CVE-2016-3696: Infoleak
Sander Bos reports:
It was found that pulp-qpid-ssl-cfg script creates certificate files and NSS database files in world-readable unsafe temporary directory $DIR, from which is than the content copied to permanent installation directory $INSTDIR with wrongly assigned permissions, which are corrected only after the copying process is done. This bug gives attacker a time frame for stealing sensitive data.
Other sources
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3696?
CVE-2016-3696 has a moderate severity rating due to the potential exposure of sensitive CA keys to local users.
How do I fix CVE-2016-3696?
To fix CVE-2016-3696, upgrade Pulp to version 2.8.5 or later to ensure the creation of certificate files in a secure environment.
Who is affected by CVE-2016-3696?
CVE-2016-3696 affects Fedora 24 systems and Pulp versions up to and including 2.8.4.
What vulnerability does CVE-2016-3696 address?
CVE-2016-3696 addresses a vulnerability that allows local users to access the CA key due to insecure file permissions.
Is CVE-2016-3696 still a risk in newer versions?
No, CVE-2016-3696 is not a risk in newer versions of Pulp beyond 2.8.5, as the issue has been resolved.