CVE-2016-7035
published 2018-09-10CVE-2016-7035: An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a…
PriorityP341high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.40%
31.8th percentile
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clusterlabs | pacemaker | <= 1.1.16 | — |
| clusterlabs | pacemaker | — | — |
| clusterlabs | pacemaker | >= 0 < 1.1.15-3 | 1.1.15-3 |
| clusterlabs | pacemaker | >= 0 < 1.1.15-3 | 1.1.15-3 |
| clusterlabs | pacemaker | >= 0 < 1.1.15-3 | 1.1.15-3 |
| clusterlabs | pacemaker | >= 0 < 1.1.15-3 | 1.1.15-3 |
| clusterlabs | pacemaker | >= 0 < 1.1.10+git20130802-1ubuntu2.4 | 1.1.10+git20130802-1ubuntu2.4 |
| clusterlabs | pacemaker | >= 0 < 1.1.14-2ubuntu1.2 | 1.1.14-2ubuntu1.2 |
| debian | pacemaker | < pacemaker 1.1.15-3 (bookworm) | pacemaker 1.1.15-3 (bookworm) |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pacemaker vulnerabilities
vendor_ubuntu·2017-10-24·CVSS 8.8
CVE-2016-7035 [HIGH] Pacemaker vulnerabilities
Title: Pacemaker vulnerabilities
Summary: Several security issues were fixed in Pacemaker.
Jan Pokorný and Alain Moulle discovered that Pacemaker incorrectly handled
the IPC interface. A local attacker could possibly use this issue to
execute arbitrary code with root privileges. (CVE-2016-7035)
Alain Moulle discovered that Pacemaker incorrectly handled authentication.
A remote attacker could possibly use this issue to shut down connections,
leading to a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-7797)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pacemaker: Privilege escalation due to improper guarding of IPC communication
vendor_redhat·2016-11-03·CVSS 8.8
CVE-2016-7035 [HIGH] CWE-285 pacemaker: Privilege escalation due to improper guarding of IPC communication
pacemaker: Privilege escalation due to improper guarding of IPC communication
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.
An authorization flaw was found in Pacemaker, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.
Debian
CVE-2016-7035: pacemaker - An authorization flaw was found in Pacemaker before 1.1.16, where it did not pro...
vendor_debian·2016·CVSS 8.8
CVE-2016-7035 [HIGH] CVE-2016-7035: pacemaker - An authorization flaw was found in Pacemaker before 1.1.16, where it did not pro...
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.
Scope: local
bookworm: resolved (fixed in 1.1.15-3)
bullseye: resolved (fixed in 1.1.15-3)
forky: resolved (fixed in 1.1.15-3)
sid: resolved (fixed in 1.1.15-3)
trixie: resolved (fixed in 1.1.15-3)
GHSA
GHSA-5wmv-gcg2-v47h: An authorization flaw was found in Pacemaker before 1
ghsa_unreviewed·2022-05-13
CVE-2016-7035 [HIGH] CWE-285 GHSA-5wmv-gcg2-v47h: An authorization flaw was found in Pacemaker before 1
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.
OSV
CVE-2016-7035: An authorization flaw was found in Pacemaker before 1
osv·2018-09-10·CVSS 7.8
CVE-2016-7035 [HIGH] CVE-2016-7035: An authorization flaw was found in Pacemaker before 1
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.
OSV
pacemaker vulnerabilities
osv·2017-10-24·CVSS 7.8
CVE-2016-7035 [HIGH] pacemaker vulnerabilities
pacemaker vulnerabilities
Jan Pokorný and Alain Moulle discovered that Pacemaker incorrectly handled
the IPC interface. A local attacker could possibly use this issue to
execute arbitrary code with root privileges. (CVE-2016-7035)
Alain Moulle discovered that Pacemaker incorrectly handled authentication.
A remote attacker could possibly use this issue to shut down connections,
leading to a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-7797)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7035 pacemaker: Privilege escalation due to improper guarding of IPC communication [fedora-all]
bugzilla·2016-11-03·CVSS 8.8
CVE-2016-7035 [HIGH] CVE-2016-7035 pacemaker: Privilege escalation due to improper guarding of IPC communication [fedora-all]
CVE-2016-7035 pacemaker: Privilege escalation due to improper guarding of IPC communication [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
Bugzilla
CVE-2016-7035 pacemaker: Privilege escalation due to improper guarding of IPC communication
bugzilla·2016-08-24·CVSS 8.8
CVE-2016-7035 [HIGH] CVE-2016-7035 pacemaker: Privilege escalation due to improper guarding of IPC communication
CVE-2016-7035 pacemaker: Privilege escalation due to improper guarding of IPC communication
It was found that pacemaker doesn't properly check privileges and allows to change privileges to root level for non-privileged user.
Vulnerable code (lib/common/ipc.c):
317 if(gid_cluster != 0 && gid_client != 0) {
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
318 uid_t best_uid = -1; /* Passing -1 to chown(2) means don't change */
319
320 if(uid_client == 0 || uid_server == 0) { /* Someone is priveliged, but the other may not be */
^^^^^^^^^^^^^^^^
321 best_uid = QB_MAX(uid_client, uid_server);
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
322 crm_trace("Allowing user %u to clean up after disconnect", best_uid);
323 }
324
325 crm_trace("Giving access to group %u", gid_cluster);
326 qb_ipcs_connection_auth_se
http://rhn.redhat.com/errata/RHSA-2016-2614.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2675.htmlhttp://www.openwall.com/lists/oss-security/2016/11/03/5http://www.securityfocus.com/bid/94214https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7035https://github.com/ClusterLabs/pacemaker/commit/5d71e65049https://lists.clusterlabs.org/pipermail/users/2016-November/004432.htmlhttps://security.gentoo.org/glsa/201710-08http://rhn.redhat.com/errata/RHSA-2016-2614.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2675.htmlhttp://www.openwall.com/lists/oss-security/2016/11/03/5http://www.securityfocus.com/bid/94214https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7035https://github.com/ClusterLabs/pacemaker/commit/5d71e65049https://lists.clusterlabs.org/pipermail/users/2016-November/004432.htmlhttps://security.gentoo.org/glsa/201710-08
2018-09-10
Published