High severity8.8NVD Advisory· Published Sep 10, 2018· Updated Jun 17, 2026
CVE-2016-7035
CVE-2016-7035
Description
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7<1.1.16+ 1 more
- (no CPE)range: <1.1.16
- (no CPE)range: 1.1.16
- osv-coords5 versionspkg:rpm/suse/pacemaker&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2011%20SP4pkg:rpm/suse/pacemaker&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP1pkg:rpm/suse/pacemaker&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP2pkg:rpm/suse/pacemaker&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/pacemaker&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2
< 1.1.12-18.1+ 4 more
- (no CPE)range: < 1.1.12-18.1
- (no CPE)range: < 1.1.13-20.1
- (no CPE)range: < 1.1.15-21.1
- (no CPE)range: < 1.1.13-20.1
- (no CPE)range: < 1.1.15-21.1
Patches
Vulnerability mechanics
References
8- rhn.redhat.com/errata/RHSA-2016-2614.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2016-2675.htmlnvdThird Party Advisory
- www.openwall.com/lists/oss-security/2016/11/03/5nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/94214nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- github.com/ClusterLabs/pacemaker/commit/5d71e65049nvdThird Party Advisory
- lists.clusterlabs.org/pipermail/users/2016-November/004432.htmlnvdMailing ListVendor Advisory
- security.gentoo.org/glsa/201710-08nvdThird Party Advisory
News mentions
0No linked articles in our index yet.