Vulnerability Description
Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 11iv3 with VxFS 5.0, VxFS 5.0.1, and VxFS 5.1SP1 mishandles ACL inheritance for default:class: entries, default:other: entries, and default:user: entries, which allows local users to bypass intended access restrictions by leveraging the configuration of a parent directory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Hp-Ux | 11.11i |
| Hp | Base-Vxfs-50 | b.05.00.01 |
| Hp | Base-Vxfs-501 | b.05.01.0 |
| Hp | Base-Vxfs-51 | b.05.10.00 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1035816
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-cPatchVendor Advisory
- http://www.securitytracker.com/id/1035816
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-cPatchVendor Advisory
FAQ
What is CVE-2016-2016?
CVE-2016-2016 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 11iv3 with VxFS 5.0, VxFS 5.0.1, and VxFS 5.1SP1 mis...
How severe is CVE-2016-2016?
CVE-2016-2016 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2016?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Hp-Ux, Hp Base-Vxfs-50, Hp Base-Vxfs-501, Hp Base-Vxfs-51.