CVE-2016-1611: Novell Filr

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.sh, which allows local users to gain privileges by replacing this file's content with arbitrary shell commands.

Affected products

  • Novell Filr: up to and including 1.2; up to and including 2.0

Published 2016-08-01. Last modified 2026-06-17.