[Secure-testing-team] Bug#834529: firewalld: CVE-2016-5410: Firewall configuration can be modified by any logged in user

Salvatore Bonaccorso carnil at debian.org
Tue Aug 16 17:48:38 UTC 2016


Source: firewalld
Version: 0.3.12-1
Severity: important
Tags: security upstream patch fixed-upstream

Hi,

the following vulnerability was published for firewalld.

CVE-2016-5410[0]:
Firewall configuration can be modified by any logged in user

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2016-5410
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1360135
[2] http://seclists.org/oss-sec/2016/q3/291
[3] https://github.com/t-woerner/firewalld/commit/0371995a58ec4c777960007b7dbee93933f760cb

Regards,
Salvatore



More information about the Secure-testing-team mailing list