CVE-2016-2985
published 2016-11-25CVE-2016-2985: IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow…
PriorityP429high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.30%
21.5th percentile
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program.
Affected
55 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.9 | 2.19-0ubuntu6.9 |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
| ibm | general_parallel_file_system | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mrxf-9q89-5jvp: IBM Spectrum Scale 4
ghsa_unreviewed·2022-05-17
CVE-2016-2985 [HIGH] GHSA-mrxf-9q89-5jvp: IBM Spectrum Scale 4
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program.
OSV
eglibc, glibc regression
osv·2016-05-26·CVSS 2.6
CVE-2014-9761 eglibc, glibc regression
eglibc, glibc regression
USN-2985-1 fixed vulnerabilities in the GNU C Library. The fix for
CVE-2014-9761 introduced a regression which affected applications that
use the libm library but were not fully restarted after the upgrade.
This update removes the fix for CVE-2014-9761 and a future update
will be provided to address this issue.
We apologize for the inconvenience.
Original advisory details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-11-25
Published