Fedora

Fedora Linux 16 (Verne)

Fedora Linux 16 (Verne)

The Fedora Linux 16 (Verne) reached end of service life on Feb 12, 2013 — Fedora no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.

End of Service LifeEOSL Date: Feb 12, 2013
Issue Management

24/7 engineers own your Fedora Linux 16 (Verne) incidents end to end.

Vulnerability Remediation

Mitigation and patch-around guidance when the vendor no longer ships fixes.

Compliance Maintenance

Controls evidence and documentation that keep auditors satisfied.

Specifications

product
fedora
release
16
product Label
Fedora Linux
release Label
16 (Verne)
codename
Verne
lts
latest Version
release Date
2011-11-08
maintained
source Url
https://endoflife.date/fedora

Lifecycle Dates

End of Service Life
Feb 12, 2013
Last OEM Support
Feb 12, 2013

Get Third Party Support

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.

OEM vs. 3rd Party Support

See how third-party support compares to the vendor contract for Fedora Linux 16 (Verne) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.

FeatureOEM Support3rd Party Support
Post-EOSL Support
Break/Fix Support
Until EOSL
24/7 Monitoring
Vulnerability Scanning & Remediation
Managed Operations
Procedure & Configuration Review
Compliance & Audit Documentation
Limited
Discounted Migration to Other Platforms

Why Choose 3rd Party Support for Fedora Linux 16 (Verne)?

Vulnerability Remediation

Scanning, mitigation and patch-around guidance for Fedora Linux 16 (Verne) when the vendor no longer ships fixes.

Compliance Maintenance

Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.

24/7 Expert Support

Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.

Fedora Linux 16 (Verne) Support: Frequently Asked Questions

Is the Fedora Linux 16 (Verne) still supported?

Fedora ended support for the Fedora Linux 16 (Verne) on Feb 12, 2013 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.

When is the Fedora Linux 16 (Verne) end of service life (EOSL) date?

Fedora lists the end of service life for the Fedora Linux 16 (Verne) as Feb 12, 2013.

Can I keep using the Fedora Linux 16 (Verne) after its EOSL date?

Yes. EOSL means Fedora stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.

How much does third-party support for the Fedora Linux 16 (Verne) cost?

Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.

Known Vulnerabilities Affecting Fedora Linux 16 (Verne)

76 published CVEs affect the Fedora Linux 16 (Verne), including 24 rated critical or high severity. Fedora no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.

CVESeverityCVSSPublishedSummary
CVE-2019-11235CRITICAL9.8Apr 22, 2019FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499.
CVE-2019-11234CRITICAL9.8Apr 22, 2019FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.
CVE-2012-4406CRITICAL9.8Oct 22, 2012OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
CVE-2011-4862HIGH10.0Dec 25, 2011Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
CVE-2012-6075HIGH9.3Feb 13, 2013Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.
CVE-2019-10132HIGH8.8May 22, 2019A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.
CVE-2011-3045HIGH8.8Mar 22, 2012Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.
CVE-2012-1168HIGH8.2Nov 14, 2019Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
CVE-2012-1615HIGH7.8Dec 6, 2019A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.
CVE-2010-4661HIGH7.8Nov 13, 2019udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
CVE-2018-5345HIGH7.8Jan 12, 2018A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.
CVE-2011-4088HIGH7.5Jan 31, 2020ABRT might allow attackers to obtain sensitive information from crash reports.
CVE-2012-5645HIGH7.5Dec 30, 2019A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption.
CVE-2012-4524HIGH7.5Nov 21, 2019xlockmore before 5.43 'dclock' security bypass vulnerability
CVE-2011-2726HIGH7.5Nov 15, 2019An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.
CVE-2012-1170HIGH7.5Nov 14, 2019Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
CVE-2012-1156HIGH7.5Nov 14, 2019Moodle before 2.2.2 has users' private files included in course backups
CVE-2012-1155HIGH7.5Nov 14, 2019Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
CVE-2019-3804HIGH7.5Mar 26, 2019It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.
CVE-2012-6129HIGH7.5Apr 3, 2013Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets."

Showing the 20 most severe of 76 known CVEs.

Get Third Party Support

Related Fedora Products

All Fedora products →
Fedora Linux 16 (Verne)
Save 40-70% vs OEM
Get Third Party Support