PT-2017-8723 · Red Hat+3 · Red Hat Enterprise Linux Server+8

Adam Mariš

+1

·

Published

2016-11-03

·

Updated

2023-02-12

·

CVE-2016-5416

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Linux Desktop versions 6 through 7 Red Hat Enterprise Linux HPC Node versions 6 through 7 Red Hat Enterprise Linux Server versions 6 through 7 Red Hat Enterprise Linux Workstation versions 6 through 7 389 Directory Server (affected versions not specified)
Description The issue allows remote attackers to read the default Access Control Instructions in 389 Directory Server within various Red Hat Enterprise Linux versions.
Recommendations For Red Hat Enterprise Linux Desktop versions 6 through 7, update the 389 Directory Server configuration to restrict access to sensitive information. For Red Hat Enterprise Linux HPC Node versions 6 through 7, update the 389 Directory Server configuration to restrict access to sensitive information. For Red Hat Enterprise Linux Server versions 6 through 7, update the 389 Directory Server configuration to restrict access to sensitive information. For Red Hat Enterprise Linux Workstation versions 6 through 7, update the 389 Directory Server configuration to restrict access to sensitive information. As a temporary workaround, consider restricting access to the 389 Directory Server until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CESA-2016_2594
CESA-2016_2765
CVE-2016-5416
RHSA-2016:2594
RHSA-2016:2765
RHSA-2016_2594
RHSA-2016_2765
SUSE-SU-2019:2155-1
SUSE-SU-2019_2155-1

Affected Products

389 Directory Server
Centos
Debian
Red Hat
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Hpc Node
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Suse