policycoreutils: Privilege escalation A vulnerability in policycoreutils could lead to local privilege escalation. policycoreutils 2014-12-26 2014-12-26 509896 local 2.2.5-r4 2.2.5-r4

policycoreutils is a collection of SELinux policy utilities.

The seunshare utility is owned by root with 4755 permissions which can be exploited by a setuid system call.

A local attacker may be able to gain escalated privileges.

There is no known workaround at this time.

All policycoreutils users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/policycoreutils-2.2.5-r4"
CVE-2014-3215 BlueKnight ackle