by other users, to be
overwritten when a victim runs sealert. (CVE-2007-5495)

A flaw was found in the way sealert displayed records from the
setroubleshoot database as unescaped HTML. An local unprivileged attacker
could cause AVC denial events with carefully crafted process or file names,
injecting arbitrary HTML tags into the logs, which could be used as a
scripting attack, or to confuse the user running sealert. (CVE-2007-5496)

Users of setroubleshoot are advised to upgrade to these updated packages,
which resolve these issues.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2008-0061.html
http://www.redhat.com/security/updates/classification/#moderate

Risk factor : Medium

CVSS Score:
4.4

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-5495
1020077
http://securitytracker.com/id?1020077
29320
http://www.securityfocus.com/bid/29320
30339
http://secunia.com/advisories/30339
RHSA-2008:0061
http://www.redhat.com/support/errata/RHSA-2008-0061.html
https://bugzilla.redhat.com/show_bug.cgi?id=288221
oval:org.mitre.oval:def:9705
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9705
setroubleshoot-sealert-symlink(42591)
https://exchange.xforce.ibmcloud.com/vulnerabilities/42591
Common Vulnerability Exposure (CVE) ID: CVE-2007-5496
1020078
http://securitytracker.com/id?1020078
29324
http://www.securityfocus.com/bid/29324
https://bugzilla.redhat.com/show_bug.cgi?id=288271
oval:org.mitre.oval:def:10455
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10455
setroubleshoot-sealert-avc-xss(42592)
https://exchange.xforce.ibmcloud.com/vulnerabilities/42592
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.