CVEs Blog | G5 Cyber Security

CVE-2016-5425 – The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS,

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5425

Reference (s):

Exit mobile version