Local Privilege Escalation in Novell Filr Affects Multiple Versions
CVE-2016-1611

7.8HIGH

Key Information:

Vendor

Novell

Status
Vendor
CVE Published:
1 August 2016

What is CVE-2016-1611?

Novell Filr versions 1.2 prior to Hot Patch 6 and 2.0 prior to Hot Patch 2 exhibit a security vulnerability where world-writable permissions for the /etc/profile.d/vainit.sh file permit local users to modify its content. This flaw enables unauthorized individuals to execute arbitrary shell commands, potentially compromising system integrity and security.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.