CVE-2016-1241
medium
CVSS v3
5.3
CVSS v2
3.5
VIR risk
5.3
Description
Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remote authenticated users to discover user password hashes via unspecified vectors.
Predictions
Exploit likelihood
63%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-1241
Vendor advisory: security@debian.org — http://www.tryton.org/posts/security-release-for-issue5795-and-issue5808.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 4.0.4-1 |
| debian | bullseye | fixed | 4.0.4-1 |
| debian | forky | fixed | 4.0.4-1 |
| debian | sid | fixed | 4.0.4-1 |
| debian | trixie | fixed | 4.0.4-1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| tryton | tryton | 3.8.0 | |
| tryton | tryton | 3.8.1 | |
| tryton | tryton | 3.8.2 | |
| tryton | tryton | 3.8.3 | |
| tryton | tryton | 3.8.4 | |
| tryton | tryton | 3.8.5 | |
| tryton | tryton | 3.8.6 | |
| tryton | tryton | 3.8.7 | |
| tryton | tryton | 4.0.0 | |
| tryton | tryton | 4.0.1 | |
| tryton | tryton | 4.0.2 | |
| tryton | tryton | 4.0.3 | |
| tryton | tryton | {"endIncluding":"3.2.16"} | |
| tryton | tryton | 3.2.0 | |
| tryton | tryton | 3.6.0 | |
| tryton | tryton | 3.6.1 | |
| tryton | tryton | 3.6.2 | |
| tryton | tryton | 3.6.3 | |
| tryton | tryton | 3.6.4 | |
| tryton | tryton | 3.6.5 | |
| tryton | tryton | 3.6.6 | |
| tryton | tryton | 3.6.7 | |
| tryton | tryton | 3.6.8 | |
| tryton | tryton | 3.6.9 | |
| tryton | tryton | 3.6.10 | |
| tryton | tryton | 3.6.11 | |
| tryton | tryton | 3.4.0 | |
| tryton | tryton | 3.4.1 | |
| tryton | tryton | 3.4.2 | |
| tryton | tryton | 3.4.3 | |
| tryton | tryton | 3.4.4 | |
| tryton | tryton | 3.4.5 | |
| tryton | tryton | 3.4.6 | |
| tryton | tryton | 3.4.7 | |
| tryton | tryton | 3.4.8 | |
| tryton | tryton | 3.4.9 | |
| tryton | tryton | 3.4.10 | |
| tryton | tryton | 3.4.11 | |
| tryton | tryton | 3.4.12 | |
| tryton | tryton | 3.4.13 | |
References
- https://nvd.nist.gov/vuln/detail/CVE-2016-1241
- https://github.com/tryton/trytond/commit/11424d57b7838381745655e2e89470ff9087cd27
- https://github.com/tryton/trytond/commit/30d2a6dcaf09340829cd70ee8a15a4941ca7161a
- https://bugs.tryton.org/issue5795
- https://github.com/pypa/advisory-database/tree/main/vulns/tryton/PYSEC-2016-40.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/trytond/PYSEC-2016-12.yaml
- https://github.com/tryton/trytond
- http://www.debian.org/security/2016/dsa-3656
- http://www.tryton.org/posts/security-release-for-issue5795-and-issue5808.html
- https://security-tracker.debian.org/tracker/CVE-2016-1241
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.