CVE-2016-1610: Path Traversal
Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote attackers to bypass intended access restrictions and write to arbitrary files via a .. (dot dot) in a blob name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1610?
CVE-2016-1610 is categorized as a medium severity vulnerability due to its ability to allow remote file writing through a directory traversal attack.
How do I fix CVE-2016-1610?
To fix CVE-2016-1610, update Novell Filr to versions 1.2 Security Update 3 or 2.0 Security Update 2 or later.
What types of attacks are possible due to CVE-2016-1610?
CVE-2016-1610 allows remote attackers to bypass access restrictions and potentially overwrite arbitrary files on the server.
What versions of Novell Filr are affected by CVE-2016-1610?
CVE-2016-1610 affects Novell Filr versions prior to 1.2 Security Update 3 and 2.0 Security Update 2.
Is CVE-2016-1610 specific to any particular file or feature in Novell Filr?
Yes, CVE-2016-1610 specifically targets the email-template feature within Novell Filr.