CVE-2016-3169
published 2016-04-12CVE-2016-3169: The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls…
PriorityP347high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
2.22%
80.5th percentile
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.
Affected
87 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| drupal | core | >= 6.0 < 6.38 | 6.38 |
| drupal | core | >= 7.0 < 7.43 | 7.43 |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Drupal saving user accounts can sometimes grant the user all roles
osv·2022-05-17
CVE-2016-3169 [HIGH] Drupal saving user accounts can sometimes grant the user all roles
Drupal saving user accounts can sometimes grant the user all roles
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.
GHSA
Drupal saving user accounts can sometimes grant the user all roles
ghsa·2022-05-17
CVE-2016-3169 [HIGH] CWE-269 Drupal saving user accounts can sometimes grant the user all roles
Drupal saving user accounts can sometimes grant the user all roles
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.
OSV
linux-lts-xenial vulnerabilities
osv·2017-01-11·CVSS 5.5
CVE-2016-9756 linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3169-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Dmitry Vyukov discovered that the KVM implementation in the Linux kernel
did not properly initialize the Code Segment (CS) in certain error cases. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2016-9756)
Andrey Konovalov discovered that signed integer overflows existed in the
setsockopt() system call when handling the SO_SNDBUFFORCE and
SO_RCVBUFFORCE options. A local attacker with the CAP_NET_ADMIN capability
could use this to cause a denial of service (system crash or memory
corruption). (CVE-2016-9793)
OSV
CVE-2016-3169: The User module in Drupal 6
osv·2016-04-12·CVSS 8.1
CVE-2016-3169 [HIGH] CVE-2016-3169: The User module in Drupal 6
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2016/dsa-3498http://www.openwall.com/lists/oss-security/2016/02/24/19http://www.openwall.com/lists/oss-security/2016/03/15/10https://www.drupal.org/SA-CORE-2016-001http://www.debian.org/security/2016/dsa-3498http://www.openwall.com/lists/oss-security/2016/02/24/19http://www.openwall.com/lists/oss-security/2016/03/15/10https://www.drupal.org/SA-CORE-2016-001
2016-04-12
Published