主要脆弱性情報 概要 (Synopsis): - 重要:setroubleshoot および setroubleshoot-plugins のセキュリティ更新 種類/重大度 (Type/Severity): - セキュリティ勧告:重要 主題 (Topic): - Red Hat Enterprise Linux 6 向けの setroubleshoot および setroubleshoot-plugins の更新が利用可能になりました。 説明 (Description): - setroubleshoot パッケージは、SELinux の問題を診断するためのツールを提供します。Access Vector Cache (AVC) メッセージが返された際、問題の情報を提供し、解決策の追跡を支援するアラートを生成できます。 - setroubleshoot-plugins は、SELinux AVC データおよびシステムデータを分析する分析プラグインのセットを提供し、ユーザーフレンドリーなレポートを生成します。 セキュリティ修正 (Security Fixes): - setroubleshoot が外部コマンドを実行する際に Shell コマンドインジェクション脆弱性が見つかり、権限昇格を招く可能性があります。(CVE-2016-4445, CVE-2016-4989) - setroubleshoot および allow_execmod および allow_execstack プラグインが外部コマンドを実行する際に Shell コマンドインジェクション脆弱性が見つかり、権限昇格を招く可能性があります。(CVE-2016-4444, CVE-2016-4446) 解決策 (Solution): - この更新の適用に関する詳細については、以下を参照してください:https://access.redhat.com/articles/11258 影響を受ける製品 (Affected Products): - Red Hat Enterprise Linux Server 6 x86_64 - Red Hat Enterprise Linux Server 6 i386 - Red Hat Enterprise Linux Server - Extended Life Cycle Support 6 x86_64 - Red Hat Enterprise Linux Server - Extended Life Cycle Support 6 i386 - Red Hat Enterprise Linux Workstation 6 x86_64 - Red Hat Enterprise Linux Workstation 6 i386 - Red Hat Enterprise Linux Desktop 6 x86_64 - Red Hat Enterprise Linux Desktop 6 i386 - Red Hat Enterprise Linux for IBM z Systems 6 s390x - Red Hat Enterprise Linux for Power, big endian 6 ppc64 - Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 6 s390x - Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6 x86_64 - Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6 i386 - Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension (for IBM z Systems) 6 s390x 修正 (Fixes): - BZ - 1332644 - CVE-2016-4444 setroubleshoot-plugins: allow_execmod プラグインにおける安全でないコマンドの問題 - BZ - 1339183 - CVE-2016-4445 setroubleshoot: getStatusOutput コマンドの安全でない使用 - BZ - 1339250 - CVE-2016-4446 setroubleshoot-plugins: allow_execstack プラグインにおける安全でないコマンドの問題 - BZ - 1346461 - CVE-2016-4989 setroubleshoot: コマンドインジェクションの問題 CVEs: - CVE-2016-4444 - CVE-2016-4445 - CVE-2016-4446 - CVE-2016-4989 参考文献 (References): - http://www.redhat.com/security/updates/classification/#normal