Vulnerability Name:

CVE-2016-4992 (CCN-118694)

Assigned:2016-06-17
Published:2016-06-17
Updated:2023-02-02
Summary:
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
4.3 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
3.8 Low (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
3.5 Low (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2016-4992

Source: CCN
Type: RHSA-2016-2594
Moderate: 389-ds-base security, bug fix, and enhancement update

Source: secalert@redhat.com
Type: Vendor Advisory
secalert@redhat.com

Source: CCN
Type: RHSA-2016-2765
Moderate: 389-ds-base security, bug fix, and enhancement update

Source: secalert@redhat.com
Type: Vendor Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: Red Hat Bugzilla
(CVE-2016-4992) CVE-2016-4992 389-ds-base: Information disclosure via repeated use of LDAP ADD operation

Source: secalert@redhat.com
Type: Issue Tracking, Vendor Advisory
secalert@redhat.com

Source: XF
Type: UNKNOWN
redhat-cve20164992-info-disc(118694)

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*
  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*
  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:6::computenode:*:*:*:*:*
  • Configuration RedHat 9:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*
  • Configuration RedHat 10:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:redhat:enterprise_linux_desktop:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20164992
    V
    CVE-2016-4992
    2022-08-07
    oval:org.opensuse.security:def:3462
    P
    389-ds-2.0.15~git17.498ec3e93-150400.1.3 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95092
    P
    389-ds-2.0.15~git17.498ec3e93-150400.1.3 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:971
    P
    Security update for libqt5-qtbase (Important)
    2022-03-15
    oval:org.opensuse.security:def:111881
    P
    389-ds-2.0.10~git0.21dd2802c-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:1493
    P
    Security update for postgresql14 (Important)
    2021-11-22
    oval:org.opensuse.security:def:64612
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:94190
    P
    (Important)
    2021-10-20
    oval:org.opensuse.security:def:105461
    P
    389-ds-2.0.10~git0.21dd2802c-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:90026
    P
    389-ds-1.4.0.3-2.39 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:2102
    P
    389-ds-1.4.0.3-2.39 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71399
    P
    subversion-1.10.0-3.3.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63191
    P
    389-ds-1.4.0.3-2.39 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103681
    P
    389-ds-1.4.0.3-2.39 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96991
    P
    389-ds-1.4.0.3-2.39 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71286
    P
    libnghttp2-14-1.31.1-1.15 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:1024
    P
    Security update for MozillaFirefox (Important)
    2021-08-19
    oval:org.opensuse.security:def:68046
    P
    Security update for the Linux Kernel (Live Patch 15 for SLE 15 SP1) (Important)
    2021-08-17
    oval:org.opensuse.security:def:47681
    P
    libXpm4-3.5.11-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47492
    P
    rpm-32bit-4.11.2-15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48006
    P
    file-5.22-10.12.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47507
    P
    sudo-1.8.20p2-1.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48246
    P
    ntp-4.2.8p13-85.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47821
    P
    libzypp-16.19.0-2.36.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47545
    P
    SuSEfirewall2-3.6.312.333-3.13.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48045
    P
    ibus-chewing-1.4.14-4.11 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47560
    P
    augeas-1.2.0-17.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47874
    P
    radvd-1.9.7-2.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47493
    P
    rrdtool-1.4.7-20.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48098
    P
    libblkid1-2.33.2-2.13 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47628
    P
    gpg2-2.0.24-9.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47953
    P
    apache2-mod_perl-2.0.8-11.43 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47546
    P
    aaa_base-13.2+git20140911.61c1681-38.8.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48193
    P
    libsnmp30-32bit-5.7.3-6.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:2224
    P
    389-ds-1.4.4.14~git0.37dc95673-1.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63313
    P
    389-ds-1.4.4.14~git0.37dc95673-1.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:100903
