CVE-2016-1242
Last modified
CVE-2016-1242 is a vulnerability of currently unknown severity. file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.. EPSS estimates a 1.82% chance of exploitation in the next 30 days.
Description
file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tryton | Tryton | 4.0.0 |
| Tryton | Tryton | 4.0.1 |
| Tryton | Tryton | 4.0.2 |
| Tryton | Tryton | 4.0.3 |
| Tryton | Tryton | <= 3.2.16 |
| Tryton | Tryton | 3.8.0 |
| Tryton | Tryton | 3.8.1 |
| Tryton | Tryton | 3.8.2 |
| Tryton | Tryton | 3.8.3 |
| Tryton | Tryton | 3.8.4 |
| Tryton | Tryton | 3.8.5 |
| Tryton | Tryton | 3.8.6 |
| Tryton | Tryton | 3.8.7 |
| Tryton | Tryton | 3.4.0 |
| Tryton | Tryton | 3.4.1 |
| Tryton | Tryton | 3.4.2 |
| Tryton | Tryton | 3.4.3 |
| Tryton | Tryton | 3.4.4 |
| Tryton | Tryton | 3.4.5 |
| Tryton | Tryton | 3.4.6 |
| Tryton | Tryton | 3.4.7 |
| Tryton | Tryton | 3.4.8 |
| Tryton | Tryton | 3.4.9 |
| Tryton | Tryton | 3.4.10 |
| Tryton | Tryton | 3.4.11 |
| Tryton | Tryton | 3.4.12 |
| Tryton | Tryton | 3.4.13 |
| Tryton | Tryton | 3.2.0 |
| Tryton | Tryton | 3.6.0 |
| Tryton | Tryton | 3.6.1 |
| Tryton | Tryton | 3.6.2 |
| Tryton | Tryton | 3.6.3 |
| Tryton | Tryton | 3.6.4 |
| Tryton | Tryton | 3.6.5 |
| Tryton | Tryton | 3.6.6 |
| Tryton | Tryton | 3.6.7 |
| Tryton | Tryton | 3.6.8 |
| Tryton | Tryton | 3.6.9 |
| Tryton | Tryton | 3.6.10 |
| Tryton | Tryton | 3.6.11 |
References
- http://www.debian.org/security/2016/dsa-3656Third Party Advisory
- https://bugs.tryton.org/issue5808Issue Tracking
- http://www.debian.org/security/2016/dsa-3656Third Party Advisory
- https://bugs.tryton.org/issue5808Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1242?
How severe is CVE-2016-1242?
How do I fix CVE-2016-1242?
Are you affected by CVE-2016-1242?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
