First published: Fri Nov 25 2016(Updated: )
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Scale | =4.1.1.0 | |
IBM Spectrum Scale | =4.1.1.1 | |
IBM Spectrum Scale | =4.1.1.2 | |
IBM Spectrum Scale | =4.1.1.3 | |
IBM Spectrum Scale | =4.1.1.4 | |
IBM Spectrum Scale | =4.1.1.5 | |
IBM Spectrum Scale | =4.1.1.6 | |
IBM Spectrum Scale | =4.1.1.7 | |
IBM Spectrum Scale | =4.1.1.8 | |
IBM Spectrum Scale | =4.2.0.0 | |
IBM Spectrum Scale | =4.2.0.1 | |
IBM Spectrum Scale | =4.2.0.2 | |
IBM Spectrum Scale | =4.2.0.3 | |
IBM General Parallel File System Storage Server | =3.5.0.0 | |
IBM General Parallel File System Storage Server | =3.5.0.1 | |
IBM General Parallel File System Storage Server | =3.5.0.2 | |
IBM General Parallel File System Storage Server | =3.5.0.3 | |
IBM General Parallel File System Storage Server | =3.5.0.4 | |
IBM General Parallel File System Storage Server | =3.5.0.5 | |
IBM General Parallel File System Storage Server | =3.5.0.6 | |
IBM General Parallel File System Storage Server | =3.5.0.7 | |
IBM General Parallel File System Storage Server | =3.5.0.8 | |
IBM General Parallel File System Storage Server | =3.5.0.9 | |
IBM General Parallel File System Storage Server | =3.5.0.10 | |
IBM General Parallel File System Storage Server | =3.5.0.11 | |
IBM General Parallel File System Storage Server | =3.5.0.12 | |
IBM General Parallel File System Storage Server | =3.5.0.13 | |
IBM General Parallel File System Storage Server | =3.5.0.14 | |
IBM General Parallel File System Storage Server | =3.5.0.15 | |
IBM General Parallel File System Storage Server | =3.5.0.16 | |
IBM General Parallel File System Storage Server | =3.5.0.17 | |
IBM General Parallel File System Storage Server | =3.5.0.18 | |
IBM General Parallel File System Storage Server | =3.5.0.19 | |
IBM General Parallel File System Storage Server | =3.5.0.20 | |
IBM General Parallel File System Storage Server | =3.5.0.21 | |
IBM General Parallel File System Storage Server | =3.5.0.22 | |
IBM General Parallel File System Storage Server | =3.5.0.23 | |
IBM General Parallel File System Storage Server | =3.5.0.24 | |
IBM General Parallel File System Storage Server | =3.5.0.25 | |
IBM General Parallel File System Storage Server | =3.5.0.26 | |
IBM General Parallel File System Storage Server | =3.5.0.27 | |
IBM General Parallel File System Storage Server | =3.5.0.28 | |
IBM General Parallel File System Storage Server | =3.5.0.29 | |
IBM General Parallel File System Storage Server | =3.5.0.30 | |
IBM General Parallel File System Storage Server | =3.5.0.31 | |
IBM General Parallel File System Storage Server | =4.1.0.0 | |
IBM General Parallel File System Storage Server | =4.1.0.1 | |
IBM General Parallel File System Storage Server | =4.1.0.2 | |
IBM General Parallel File System Storage Server | =4.1.0.3 | |
IBM General Parallel File System Storage Server | =4.1.0.4 | |
IBM General Parallel File System Storage Server | =4.1.0.5 | |
IBM General Parallel File System Storage Server | =4.1.0.6 | |
IBM General Parallel File System Storage Server | =4.1.0.7 | |
IBM General Parallel File System Storage Server | =4.1.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2985 has a medium severity rating, highlighting the potential for local privilege escalation.
To fix CVE-2016-2985, upgrade IBM Spectrum Scale to version 4.1.1.8 or later, or 4.2.0.4 or later, or GPFS to version 3.5.0.32 or later.
CVE-2016-2985 affects local users of IBM Spectrum Scale versions prior to 4.1.1.8 and 4.2.0.4, and General Parallel File System versions prior to 3.5.0.32.
CVE-2016-2985 is a local privilege escalation vulnerability involving crafted environment variables.
IBM Spectrum Scale versions 4.1.1.0 through 4.1.1.7 and 4.2.0.0 through 4.2.0.3 are vulnerable as per CVE-2016-2985.