First published: Mon Aug 01 2016(Updated: )
Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.sh, which allows local users to gain privileges by replacing this file's content with arbitrary shell commands.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Filr | <=1.2 | |
Novell Filr | <=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1611 is considered a high severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2016-1611, apply Hot Patch 6 for Novell Filr 1.2 or Hot Patch 2 for Novell Filr 2.0.
Local users can exploit CVE-2016-1611 by replacing the content of /etc/profile.d/vainit.sh with arbitrary shell commands, leading to privilege escalation.
CVE-2016-1611 affects Novell Filr versions 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2.
CVE-2016-1611 is classified as a local privilege escalation vulnerability.