CVE-2016-2057
published 2016-04-13CVE-2016-2057: lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to…
PriorityP411low3.3CVSS 3.0
AVLACLPRLUINSUCNILAN
EPSS
0.47%
38.3th percentile
lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to inject arbitrary messages by writing to that queue.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xymon | < xymon 4.3.25-1 (bookworm) | xymon 4.3.25-1 (bookworm) |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
| xymon | xymon | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv3.3LOW
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-529x-f9rr-pg3j: lib/xymond_ipc
ghsa_unreviewed·2022-05-14
CVE-2016-2057 [LOW] GHSA-529x-f9rr-pg3j: lib/xymond_ipc
lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to inject arbitrary messages by writing to that queue.
OSV
CVE-2016-2057: lib/xymond_ipc
osv·2016-04-13·CVSS 3.3
CVE-2016-2057 [LOW] CVE-2016-2057: lib/xymond_ipc
lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to inject arbitrary messages by writing to that queue.
Debian
CVE-2016-2057: xymon - lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permiss...
vendor_debian·2016·CVSS 3.3
CVE-2016-2057 [LOW] CVE-2016-2057: xymon - lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permiss...
lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to inject arbitrary messages by writing to that queue.
Scope: local
bookworm: resolved (fixed in 4.3.25-1)
bullseye: resolved (fixed in 4.3.25-1)
forky: resolved (fixed in 4.3.25-1)
sid: resolved (fixed in 4.3.25-1)
trixie: resolved (fixed in 4.3.25-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.htmlhttp://www.debian.org/security/2016/dsa-3495http://www.securityfocus.com/archive/1/537522/100/0/threadedhttps://sourceforge.net/p/xymon/code/7891/http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.htmlhttp://www.debian.org/security/2016/dsa-3495http://www.securityfocus.com/archive/1/537522/100/0/threadedhttps://sourceforge.net/p/xymon/code/7891/
2016-04-13
Published