Bug 1360135 (CVE-2016-5410)
Summary: | CVE-2016-5410 firewalld: Firewall configuration can be modified by any logged in user | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Huzaifa S. Sidhpurwala <huzaifas> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | anemec, security-response-team, slawomir, thoger, todoleza, twoerner |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | firewalld 0.4.3.3 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in the way firewalld allowed certain firewall configurations to be modified by unauthenticated users. Any locally logged in user could use this flaw to tamper or change firewall settings.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2016-11-06 04:28:34 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1359296, 1367381 | ||
Bug Blocks: | 1323912, 1360139 |
Description
Huzaifa S. Sidhpurwala
2016-07-26 06:04:34 UTC
Created firewalld tracking bugs for this issue: Affects: fedora-all [bug 1367381] Public via: http://seclists.org/oss-sec/2016/q3/291 This issue was fixed in firewalld-0.4.3.3 release: http://www.firewalld.org/2016/08/firewalld-0-4-3-3-release/ This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:2597 https://rhn.redhat.com/errata/RHSA-2016-2597.html |