Candidate: CVE-2016-7545 PublicDate: 2017-01-19 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7545 https://bugzilla.redhat.com/show_bug.cgi?id=1378577 Description: SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call. Ubuntu-Description: Notes: ebarretto> sandbox executable not packaged in Trusty and Xenial Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=838599 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H [8.8 HIGH] Patches_policycoreutils: upstream_policycoreutils: released (2.6-1) precise_policycoreutils: ignored (reached end-of-life) precise/esm_policycoreutils: DNE (precise was needed) trusty_policycoreutils: ignored (out of standard support) trusty/esm_policycoreutils: not-affected vivid/stable-phone-overlay_policycoreutils: DNE vivid/ubuntu-core_policycoreutils: DNE xenial_policycoreutils: not-affected yakkety_policycoreutils: ignored (reached end-of-life) zesty_policycoreutils: ignored (reached end-of-life) artful_policycoreutils: ignored (reached end-of-life) bionic_policycoreutils: not-affected (2.6-1) cosmic_policycoreutils: not-affected (2.6-1) disco_policycoreutils: not-affected (2.6-1) eoan_policycoreutils: not-affected (2.6-1) devel_policycoreutils: not-affected (2.6-1)