CVE-2016-3106: Race Condition
It was found that fix for CVE-2016-3095 was incomplete, introducing new vulnerabilities due to insecure way of creating the temporary directory when generating new CA key.
Other sources
Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3106?
CVE-2016-3106 is considered a moderate severity vulnerability due to its potential impact on the security of temporary files.
How do I fix CVE-2016-3106?
To fix CVE-2016-3106, upgrade Pulp to version 2.8.3 or later where the vulnerability has been addressed.
What versions of Pulp are affected by CVE-2016-3106?
Pulp versions prior to 2.8.3, including 2.8.2-1, are affected by CVE-2016-3106.
What type of vulnerability is CVE-2016-3106?
CVE-2016-3106 is a security vulnerability related to improper handling of temporary directories.
Is CVE-2016-3106 related to any other vulnerabilities?
Yes, CVE-2016-3106 is a follow-up to CVE-2016-3095 and stems from an incomplete fix that introduced new security concerns.