PT-2016-5309 · Ibm · Ibm Spectrum Scale+1
Publicado
2016-11-25
·
Atualizado
2016-11-28
·
CVE-2016-2984
CVSS v3.1
7.0
Alta
| Vetor | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Scale versions 4.1.1.x through 4.1.1.7
IBM Spectrum Scale versions 4.2.x through 4.2.0.3
General Parallel File System (GPFS) versions 3.5.x through 3.5.0.31
General Parallel File System (GPFS) versions 4.1.x through 4.1.1.7
Description
The issue allows local users to gain privileges via crafted command-line parameters to a setuid program located at
/usr/lpp/mmfs/bin/.Recommendations
For IBM Spectrum Scale versions 4.1.1.x through 4.1.1.7, update to version 4.1.1.8 or later.
For IBM Spectrum Scale versions 4.2.x through 4.2.0.3, update to version 4.2.0.4 or later.
For General Parallel File System (GPFS) versions 3.5.x through 3.5.0.31, update to version 3.5.0.32 or later.
For General Parallel File System (GPFS) versions 4.1.x through 4.1.1.7, update to version 4.1.1.8 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm General Parallel File System
Ibm Spectrum Scale