CVE-2016-1608: Critical severity novell filr vulnerability
Published Aug 1, 2016
·Updated
vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ntpServer parameter.
Affected Software
2 affected components
Novell Filr<=1.2
Novell Filr<=2.0
Remediation
Patch Available
Event History
Aug 1, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1608?
CVE-2016-1608 has a medium severity rating due to its potential for remote code execution by authenticated users.
2
How do I fix CVE-2016-1608?
To fix CVE-2016-1608, upgrade to Novell Filr version 1.2 Security Update 3 or 2.0 Security Update 2.
3
Who is affected by CVE-2016-1608?
CVE-2016-1608 affects users of Novell Filr versions prior to 1.2 Security Update 3 and 2.0 Security Update 2.
4
What type of vulnerability is CVE-2016-1608?
CVE-2016-1608 is classified as a command injection vulnerability.
5
Can CVE-2016-1608 be exploited remotely?
Yes, CVE-2016-1608 can be exploited remotely by authenticated users.