CVE-2016-1844
published 2016-05-20CVE-2016-1844: The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote attackers to modify contact lists via unspecified vectors.
PriorityP431medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
1.91%
77.8th percentile
The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote attackers to modify contact lists via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.11.4 | — |
| apple | os_x_el_capitan_v10.11.5_and_security_update_2016-003 | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-1844: OS X El Capitan v10.11.5 and Security Update 2016-003
vendor_apple·CVSS 5.3
CVE-2016-1844 [MEDIUM] CVE-2016-1844: OS X El Capitan v10.11.5 and Security Update 2016-003
Apple Security Update: About the security content of OS X El Capitan v10.11.5 and Security Update 2016-003
Product: OS X El Capitan v10.11.5 and Security Update 2016-003
CVE: CVE-2016-1844
Component: CVE-ID
GHSA
GHSA-77qc-55hq-3c2q: The Messages component in Apple OS X before 10
ghsa_unreviewed·2022-05-17
CVE-2016-1844 [MEDIUM] CWE-284 GHSA-77qc-55hq-3c2q: The Messages component in Apple OS X before 10
The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote attackers to modify contact lists via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8934 libarchive: out of bounds heap read in RAR parser
bugzilla·2016-06-23·CVSS 5.5
CVE-2015-8934 [MEDIUM] CVE-2015-8934 libarchive: out of bounds heap read in RAR parser
CVE-2015-8934 libarchive: out of bounds heap read in RAR parser
An out of bounds read was found in libarchive's RAR parser. A specially
crafted file could cause the application to read heap memory beyond the end
of the decompression buffer.
Upstream bug:
https://github.com/libarchive/libarchive/issues/521
Upstream fix:
https://github.com/libarchive/libarchive/commit/603454e
Fix included in upstream release v3.2.1.
The vulnerable code was not included in libarchive-2.8.
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-2016-1844.html
Bugzilla
CVE-2015-8930 libarchive: Endless loop in ISO parser
bugzilla·2016-06-23·CVSS 7.5
CVE-2015-8930 [HIGH] CVE-2015-8930 libarchive: Endless loop in ISO parser
CVE-2015-8930 libarchive: Endless loop in ISO parser
A denial of service was discovered in libarchive in the processing of .iso
files. A specially crafted .iso could cause the process to go into an (almost)
endless loop, eventually exiting with an error after hitting memory limits.
libarchive-2.8 does not support the required construct in ISO files.
Upstream bug:
https://github.com/libarchive/libarchive/issues/522
Upstream fix (two parts):
https://github.com/libarchive/libarchive/commit/39fc593
https://github.com/libarchive/libarchive/commit/01cfbca
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/
Bugzilla
CVE-2015-8923 libarchive: Unclear crashes in ZIP parser
bugzilla·2016-06-22·CVSS 6.5
CVE-2015-8923 [MEDIUM] CVE-2015-8923 libarchive: Unclear crashes in ZIP parser
CVE-2015-8923 libarchive: Unclear crashes in ZIP parser
An out-of-bounds read due to incorrect sign extension was found in
libarchive. A specially crafted ZIP file could cause libarchive to
crash. A few bytes of heap memory within a 256-byte region could
potentially be exposed.
Upstream bug:
https://github.com/libarchive/libarchive/issues/514
Upstream fix:
https://github.com/libarchive/libarchive/commit/9e0689c
libarchive-2.8 does not include support for "Info-Zip Unix extra field
(type 3)", where this flaw was found, and is thus unaffected.
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-201
Bugzilla
CVE-2015-8931 libarchive: Undefined behavior (signed integer overflow) in mtree parser
bugzilla·2016-06-22·CVSS 7.8
CVE-2015-8931 [HIGH] CVE-2015-8931 libarchive: Undefined behavior (signed integer overflow) in mtree parser
CVE-2015-8931 libarchive: Undefined behavior (signed integer overflow) in mtree parser
Undefined behaviour (signed integer overflow) was discovered in libarchive,
in the MTREE parser's calculation of maximum and minimum dates.
Upstream bug:
https://github.com/libarchive/libarchive/issues/539
Upstream fix:
https://github.com/libarchive/libarchive/commit/b31744d
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
---
FTR: Also 11f6da24 should be backported.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-2016-1844.html
Bugzilla
CVE-2015-8922 libarchive: NULL pointer access in 7z parser
bugzilla·2016-06-21·CVSS 5.5
CVE-2015-8922 [MEDIUM] CVE-2015-8922 libarchive: NULL pointer access in 7z parser
CVE-2015-8922 libarchive: NULL pointer access in 7z parser
Upstream bug:
https://github.com/libarchive/libarchive/issues/513
Upstream fix:
https://github.com/libarchive/libarchive/commit/d094dc
libarchive-2.8 does not include support for this format.
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-2016-1844.html
Bugzilla
CVE-2015-8920 libarchive: Stack out of bounds read in ar parser
bugzilla·2016-06-21·CVSS 5.5
CVE-2015-8920 [MEDIUM] CVE-2015-8920 libarchive: Stack out of bounds read in ar parser
CVE-2015-8920 libarchive: Stack out of bounds read in ar parser
Upstream bug:
https://github.com/libarchive/libarchive/issues/511
Upstream fix:
https://github.com/libarchive/libarchive/commit/97f964e
> While pruning trailing text from ar filenames, we did not
> check for an empty filename. This results in reading the
> byte before the filename on the stack.
