First published: Sun Jun 19 2016(Updated: )
IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a setuid program.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Elastic Storage Server | =2.5.0 | |
IBM Elastic Storage Server | =2.5.1 | |
IBM Elastic Storage Server | =2.5.2 | |
IBM Elastic Storage Server | =2.5.3 | |
IBM Elastic Storage Server | =2.5.4 | |
IBM Elastic Storage Server | =2.5.5 | |
IBM Elastic Storage Server | =3.0.0 | |
IBM Elastic Storage Server | =3.0.1 | |
IBM Elastic Storage Server | =3.0.2 | |
IBM Elastic Storage Server | =3.0.3 | |
IBM Elastic Storage Server | =3.0.4 | |
IBM Elastic Storage Server | =3.0.5 | |
IBM Elastic Storage Server | =3.5.0 | |
IBM Elastic Storage Server | =3.5.1 | |
IBM Elastic Storage Server | =3.5.2 | |
IBM Elastic Storage Server | =3.5.3 | |
IBM Elastic Storage Server | =3.5.4 | |
IBM Elastic Storage Server | =4.0.0 | |
IBM Elastic Storage Server | =4.0.1 | |
IBM Elastic Storage Server | =4.0.2 | |
Ibm General Parallel File System Storage Server | =2.0.0 | |
Ibm General Parallel File System Storage Server | =2.0.1 | |
Ibm General Parallel File System Storage Server | =2.0.2 | |
Ibm General Parallel File System Storage Server | =2.0.3 | |
Ibm General Parallel File System Storage Server | =2.0.4 | |
Ibm General Parallel File System Storage Server | =2.0.5 | |
Ibm General Parallel File System Storage Server | =2.0.6 | |
Ibm General Parallel File System Storage Server | =2.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0392 is classified as a high-severity vulnerability due to its potential to allow local users to gain elevated privileges.
To fix CVE-2016-0392, you should update your IBM General Parallel File System or Elastic Storage Server to a version that has addressed this vulnerability.
CVE-2016-0392 affects IBM General Parallel File System and IBM Elastic Storage Server versions from 2.0.0 to earlier than 4.0.3.
CVE-2016-0392 requires local access to the system, meaning it cannot be exploited remotely.
If exploited, CVE-2016-0392 can allow an attacker to gain unauthorized privileges, potentially leading to data loss or system compromise.