Vulnerability Description
The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oar Project | Oar | <= 2.5.6 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://oar.imag.fr/oar_2.5.7PatchVendor Advisory
- http://www.debian.org/security/2016/dsa-3543
- https://raw.githubusercontent.com/oar-team/oar/ce77ffed620fdce94881c9b3506450777
- http://oar.imag.fr/oar_2.5.7PatchVendor Advisory
- http://www.debian.org/security/2016/dsa-3543
- https://raw.githubusercontent.com/oar-team/oar/ce77ffed620fdce94881c9b3506450777
FAQ
What is CVE-2016-1235?
CVE-2016-1235 is a vulnerability with a CVSS score of 8.8 (HIGH). The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options.
How severe is CVE-2016-1235?
CVE-2016-1235 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1235?
Check the references section above for vendor advisories and patch information. Affected products include: Oar Project Oar, Debian Debian Linux.