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
Affects: epel-5 [bug 1352775]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1850 https://rhn.redhat.com/errata/RHSA-2016-1850.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-20
Bugzilla
CVE-2015-8925 libarchive: Unclear invalid memory read in mtree parser
bugzilla·2016-06-21·CVSS 5.5
CVE-2015-8925 [MEDIUM] CVE-2015-8925 libarchive: Unclear invalid memory read in mtree parser
CVE-2015-8925 libarchive: Unclear invalid memory read in mtree parser
Upstream bug:
https://github.com/libarchive/libarchive/issues/516
Upstream fix:
https://github.com/libarchive/libarchive/commit/1e18cbb71
Incorrect parsing of escaped newlines allows a small OOB read.
libarchive-2.8 has less capable mtree parsing which does not include this vulnerability.
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-2016-1844.html
Bugzilla
CVE-2015-8924 libarchive: Heap out of bounds read in TAR parser
bugzilla·2016-06-21·CVSS 5.5
CVE-2015-8924 [MEDIUM] CVE-2015-8924 libarchive: Heap out of bounds read in TAR parser
CVE-2015-8924 libarchive: Heap out of bounds read in TAR parser
Upstream bug:
https://github.com/libarchive/libarchive/issues/515
Upstream fix:
https://github.com/libarchive/libarchive/commit/bb9b157
> Tar reader tries to examine last character of an empty filename
libarchive-2.8 does not appear to be vulnerable in the same way, as it rejects the invalid archive early.
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-2016-1844.html
Bugzilla
CVE-2015-8926 libarchive: NULL pointer access in RAR parser
bugzilla·2016-06-21·CVSS 5.5
CVE-2015-8926 [MEDIUM] CVE-2015-8926 libarchive: NULL pointer access in RAR parser
CVE-2015-8926 libarchive: NULL pointer access in RAR parser
Upstream bug:
https://github.com/libarchive/libarchive/issues/518
Upstream fix:
https://github.com/libarchive/libarchive/commit/aab73938
crafted RAR file can trick libarchive into returning to the caller a 128k block
of data starting at whatever value was previously in the caller's variable.
libarchive-2.8 does not include support for this format.
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-2016-1844.html
Bugzilla
CVE-2015-8919 libarchive: Heap out of bounds read in LHA/LZH parser
bugzilla·2016-06-21·CVSS 7.5
CVE-2015-8919 [HIGH] CVE-2015-8919 libarchive: Heap out of bounds read in LHA/LZH parser
CVE-2015-8919 libarchive: Heap out of bounds read in LHA/LZH parser
Upstream bug:
https://github.com/libarchive/libarchive/issues/510
Upstream fix:
https://github.com/libarchive/libarchive/commit/e8a2e4d
libarchive-2.8 does not include support for this format.
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-2016-1844.html
Bugzilla
CVE-2015-8928 libarchive: Heap out of bounds read in mtree parser
bugzilla·2016-06-21·CVSS 5.5
CVE-2015-8928 [MEDIUM] CVE-2015-8928 libarchive: Heap out of bounds read in mtree parser
CVE-2015-8928 libarchive: Heap out of bounds read in mtree parser
Upstream bug:
https://github.com/libarchive/libarchive/issues/550
Upstream fix:
https://github.com/libarchive/libarchive/commit/64d5628
> The mtree parser scanned from the end of the string to identify
> the filename when the filename is the last element of the line.
> If the filename was the entire line, the logic would scan back
> to before the start of the string.
libarchive-2.8 does not include support for this mtree variant.
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-2016-1844.html
Bugzilla
CVE-2015-8917 libarchive: NULL pointer access in CAB parser
bugzilla·2016-06-21·CVSS 7.5
CVE-2015-8917 [HIGH] CVE-2015-8917 libarchive: NULL pointer access in CAB parser
CVE-2015-8917 libarchive: NULL pointer access in CAB parser
Upstream bug:
https://github.com/libarchive/libarchive/issues/505
Upstream Fix (bsdtar only):
https://github.com/libarchive/libarchive/commit/b2e2abb
libarchive-2.8 does not include support for this format.
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-2016-1844.html
Bugzilla
CVE-2015-8916 libarchive: NULL pointer access in RAR parser through bsdtar
bugzilla·2016-06-21·CVSS 6.5
CVE-2015-8916 [MEDIUM] CVE-2015-8916 libarchive: NULL pointer access in RAR parser through bsdtar
CVE-2015-8916 libarchive: NULL pointer access in RAR parser through bsdtar
Upstream bug:
https://github.com/libarchive/libarchive/issues/504
Upstream Fix (bsdtar only):
https://github.com/libarchive/libarchive/commit/b2e2abb
libarchive-2.8 does not include support for this format.
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-2016-1844.html
http://lists.apple.com/archives/security-announce/2016/May/msg00004.htmlhttp://www.securityfocus.com/bid/90696http://www.securitytracker.com/id/1035895https://support.apple.com/HT206567http://lists.apple.com/archives/security-announce/2016/May/msg00004.htmlhttp://www.securityfocus.com/bid/90696http://www.securitytracker.com/id/1035895https://support.apple.com/HT206567
2016-05-20
Published