UBUNTU-CVE-2016-10156

Source
https://ubuntu.com/security/CVE-2016-10156
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-10156.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2016-10156
Related
Published
2017-01-23T07:59:00Z
Modified
2017-01-23T07:59:00Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root. This is fixed in v229.

References

Affected packages

Ubuntu:16.04:LTS / systemd

Package

Name
systemd
Purl
pkg:deb/ubuntu/systemd?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
229-4ubuntu16

Affected versions

Other

225-1ubuntu9
227-2ubuntu1
227-2ubuntu2
228-1ubuntu2
228-2ubuntu1
228-2ubuntu2
228-3ubuntu1
228-4ubuntu1
228-4ubuntu2
228-5ubuntu1
228-5ubuntu2
228-5ubuntu3
228-6ubuntu1
229-1ubuntu2
229-1ubuntu4
229-2ubuntu1
229-3ubuntu1
229-3ubuntu2
229-4ubuntu1
229-4ubuntu4
229-4ubuntu5
229-4ubuntu6
229-4ubuntu7
229-4ubuntu8
229-4ubuntu10
229-4ubuntu11
229-4ubuntu12
229-4ubuntu13

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "high",
    "binaries": [
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libnss-myhostname"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libnss-myhostname-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libnss-mymachines"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libnss-mymachines-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libnss-resolve"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libnss-resolve-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libpam-systemd"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libpam-systemd-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libsystemd-dev"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libsystemd-dev-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libsystemd0"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libsystemd0-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libudev-dev"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libudev-dev-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libudev1"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libudev1-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libudev1-udeb"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "libudev1-udeb-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "systemd"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "systemd-container"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "systemd-container-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "systemd-coredump"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "systemd-coredump-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "systemd-dbg"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "systemd-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "systemd-journal-remote"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "systemd-journal-remote-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "systemd-sysv"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "systemd-sysv-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "udev"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "udev-dbgsym"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "udev-udeb"
        },
        {
            "binary_version": "229-4ubuntu16",
            "binary_name": "udev-udeb-dbgsym"
        }
    ]
}