CVE-2016-7035
Last modified
CVE-2016-7035 is a vulnerability of currently unknown severity. An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Clusterlabs | Pacemaker | <= 1.1.16 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Eus | 7.3 |
| Redhat | Enterprise Linux Server Eus | 7.4 |
| Redhat | Enterprise Linux Server Eus | 7.5 |
| Redhat | Enterprise Linux Server Eus | 7.6 |
References
- http://rhn.redhat.com/errata/RHSA-2016-2614.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2675.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/11/03/5Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/94214Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7035Issue Tracking, Third Party Advisory
- https://github.com/ClusterLabs/pacemaker/commit/5d71e65049Third Party Advisory
- https://lists.clusterlabs.org/pipermail/users/2016-November/004432.htmlMailing List, Vendor Advisory
- https://security.gentoo.org/glsa/201710-08Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2614.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2675.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/11/03/5Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/94214Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7035Issue Tracking, Third Party Advisory
- https://github.com/ClusterLabs/pacemaker/commit/5d71e65049Third Party Advisory
- https://lists.clusterlabs.org/pipermail/users/2016-November/004432.htmlMailing List, Vendor Advisory
- https://security.gentoo.org/glsa/201710-08Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-7035?
How severe is CVE-2016-7035?
How do I fix CVE-2016-7035?
Are you affected by CVE-2016-7035?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
