CVE-2016-5425 PUBLISHED

Reported by redhat · Published October 13, 2016

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.

Affected Products

VendorProductVersions
n/an/an/a
chainguardtomcat-8.5.87*
n/an/an/a

Timeline

References

Open in Interactive Console →