CVE-2016-2016: Medium severity hpe hp-ux vulnerability
Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 11iv3 with VxFS 5.0, VxFS 5.0.1, and VxFS 5.1SP1 mishandles ACL inheritance for default:class: entries, default:other: entries, and default:user: entries, which allows local users to bypass intended access restrictions by leveraging the configuration of a parent directory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2016?
The severity of CVE-2016-2016 is classified as medium, indicating potential impacts on the system's security.
How do I fix CVE-2016-2016?
To fix CVE-2016-2016, upgrade to the patched versions of Base-VxFS that are not affected by this vulnerability.
What systems are affected by CVE-2016-2016?
CVE-2016-2016 affects HPE HP-UX 11iv3 running specific versions of Base-VxFS, namely B.05.00.01 through B.05.00.02, B.05.01.0 through B.05.01.03, and B.05.10.00 through B.05.10.02.
What is the nature of the vulnerability in CVE-2016-2016?
CVE-2016-2016 involves a mishandling of ACL inheritance for default class entries, which may lead to improper file permissions.
Is CVE-2016-2016 a remote or local vulnerability?
CVE-2016-2016 is considered a local vulnerability, requiring authenticated access to exploit.