CVE-2016-1773
published 2016-03-24CVE-2016-1773: The code-signing subsystem in Apple OS X before 10.11.4 does not properly verify file ownership, which allows local users to determine the existence of…
PriorityP413low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.32%
23.9th percentile
The code-signing subsystem in Apple OS X before 10.11.4 does not properly verify file ownership, which allows local users to determine the existence of arbitrary files via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.11.3 | — |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-1773: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 3.3
CVE-2016-1773 [LOW] CVE-2016-1773: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2016-1773
Component: CVE-ID
GHSA
GHSA-2987-5c42-f4x4: The code-signing subsystem in Apple OS X before 10
ghsa_unreviewed·2022-05-17
CVE-2016-1773 [LOW] GHSA-2987-5c42-f4x4: The code-signing subsystem in Apple OS X before 10
The code-signing subsystem in Apple OS X before 10.11.4 does not properly verify file ownership, which allows local users to determine the existence of arbitrary files via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0791 jenkins: Non-constant time comparison of CSRF crumbs (SECURITY-245)
bugzilla·2016-02-25·CVSS 9.8
CVE-2016-0791 [CRITICAL] CVE-2016-0791 jenkins: Non-constant time comparison of CSRF crumbs (SECURITY-245)
CVE-2016-0791 jenkins: Non-constant time comparison of CSRF crumbs (SECURITY-245)
The following flaw was found in Jenkins:
The verification of user-provided CSRF crumbs with the expected value did not use a constant-time comparison algorithm, potentially allowing attackers to use statistical methods to determine valid CSRF crumbs using brute-force methods.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24
Discussion:
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 3.1
Via RHSA-2016:0711 https://access.redhat.com/errata/RHSA-2016:0711
---
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 2.2
Via RHSA-2016:1773 https://rhn.redhat.com/errata/RHSA-2016-1773
Bugzilla
CVE-2016-0788 jenkins: Remote code execution vulnerability in remoting module (SECURITY-232)
bugzilla·2016-02-25·CVSS 9.8
CVE-2016-0788 [CRITICAL] CVE-2016-0788 jenkins: Remote code execution vulnerability in remoting module (SECURITY-232)
CVE-2016-0788 jenkins: Remote code execution vulnerability in remoting module (SECURITY-232)
The following flaw was found in Jenkins:
A vulnerability in the Jenkins remoting module allowed unauthenticated remote attackers to open a JRMP listener on the server hosting the Jenkins master process, which allowed arbitrary code execution.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24
Discussion:
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 3.1
Via RHSA-2016:0711 https://access.redhat.com/errata/RHSA-2016:0711
---
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 2.2
Via RHSA-2016:1773 https://rhn.redhat.com/errata/RHSA-2016-1773.html
Bugzilla
CVE-2016-0789 jenkins: HTTP response splitting vulnerability (SECURITY-238)
bugzilla·2016-02-25·CVSS 6.1
CVE-2016-0789 [MEDIUM] CVE-2016-0789 jenkins: HTTP response splitting vulnerability (SECURITY-238)
CVE-2016-0789 jenkins: HTTP response splitting vulnerability (SECURITY-238)
The following flaw was found in Jenkins:
An HTTP response splitting vulnerability in the CLI command documentation allowed attackers to craft Jenkins URLs that serve malicious content.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24
Discussion:
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 3.1
Via RHSA-2016:0711 https://access.redhat.com/errata/RHSA-2016:0711
---
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 2.2
Via RHSA-2016:1773 https://rhn.redhat.com/errata/RHSA-2016-1773.html
Bugzilla
CVE-2016-0790 jenkins: Non-constant time comparison of API token (SECURITY-241)
bugzilla·2016-02-25·CVSS 5.3
CVE-2016-0790 [MEDIUM] CVE-2016-0790 jenkins: Non-constant time comparison of API token (SECURITY-241)
CVE-2016-0790 jenkins: Non-constant time comparison of API token (SECURITY-241)
The following flaw was found in Jenkins:
The verification of user-provided API tokens with the expected value did not use a constant-time comparison algorithm, potentially allowing attackers to use statistical methods to determine valid API tokens using brute-force methods.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24
Discussion:
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 3.1
Via RHSA-2016:0711 https://access.redhat.com/errata/RHSA-2016:0711
---
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 2.2
Via RHSA-2016:1773 https://rhn.redhat.com/errata/RHSA-2016-1773.htm
2016-03-24
Published