CVE-2016-3111
Last modified
CVE-2016-3111 is a vulnerability of currently unknown severity. pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-readable before later modifying the permissions, which might allow local users to read the generated RSA keys via reading the key files while the installation process is running.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-readable before later modifying the permissions, which might allow local users to read the generated RSA keys via reading the key files while the installation process is running.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pulpproject | Pulp | <= 2.8.2-1 |
References
- http://pkgs.fedoraproject.org/cgit/rpms/pulp.git/tree/pulp.spec#n317Issue Tracking, Patch, Third Party Advisory
- http://pkgs.fedoraproject.org/cgit/rpms/pulp.git/tree/pulp.spec#n620Issue Tracking, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/05/20/1Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/attachment.cgi?id=1146522Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=1326251Issue Tracking, Patch
- https://github.com/pulp/pulp/blob/master/pulp.spec#L473-L486Issue Tracking, Patch, Third Party Advisory
- https://github.com/pulp/pulp/blob/master/pulp.spec#L894-L903Issue Tracking, Patch, Third Party Advisory
- https://pulp.plan.io/issues/1837Patch, Vendor Advisory
- http://pkgs.fedoraproject.org/cgit/rpms/pulp.git/tree/pulp.spec#n317Issue Tracking, Patch, Third Party Advisory
- http://pkgs.fedoraproject.org/cgit/rpms/pulp.git/tree/pulp.spec#n620Issue Tracking, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/05/20/1Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/attachment.cgi?id=1146522Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=1326251Issue Tracking, Patch
- https://github.com/pulp/pulp/blob/master/pulp.spec#L473-L486Issue Tracking, Patch, Third Party Advisory
- https://github.com/pulp/pulp/blob/master/pulp.spec#L894-L903Issue Tracking, Patch, Third Party Advisory
- https://pulp.plan.io/issues/1837Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-3111?
How severe is CVE-2016-3111?
How do I fix CVE-2016-3111?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-3105The convert extension in Mercurial before 3.8 might allow co…
- CVE-2016-3106Pulp before 2.8.3 creates a temporary directory during CA ke…
- CVE-2016-3107The Node certificate in Pulp before 2.8.3 contains the priva…
- CVE-2016-3108The pulp-gen-nodes-certificate script in Pulp before 2.8.3 a…
- CVE-2016-3109The backend/Login/load/ script in Shopware before 5.1.5 allo…
- CVE-2016-3110mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows…
- CVE-2016-3112client/consumer/cli.py in Pulp before 2.8.3 writes consumer …
- CVE-2016-3113Cross-site scripting (XSS) vulnerability in ovirt-engine all…6.1
- CVE-2016-3114Kallithea before 0.3.2 allows remote authenticated users to …
- CVE-2016-3115Multiple CRLF injection vulnerabilities in session.c in sshd…6.4
- CVE-2016-3116CRLF injection vulnerability in Dropbear SSH before 2016.72 …
- CVE-2016-3118CRLF injection vulnerability in CA API Gateway (formerly Lay…
Are you affected by CVE-2016-3111?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