    P
    libcroco-0.6.13-1.26 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1546
    P
    Security update for the Linux Kernel (Important)
    2021-07-20
    oval:org.opensuse.security:def:66859
    P
    Security update for sqlite3 (Important)
    2021-07-14
    oval:org.opensuse.security:def:48702
    P
    pulseaudio-module-bluetooth-5.0-2.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48491
    P
    libexif12-0.6.21-6.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48618
    P
    rsyslog-8.4.0-14.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48720
    P
    gcc48-gij-32bit-4.8.5-24.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48544
    P
    libqt4-4.8.6-7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48671
    P
    freerdp-1.0.2-7.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48407
    P
    dstat-0.7.2-1.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48773
    P
    gd-32bit-2.1.0-12.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48553
    P
    libsrtp1-1.5.2-2.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48649
    P
    xdg-utils-20140630-5.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48460
    P
    libQt5Concurrent5-5.6.1-11.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48606
    P
    python-imaging-1.1.7-21.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64699
    P
    Security update for lz4 (Important)
    2021-06-01
    oval:org.opensuse.security:def:1603
    P
    Security update for ibutils (Low)
    2021-05-13
    oval:org.opensuse.security:def:70215
    P
    Security update for java-11-openjdk (Important)
    2021-05-11
    oval:org.opensuse.security:def:66767
    P
    Security update for samba (Important)
    2021-05-04
    oval:org.opensuse.security:def:63138
    P
    389-ds-1.4.0.3-2.39 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2159
    P
    389-ds-1.4.3.9~git0.3eb8617f6-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63248
    P
    389-ds-1.4.3.9~git0.3eb8617f6-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107569
    P
    389-ds-1.4.3.9~git0.3eb8617f6-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2049
    P
    389-ds-1.4.0.3-2.39 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:70110
    P
    libplist++-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49987
    P
    389-ds on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73432
    P
    liblouis-data on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49880
    P
    ntp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50044
    P
    389-ds on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73550
    P
    389-ds on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49933
    P
    clamsap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67946
    P
    perl-CGI on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49934
    P
    389-ds on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49990
    P
    apache2-mod_jk on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.xenial:def:20164992000
    V
    CVE-2016-4992 on Ubuntu 16.04 LTS (xenial) - low.
    2017-06-08
    oval:com.ubuntu.xenial:def:201649920000000
    V
    CVE-2016-4992 on Ubuntu 16.04 LTS (xenial) - low.
    2017-06-08
    oval:com.ubuntu.cosmic:def:20164992000
    V
    CVE-2016-4992 on Ubuntu 18.10 (cosmic) - low.
    2017-06-08
    oval:com.ubuntu.cosmic:def:201649920000000
    V
    CVE-2016-4992 on Ubuntu 18.10 (cosmic) - low.
    2017-06-08
    oval:com.ubuntu.artful:def:20164992000
    V
    CVE-2016-4992 on Ubuntu 17.10 (artful) - low.
    2017-06-08
    oval:com.ubuntu.trusty:def:20164992000
    V
    CVE-2016-4992 on Ubuntu 14.04 LTS (trusty) - low.
    2017-06-08
    oval:com.ubuntu.bionic:def:201649920000000
    V
    CVE-2016-4992 on Ubuntu 18.04 LTS (bionic) - low.
    2017-06-08
    oval:com.ubuntu.bionic:def:20164992000
    V
    CVE-2016-4992 on Ubuntu 18.04 LTS (bionic) - low.
    2017-06-08
    oval:com.redhat.rhsa:def:20162765
    P
    RHSA-2016:2765: 389-ds-base security, bug fix, and enhancement update (Moderate)
    2016-11-15
    oval:com.redhat.rhsa:def:20162594
    P
    RHSA-2016:2594: 389-ds-base security, bug fix, and enhancement update (Moderate)
    2016-11-03
    oval:com.ubuntu.precise:def:20164992000
    V
    CVE-2016-4992 on Ubuntu 12.04 LTS (precise) - low.
    2016-06-24
    BACK
    redhat enterprise linux desktop 7
    redhat enterprise linux hpc node 7.0
    redhat enterprise linux server 7
    redhat enterprise linux workstation 7
    redhat enterprise linux 7
    redhat enterprise linux desktop 6
    redhat enterprise linux hpc node 6
    redhat enterprise linux server 6
    redhat enterprise linux workstation 6