跳转到帖子

CentOS Linux: CVE-2023-3972: Important: insights-client security update (CESA-2023:6795)

recommended_posts

发布于
  • Members

CentOS Linux: CVE-2023-3972: Important: insights-client security update (CESA-2023:6795)

Severity
7
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
11/01/2023
Created
11/04/2023
Added
11/03/2023
Modified
01/28/2025

Description

A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could create the /var/tmp/insights-client directory (owning the directory with read, write, and execute permissions) on the system. After the insights-client is registered by root, an attacker could then control the directory content that insights are using by putting malicious scripts into it and executing arbitrary code as root (trivially bypassing SELinux protections because insights processes are allowed to disable SELinux system-wide).

Solution(s)

  • centos-upgrade-insights-client

References

  • CVE-2023-3972
  • 查看数 706
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…