CVE-2016-1235
published 2016-04-11CVE-2016-1235: The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors…
PriorityP346high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
3.45%
87.8th percentile
The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | oar | < oar 2.5.7-1 (bookworm) | oar 2.5.7-1 (bookworm) |
| oar_project | oar | <= 2.5.6 | — |
| oar_project | oar | >= 0 < 2.5.7-1 | 2.5.7-1 |
| oar_project | oar | >= 0 < 2.5.7-1 | 2.5.7-1 |
| oar_project | oar | >= 0 < 2.5.7-1 | 2.5.7-1 |
| oar_project | oar | >= 0 < 2.5.7-1 | 2.5.7-1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vjg5-gcmw-v53j: The oarsh script in OAR before 2
ghsa_unreviewed·2022-05-17
CVE-2016-1235 [HIGH] GHSA-vjg5-gcmw-v53j: The oarsh script in OAR before 2
The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options.
OSV
CVE-2016-1235: The oarsh script in OAR before 2
osv·2016-04-11·CVSS 8.8
CVE-2016-1235 [HIGH] CVE-2016-1235: The oarsh script in OAR before 2
The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options.
Debian
CVE-2016-1235: oar - The oarsh script in OAR before 2.5.7 allows remote authenticated users of a clus...
vendor_debian·2016·CVSS 8.8
CVE-2016-1235 [HIGH] CVE-2016-1235: oar - The oarsh script in OAR before 2.5.7 allows remote authenticated users of a clus...
The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options.
Scope: local
bookworm: resolved (fixed in 2.5.7-1)
bullseye: resolved (fixed in 2.5.7-1)
forky: resolved (fixed in 2.5.7-1)
sid: resolved (fixed in 2.5.7-1)
trixie: resolved (fixed in 2.5.7-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://oar.imag.fr/oar_2.5.7http://www.debian.org/security/2016/dsa-3543https://raw.githubusercontent.com/oar-team/oar/ce77ffed620fdce94881c9b35064507777c24a1c/debian/patches/004-fix-oarsh-security-issuehttp://oar.imag.fr/oar_2.5.7http://www.debian.org/security/2016/dsa-3543https://raw.githubusercontent.com/oar-team/oar/ce77ffed620fdce94881c9b35064507777c24a1c/debian/patches/004-fix-oarsh-security-issue
2016-04-11
Published