CVE-2016-5410

NameCVE-2016-5410
Descriptionfirewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries D-Bus API method.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs834529

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
firewalld (PTS)buster0.6.3-5fixed
bullseye0.9.3-2fixed
bookworm1.3.3-1~deb12u1fixed
sid, trixie2.1.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
firewalldsource(unstable)0.4.3.3-1834529

Notes

[jessie] - firewalld <ignored> (Minor issue)
Introduced by: https://github.com/t-woerner/firewalld/commit/6b9867cd5c5e2c83adeec42666521a420e59ef11

Search for package or bug name: Reporting problems