CVE-2016-8017: Input Validation
Published Mar 14, 2017
·Updated
Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to read files on the webserver via a crafted user input.
Affected Software
1 affected component
McAfee Virusscan Enterprise Linux<=2.0.3
Event History
Mar 14, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-8017?
CVE-2016-8017 is considered a medium severity vulnerability due to its potential for file reading by authenticated attackers.
2
How do I fix CVE-2016-8017?
To fix CVE-2016-8017, upgrade to a version of Intel Security VirusScan Enterprise Linux later than 2.0.3.
3
Who is affected by CVE-2016-8017?
CVE-2016-8017 affects users of Intel Security VirusScan Enterprise Linux version 2.0.3 and earlier.
4
What type of attack does CVE-2016-8017 facilitate?
CVE-2016-8017 facilitates authenticated remote attacks that can lead to unauthorized file access on the web server.
5
Is CVE-2016-8017 a local or remote vulnerability?
CVE-2016-8017 is a remote vulnerability that requires authentication to exploit.