Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-0764


Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive connection information by reading temporary files during ifcfg and keyfile changes.


Published

2017-07-17T13:18:05.373

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 6.2 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-362

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat networkmanager ≤ 1.0.8 Yes
Operating System redhat enterprise_linux_desktop 7.0 No
Operating System redhat enterprise_linux_hpc_node 7.0 No
Operating System redhat enterprise_linux_server 7.0 No
Operating System redhat enterprise_linux_workstation 7.0 No

References