Synopsis:          Important: setroubleshoot and setroubleshoot-plugins security update
Advisory ID:       SLSA-2016:1267-1
Issue Date:        2016-06-21
CVE Numbers:       CVE-2016-4444
                   CVE-2016-4445
                   CVE-2016-4446
                   CVE-2016-4989
--

The setroubleshoot-plugins package provides a set of analysis plugins for
use with setroubleshoot. Each plugin has the capacity to analyze SELinux
AVC data and system data to provide user friendly reports describing how
to interpret SELinux AVC denials.

Security Fix(es):

* Shell command injection flaws were found in the way the setroubleshoot
executed external commands. A local attacker able to trigger certain
SELinux denials could use these flaws to execute arbitrary code with root
privileges. (CVE-2016-4445, CVE-2016-4989)

* Shell command injection flaws were found in the way the setroubleshoot
allow_execmod and allow_execstack plugins executed external commands. A
local attacker able to trigger an execmod or execstack SELinux denial
could use these flaws to execute arbitrary code with root privileges.
(CVE-2016-4444, CVE-2016-4446)

The CVE-2016-4444 and CVE-2016-4446 issues were discovered by Milos Malik
(Red Hat) and the CVE-2016-4445 and CVE-2016-4989 issues were discovered
by Red Hat Product Security.
--

SL6
  x86_64
    setroubleshoot-3.0.47-12.el6_8.x86_64.rpm
    setroubleshoot-debuginfo-3.0.47-12.el6_8.x86_64.rpm
    setroubleshoot-server-3.0.47-12.el6_8.x86_64.rpm
    setroubleshoot-doc-3.0.47-12.el6_8.x86_64.rpm
  i386
    setroubleshoot-3.0.47-12.el6_8.i686.rpm
    setroubleshoot-debuginfo-3.0.47-12.el6_8.i686.rpm
    setroubleshoot-server-3.0.47-12.el6_8.i686.rpm
    setroubleshoot-doc-3.0.47-12.el6_8.i686.rpm
  noarch
    setroubleshoot-plugins-3.0.40-3.1.el6_8.noarch.rpm

- Scientific Linux Development Team