selinux-policy-3.7.19-54.AXS4.5, policycoreutils-2.0.83-19.8.AXS4

エラータID: AXSA:2011-152:01

リリース日: 
2011/04/20 Wednesday - 21:50
題名: 
selinux-policy-3.7.19-54.AXS4.5, policycoreutils-2.0.83-19.8.AXS4
影響のあるチャネル: 
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity: 
High
Description: 

Security-enhanced Linux is a feature of the Linux® kernel and a number of utilities with enhanced security functionality designed to add mandatory access controls to Linux. The Security-enhanced Linux kernel contains new architectural components originally developed to improve the security of the Flask operating system. These architectural components provide general support for the enforcement of many kinds of mandatory access control policies, including those based on the concepts of Type Enforcement®, Role-based Access Control, and Multi-level Security.
policycoreutils contains the policy core utilities that are required for basic operation of a SELinux system. These utilities include load_policy to load policies, setfiles to label filesystems, newrole to switch roles, and run_init to run /etc/init.d scripts in the proper context.
Security issues fixed with this release:
CVE-2011-1011
The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Asianux packages of policycoreutils 2.0.83 and earlier in Asianux Server 4 and earlier, mounts a new directory on top of /tmp without assigning root ownership and the sticky bit to this new directory, which allows local users to replace or delete arbitrary /tmp files, and consequently cause a denial of service or possibly gain privileges, by running a setuid application that relies on /tmp, as demonstrated by the ksu application.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. policycoreutils-2.0.83-19.8.AXS4.src.rpm
    MD5: 31ab3dc032833f04b5b52bae96ac7caf
    SHA-256: 4121caf13de5247d6357bebc71754f1394c7c62831c0612840573c0ff4c2f227
    Size: 2.87 MB
  2. selinux-policy-3.7.19-54.AXS4.5.src.rpm
    MD5: 0f884c3f093fcc27774863ec03ca47ac
    SHA-256: 84317d1dfc02c99fecbfa0c10121a662f476de30ab39be133746b43e5b4185b2
    Size: 18.56 MB

Asianux Server 4 for x86
  1. policycoreutils-2.0.83-19.8.AXS4.i686.rpm
    MD5: dea084159ce90bb991a05baaa8f4b995
    SHA-256: 4efafe84f19ab6e1f33dae04d3c64d9b073abcf02593045205ef371e4305b700
    Size: 669.43 kB
  2. policycoreutils-gui-2.0.83-19.8.AXS4.i686.rpm
    MD5: 555465a33ad4a26ef0df9c2e57c3b420
    SHA-256: f0208867494680daa3ba87f72ec4fa3aab46e31a7d43056090b467fa3ae1c6f4
    Size: 205.01 kB
  3. policycoreutils-newrole-2.0.83-19.8.AXS4.i686.rpm
    MD5: 32093f7fa94fc67d9941e92a440bae6f
    SHA-256: f5e8eb987e6d6ec77ba04654014fdb1e096999098e34e0d82312921ae9d956e8
    Size: 104.80 kB
  4. policycoreutils-python-2.0.83-19.8.AXS4.i686.rpm
    MD5: e0ec4ae9f3da0a1ef9f899f74bf87131
    SHA-256: add6a093b54cf9004ac5061354bc067d9cc5784e178ece3040531faac886ad22
    Size: 330.86 kB
  5. policycoreutils-sandbox-2.0.83-19.8.AXS4.i686.rpm
    MD5: 4fce5a01c42d70b91207612894bda122
    SHA-256: 13b57b0912a79c0d0a0e1ad6c1f793c100fccb6a0a012e484de2443a23fc3345
    Size: 105.56 kB

Asianux Server 4 for x86_64
  1. policycoreutils-2.0.83-19.8.AXS4.x86_64.rpm
    MD5: c7ba8cdaa4dd62e81efea9e9fc4d377a
    SHA-256: 4fea53a3b465d2154f7e6838b00a41f132584d61247e7727a0a7a1c83d884604
    Size: 674.30 kB
  2. policycoreutils-gui-2.0.83-19.8.AXS4.x86_64.rpm
    MD5: 01393f272f2c12b6b4e1aeb72671073f
    SHA-256: 3f61a76dce2013161338e2a222cd9d963fd7eab09b7376085ec33bb60a195390
    Size: 204.54 kB
  3. policycoreutils-newrole-2.0.83-19.8.AXS4.x86_64.rpm
    MD5: 7aae9dcab363146ddac2ee02355825c5
    SHA-256: 48ae48cddee7f54697437300576386aeeb06a18284eb526df0a8bf41652c7e51
    Size: 104.79 kB
  4. policycoreutils-python-2.0.83-19.8.AXS4.x86_64.rpm
    MD5: cc4df8e8eaf5bdcbc583474de62d1ce2
    SHA-256: 5c89e104d29cb1a3edb42e419ee92b048d6bc97431d02d486346bf76163e0cb3
    Size: 332.70 kB
  5. policycoreutils-sandbox-2.0.83-19.8.AXS4.x86_64.rpm
    MD5: 841ac1dc77751f4383ab477a3c1d3647
    SHA-256: 0d347f88e23121eee976f7ff62c67f527df2cec1fb33f56b2ae5583f9ecf07ab
    Size: 104.95 kB