ZeroHour

CVE-2016-4455

CVSS 3.1
3.3 low
EPSS
<1%p36
Published
()
Modified
Description

The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories.

Vendors
redhat
Products
enterprise linux desktop, enterprise linux hpc node, enterprise linux server, enterprise linux workstation, subscription-manager
Weakness
CWE-264
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.