CVE-2016-10659
published 2018-05-29CVE-2016-10659: poco - The POCO libraries, downloads source file resources used for compilation over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to…
PriorityP340high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
1.75%
75.7th percentile
poco - The POCO libraries, downloads source file resources used for compilation over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hackerone | poco_node_module | — | — |
| macchina | poco | <= 1.7.7 | — |
| pocoproject | poco | 0 – 1.5.4 | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
poco downloads Resources over HTTP
ghsa·2019-02-18
CVE-2016-10659 [HIGH] CWE-311 poco downloads Resources over HTTP
poco downloads Resources over HTTP
Affected versions of `poco` insecurely download an executable over an unencrypted HTTP connection.
In scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `poco`.
## Recommendation
No patch is currently available for this vulnerability.
The best mitigation is currently to avoid using this package, using a different package if available.
Alternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromise
OSV
poco downloads Resources over HTTP
osv·2019-02-18
CVE-2016-10659 [HIGH] poco downloads Resources over HTTP
poco downloads Resources over HTTP
Affected versions of `poco` insecurely download an executable over an unencrypted HTTP connection.
In scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `poco`.
## Recommendation
No patch is currently available for this vulnerability.
The best mitigation is currently to avoid using this package, using a different package if available.
Alternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromise
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-10659 poco: MITM due to resources download over HTTP [epel-all]
bugzilla·2018-05-31·CVSS 8.1
CVE-2016-10659 [HIGH] CVE-2016-10659 poco: MITM due to resources download over HTTP [epel-all]
CVE-2016-10659 poco: MITM due to resources download over HTTP [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2016-10659 poco: MITM due to resources download over HTTP
bugzilla·2018-05-31·CVSS 8.1
CVE-2016-10659 [HIGH] CVE-2016-10659 poco: MITM due to resources download over HTTP
CVE-2016-10659 poco: MITM due to resources download over HTTP
A flaw was found in the POCO libraries, downloads source file resources used for compliation over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
References:
https://nodesecurity.io/advisories/271
Discussion:
Created poco tracking bugs for this issue:
Affects: epel-all [bug 1584894]
Affects: fedora-all [bug 1584895]
---
I believe this can be closed out as the CVE doesn't apply to the Fedora/EPEL packages, but to a Node package of poco.
---
Closing as this does not apply to the Fedora/EPEL packages.
Bugzilla
CVE-2016-10659 poco: MITM due to resources download over HTTP [fedora-all]
bugzilla·2018-05-31·CVSS 8.1
CVE-2016-10659 [HIGH] CVE-2016-10659 poco: MITM due to resources download over HTTP [fedora-all]
CVE-2016-10659 poco: MITM due to resources download over HTTP [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
2018-05-29
Published