Low severity3.3NVD Advisory· Published Apr 14, 2017· Updated Jun 17, 2026
CVE-2016-4455
CVE-2016-4455
Description
The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_hpc_node:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_hpc_node:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
- Range: <1.17.7-1
Patches
Vulnerability mechanics
References
8- www.openwall.com/lists/oss-security/2016/10/26/5nvdMailing ListPatchThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party AdvisoryVDB Entry
- github.com/candlepin/subscription-manager/commit/9dec31nvdPatchThird Party Advisory
- rhn.redhat.com/errata/RHSA-2016-2592.htmlnvdThird Party AdvisoryVDB Entry
- rhn.redhat.com/errata/RHSA-2017-0698.htmlnvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/93926nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1038083nvdThird Party AdvisoryVDB Entry
- github.com/candlepin/subscription-manager/blob/subscription-manager-1.17.7-1/subscription-manager.specnvdThird Party Advisory
News mentions
0No linked articles in our index yet.