ALT-BU-2016-2617-1
Branch t6 update bulletin.
Closed vulnerabilities
BDU:2016-01052
Уязвимость программного средства мониторинга сети Xymon, позволяющая нарушителю вводить произвольные сообщения
BDU:2016-01053
Уязвимость программного средства мониторинга сети Xymon, позволяющая нарушителю выполнить произвольные команды
BDU:2016-01054
Уязвимость операционной системы Debian GNU/Linux, позволяющая нарушителю читать произвольные файлы в каталоге конфигурации
BDU:2016-01055
Уязвимости программного средства мониторинга сети Xymon, позволяющие нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2024-11-21
CVE-2016-2054
Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long filename, involving handling a "config" command.
- [Xymon] 20160208 Xymon 4.3.25 - Important Security Update
- [Xymon] 20160208 Xymon 4.3.25 - Important Security Update
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- DSA-3495
- DSA-3495
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- https://sourceforge.net/p/xymon/code/7859/
- https://sourceforge.net/p/xymon/code/7859/
- https://sourceforge.net/p/xymon/code/7860/
- https://sourceforge.net/p/xymon/code/7860/
Modified: 2024-11-21
CVE-2016-2055
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration directory via a "config" command.
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- DSA-3495
- DSA-3495
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- https://sourceforge.net/p/xymon/code/7890/
- https://sourceforge.net/p/xymon/code/7890/
Modified: 2024-11-21
CVE-2016-2056
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) web/useradm.c or (2) web/chpasswd.c.
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- http://packetstormsecurity.com/files/153620/Xymon-useradm-Command-Execution.html
- http://packetstormsecurity.com/files/153620/Xymon-useradm-Command-Execution.html
- DSA-3495
- DSA-3495
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- https://sourceforge.net/p/xymon/code/7892/
- https://sourceforge.net/p/xymon/code/7892/
Modified: 2024-11-21
CVE-2016-2057
lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to inject arbitrary messages by writing to that queue.
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- DSA-3495
- DSA-3495
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- https://sourceforge.net/p/xymon/code/7891/
- https://sourceforge.net/p/xymon/code/7891/
Modified: 2024-11-21
CVE-2016-2058
Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject arbitrary web script or HTML via a status-message, which is not properly handled in the "detailed status" page, or (2) remote authenticated users to inject arbitrary web script or HTML via an acknowledgement message, which is not properly handled in the "status" page.
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
- DSA-3495
- DSA-3495
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
- https://sourceforge.net/p/xymon/code/7892/
- https://sourceforge.net/p/xymon/code/7892/