CVE-2016-5425

Publication date 13 October 2016

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

7.8 · High

Score breakdown

Description

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.

Status

Package Ubuntu Release Status
tomcat6 16.04 LTS xenial
Not affected
14.04 LTS trusty
Not affected
12.04 LTS precise
Not affected
tomcat7 16.04 LTS xenial
Not affected
14.04 LTS trusty
Not affected
12.04 LTS precise
Not affected
tomcat8 16.04 LTS xenial
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.8 · High

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H


Access our resources on patching vulnerabilities