CVE-2016-2957
published 2016-11-30CVE-2016-2957: IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace…
PriorityP419medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
1.15%
63.3th percentile
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | connections | — | — |
| ibm | connections | — | — |
| ibm | connections | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-849g-mx4m-3h2v: IBM Connections 4
ghsa_unreviewed·2022-05-17
CVE-2016-2957 [MEDIUM] CWE-200 GHSA-849g-mx4m-3h2v: IBM Connections 4
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response.
Red Hat
libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
vendor_redhat·2016-05-03·CVSS 7.5
CVE-2016-9597 [HIGH] CWE-674 libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
libxml2: stack overflow before detecting invalid XML file (unfixed CVE-2016-3705 in JBCS)
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705.
Package: libxml2 (Red Hat Enterprise Linux 5) - Not affected
Package: libxml2 (Red Hat Enterprise Linux 6) - Not affected
Package: libxml2 (Red Hat Enterprise Linux 7) - Not affected
Package: httpd (Red Hat JBoss Core Services) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9596 libxml2: stack exhaustion while parsing xml files in recovery mode (unfixed CVE-2016-3627 in JBCS)
bugzilla·2016-12-22·CVSS 7.5
CVE-2016-9596 [HIGH] CVE-2016-9596 libxml2: stack exhaustion while parsing xml files in recovery mode (unfixed CVE-2016-3627 in JBCS)
CVE-2016-9596 libxml2: stack exhaustion while parsing xml files in recovery mode (unfixed CVE-2016-3627 in JBCS)
It was found that Red Hat JBoss Core Services incorrectly fixed CVE-2016-3627 in Apache HTTP 2.4.23 (erratum RHSA-2016:2957), leaving libxml2 vulnerable to a Denial of Service attack via stack consumption.
Discussion:
Are there any details available for this? Upsteam bug, commit reference?
---
(In reply to Salvatore Bonaccorso from comment #2)
> Are there any details available for this? Upsteam bug, commit reference?
This and the other two should be for a Red Hat specific security regressions, effectively duplicates of other public CVEs. I'm going to ask Bharti to fix these bugs up properly.
---
dup of CVE-2016-3627 I would say
---
This CVE id is for the same issue as
Bugzilla
CVE-2016-8612 JBCS mod_cluster: Protocol parsing logic error
bugzilla·2016-10-21·CVSS 4.3
CVE-2016-8612 [MEDIUM] CVE-2016-8612 JBCS mod_cluster: Protocol parsing logic error
CVE-2016-8612 JBCS mod_cluster: Protocol parsing logic error
There is an error in protocol parsing logic of mod_cluster load balancer Apache HTTP Server modules that allows attacker to cause a Segmentation Fault in the serving httpd process. The vector is mod_cluster service messages that are used by worker nodes to communicate their status, load and deployed applications to the mod_cluster balancer. With proper production configuration, the VirtualHost accepting these messages is accessible only from an internal network where worker nodes reside. The error cannot be exploited from the Internet by arbitrary clients.
Upstream bug:
https://issues.jboss.org/browse/JBCS-193
Discussion:
This issue has been addressed in the following products:
Via RHSA-2016:2957 https://rhn.redhat.com/err
Bugzilla
CVE-2016-6808 mod_jk: Buffer overflow when concatenating virtual host name and URI
bugzilla·2016-10-06·CVSS 9.8
CVE-2016-6808 [CRITICAL] CVE-2016-6808 mod_jk: Buffer overflow when concatenating virtual host name and URI
CVE-2016-6808 mod_jk: Buffer overflow when concatenating virtual host name and URI
The IIS/ISAPI specific code implements special handling when a virtual host is present. The virtual host name and the URI are concatenated to create a virtual host mapping rule. It was found that the length checks prior to writing to the target buffer for this rule did not take account of the length of the virtual host name, creating the potential for a buffer overflow.
Upstream patch:
https://svn.apache.org/viewvc?view=revision&revision=1762057
External References:
https://tomcat.apache.org/security-jk.html#Fixed_in_Apache_Tomcat_JK_Connector_1.2.42
Discussion:
This issue has been addressed in the following products:
Via RHSA-2016:2957 https://rhn.redhat.com/errata/RHSA-2016-2957.html
---
This is
Bugzilla
CVE-2016-1834 libxml2: Heap-buffer-overflow in xmlStrncat
bugzilla·2016-05-23·CVSS 7.8
CVE-2016-1834 [HIGH] CVE-2016-1834 libxml2: Heap-buffer-overflow in xmlStrncat
CVE-2016-1834 libxml2: Heap-buffer-overflow in xmlStrncat
A vulnerability was found in the libxml2 library. A heap-buffer-overflow could happen in xmlStrncat.
References:
https://bugzilla.gnome.org/show_bug.cgi?id=763071
Upstream fix:
https://git.gnome.org/browse/libxml2/commit/?id=8fbbf5513d609c1770b391b99e33314cd0742704
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:1292 https://access.redhat.com/errata/RHSA-2016:1292
---
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1349794]
---
Created mingw-libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1349795]
---
This issue has been addressed in the following products:
Via RHSA-2016:2957 https://rhn.r
Bugzilla
CVE-2016-1762 libxml2: Heap-based buffer-overread in xmlNextChar
bugzilla·2016-05-23·CVSS 8.1
CVE-2016-1762 [HIGH] CVE-2016-1762 libxml2: Heap-based buffer-overread in xmlNextChar
CVE-2016-1762 libxml2: Heap-based buffer-overread in xmlNextChar
A vulnerability was found in the libxml2 library. A heap-based buffer overread could happen in xmlNextChar.
References:
https://bugzilla.gnome.org/show_bug.cgi?id=759671
Upstream fix:
https://git.gnome.org/browse/libxml2/commit/?id=a7a94612aa3b16779e2c74e1fa353b5d9786c602
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:1292 https://access.redhat.com/errata/RHSA-2016:1292
---
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1349794]
---
Created mingw-libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1349795]
---
This issue has been addressed in the following products:
Via RHSA-2016:2957
Bugzilla
CVE-2016-4483 libxml2: out-of-bounds read
bugzilla·2016-05-04·CVSS 7.5
CVE-2016-4483 [HIGH] CVE-2016-4483 libxml2: out-of-bounds read
CVE-2016-4483 libxml2: out-of-bounds read
A vulnerability was found in libxml2. Parsing a maliciously crafted xml file could cause the application to crash if recover mode is used.
References:
http://seclists.org/oss-sec/2016/q2/195
Discussion:
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1332823]
---
Created mingw-libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1332824]
Affects: epel-7 [bug 1332825]
---
This issue has been addressed in the following products:
Via RHSA-2016:2957 https://rhn.redhat.com/errata/RHSA-2016-2957.html
---
CVE-2016-4483 is NOT a duplicate of CVE-2016-3627!
This issue has NOT been fixed for at least RHEL6 (CVE-2016-3627 has been).
This issue was fixed upstream with commit c97750d11bb8b6f3303e7131fe526a61ac65
http://www-01.ibm.com/support/docview.wss?uid=swg1LO90039http://www-01.ibm.com/support/docview.wss?uid=swg21990864http://www.securityfocus.com/bid/94300http://www-01.ibm.com/support/docview.wss?uid=swg1LO90039http://www-01.ibm.com/support/docview.wss?uid=swg21990864http://www.securityfocus.com/bid/94300
2016-11-30
Published