CVE-2016-0764
Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive…
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive connection information by reading temporary files during ifcfg and keyfile changes.
- CVSS 3.1
- 6.2 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- redhat/networkmanager
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2016-2581.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1324025Issue Tracking
- http://rhn.redhat.com/errata/RHSA-2016-2581.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1324025Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.