Vulnerability Name: | CVE-2016-4455 (CCN-118643) |
Assigned: | 2016-05-25 |
Published: | 2016-05-25 |
Updated: | 2023-02-12 |
Summary: | The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories. |
CVSS v3 Severity: | 3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None | 3.3 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None | 3.3 Low (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 2.9 Low (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None |
|
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 1.7 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Athentication (Au): Single_Instance
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 1.7 Low (REDHAT CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None |
|
Vulnerability Type: | CWE-732
|
Vulnerability Consequences: | Obtain Information |
References: | Source: MITRE Type: CNA CVE-2016-4455
Source: CCN Type: Red Hat Security Advisory RHSA-2016:2592-1
Source: CCN Type: RHSA-2016-2592 Moderate: subscription-manager security, bug fix, and enhancement update
Source: secalert@redhat.com Type: Third Party Advisory, VDB Entry secalert@redhat.com
Source: CCN Type: RHSA-2017-0698 Moderate: subscription-manager security, bug fix, and enhancement update
Source: secalert@redhat.com Type: Third Party Advisory, VDB Entry secalert@redhat.com
Source: secalert@redhat.com Type: Mailing List, Patch, Third Party Advisory secalert@redhat.com
Source: CCN Type: BID-93926 Candlepin 'subscription-manager' CVE-2016-4455 Insecure File Permissions Vulnerability
Source: secalert@redhat.com Type: Third Party Advisory, VDB Entry secalert@redhat.com
Source: secalert@redhat.com Type: Third Party Advisory, VDB Entry secalert@redhat.com
Source: CCN Type: Red Hat Bugzilla (CVE-2016-4455) CVE-2016-4455 subscription-manager: sensitive world readable files in /var/lib/rhsm/
Source: secalert@redhat.com Type: Issue Tracking, Patch, Third Party Advisory, VDB Entry secalert@redhat.com
Source: XF Type: UNKNOWN redhat-cve20164455-info-disc(118643)
Source: secalert@redhat.com Type: Third Party Advisory secalert@redhat.com
Source: secalert@redhat.com Type: Patch, Third Party Advisory secalert@redhat.com
|
Vulnerable Configuration: | Configuration RedHat 1: cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*Configuration RedHat 2: cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*Configuration RedHat 3: cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*Configuration RedHat 4: cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*Configuration RedHat 5: cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*Configuration RedHat 6: cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*Configuration RedHat 7: cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*Configuration RedHat 8: cpe:/o:redhat:enterprise_linux:6::computenode:*:*:*:*:*Configuration RedHat 9: cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*Configuration RedHat 10: cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:* Configuration CCN 1: cpe:/o:redhat:enterprise_linux_desktop:7:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_hpc_node:7:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_server:7:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_workstation:7:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_desktop:6:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_hpc_node:6:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_server:6:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_workstation:6:*:*:*:*:*:*:* Denotes that component is vulnerable |
Oval Definitions |
|
BACK |