Fedora Linux 16 (Verne)
Fedora Linux 16 (Verne)
The Fedora Linux 16 (Verne) reached end of service life on Feb 12, 2013 — Fedora no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Fedora Linux 16 (Verne) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- fedora
- release
- 16
- product Label
- Fedora Linux
- release Label
- 16 (Verne)
- codename
- Verne
- lts
- latest Version
- release Date
- 2011-11-08
- maintained
- source Url
- https://endoflife.date/fedora
Lifecycle Dates
- End of Service Life
- Feb 12, 2013
- Last OEM Support
- Feb 12, 2013
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Fedora Linux 16 (Verne) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Fedora Linux 16 (Verne)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Fedora Linux 16 (Verne) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Fedora Linux 16 (Verne) Support: Frequently Asked Questions
Is the Fedora Linux 16 (Verne) still supported?
Fedora ended support for the Fedora Linux 16 (Verne) on Feb 12, 2013 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Fedora Linux 16 (Verne) end of service life (EOSL) date?
Fedora lists the end of service life for the Fedora Linux 16 (Verne) as Feb 12, 2013.
Can I keep using the Fedora Linux 16 (Verne) after its EOSL date?
Yes. EOSL means Fedora stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Fedora Linux 16 (Verne) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Fedora Linux 16 (Verne)
76 published CVEs affect the Fedora Linux 16 (Verne), including 24 rated critical or high severity. Fedora no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2019-11235 | CRITICAL | 9.8 | Apr 22, 2019 | FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499. |
| CVE-2019-11234 | CRITICAL | 9.8 | Apr 22, 2019 | FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497. |
| CVE-2012-4406 | CRITICAL | 9.8 | Oct 22, 2012 | OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object. |
| CVE-2011-4862 | HIGH | 10.0 | Dec 25, 2011 | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011. |
| CVE-2012-6075 | HIGH | 9.3 | Feb 13, 2013 | Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet. |
| CVE-2019-10132 | HIGH | 8.8 | May 22, 2019 | A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons. |
| CVE-2011-3045 | HIGH | 8.8 | Mar 22, 2012 | Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026. |
| CVE-2012-1168 | HIGH | 8.2 | Nov 14, 2019 | Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified. |
| CVE-2012-1615 | HIGH | 7.8 | Dec 6, 2019 | A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file. |
| CVE-2010-4661 | HIGH | 7.8 | Nov 13, 2019 | udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules. |
| CVE-2018-5345 | HIGH | 7.8 | Jan 12, 2018 | A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file. |
| CVE-2011-4088 | HIGH | 7.5 | Jan 31, 2020 | ABRT might allow attackers to obtain sensitive information from crash reports. |
| CVE-2012-5645 | HIGH | 7.5 | Dec 30, 2019 | A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption. |
| CVE-2012-4524 | HIGH | 7.5 | Nov 21, 2019 | xlockmore before 5.43 'dclock' security bypass vulnerability |
| CVE-2011-2726 | HIGH | 7.5 | Nov 15, 2019 | An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. |
| CVE-2012-1170 | HIGH | 7.5 | Nov 14, 2019 | Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough |
| CVE-2012-1156 | HIGH | 7.5 | Nov 14, 2019 | Moodle before 2.2.2 has users' private files included in course backups |
| CVE-2012-1155 | HIGH | 7.5 | Nov 14, 2019 | Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to |
| CVE-2019-3804 | HIGH | 7.5 | Mar 26, 2019 | It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash. |
| CVE-2012-6129 | HIGH | 7.5 | Apr 3, 2013 | Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets." |
Showing the 20 most severe of 76 known CVEs.
Get Third Party Support