PublicDateAtUSN: 2016-11-03 Candidate: CVE-2016-7035 PublicDate: 2018-09-10 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7035 https://github.com/ClusterLabs/pacemaker/pull/1166 https://ubuntu.com/security/notices/USN-3462-1 Description: An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=843041 Priority: medium Discovered-by: Jan Pokorný and Alain Moulle Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_pacemaker: upstream: https://github.com/ClusterLabs/pacemaker/commit/5d71e65049 upstream_pacemaker: released (1.1.15-3) precise_pacemaker: ignored (reached end-of-life) precise/esm_pacemaker: DNE (precise was needs-triage) trusty_pacemaker: released (1.1.10+git20130802-1ubuntu2.4) trusty/esm_pacemaker: DNE (trusty was released [1.1.10+git20130802-1ubuntu2.4]) vivid/stable-phone-overlay_pacemaker: DNE vivid/ubuntu-core_pacemaker: DNE xenial_pacemaker: released (1.1.14-2ubuntu1.2) esm-infra/xenial_pacemaker: released (1.1.14-2ubuntu1.2) yakkety_pacemaker: ignored (reached end-of-life) zesty_pacemaker: not-affected (1.1.16-1ubuntu1) artful_pacemaker: not-affected (1.1.16-1ubuntu1) devel_pacemaker: not-affected (1.1.16-1ubuntu1)