First published: Fri Jun 17 2016(Updated: )
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to infer the existence of RDN component objects.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux HPC Node | =6.0 | |
Red Hat Enterprise Linux HPC Node | =7.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4992 has a moderate severity rating, as it allows remote attackers to infer the existence of certain directory objects.
To mitigate CVE-2016-4992, apply the appropriate security patches provided by Red Hat for your affected version.
CVE-2016-4992 affects Red Hat Enterprise Linux Desktop, HPC Node, Server, and Workstation versions 6 and 7.
No, CVE-2016-4992 is not a remote code execution vulnerability; it involves information disclosure.
CVE-2016-4992 can lead to unauthorized inference of directory service information, potentially compromising sensitive data.