CVE-2016-2054

Published on: 04/13/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:15 PM UTC

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Certain versions of Debian Linux from Debian contain the following vulnerability:

Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long filename, involving handling a "config" command.

  • CVE-2016-2054 has been assigned by [email protected] to track the vulnerability - currently rated as - currently rated as CRITICAL severity.

CVSS3 Score: 9.8 - CRITICAL

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH HIGH HIGH

CVSS2 Score: 7.5 - HIGH

Access
Vector
Access
Complexity
Authentication
NETWORK LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
PARTIAL PARTIAL PARTIAL

CVE References

Description Tags Link
Xymon systems and network monitor / Code / Commit [r7860] Patch
sourceforge.net
text/html
URL Logo CONFIRM sourceforge.net/p/xymon/code/7860/
Xymon 4.3.x Buffer Overflow / Code Execution / Information Disclosure ≈ Packet Storm packetstormsecurity.com
text/html
URL Logo MISC packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html
SecurityFocus www.securityfocus.com
text/html
URL Logo BUGTRAQ 20160214 Xymon: Critical security issues in all versions prior to 4.3.25
[Xymon] Xymon 4.3.25 - Important Security Update Vendor Advisory
lists.xymon.com
text/html
URL Logo MLIST [Xymon] 20160208 Xymon 4.3.25 - Important Security Update
Debian -- Security Information -- DSA-3495-1 xymon www.debian.org
Depreciated Link
text/html
URL Logo DEBIAN DSA-3495
Xymon systems and network monitor / Code / Commit [r7859] Patch
sourceforge.net
text/html
URL Logo CONFIRM sourceforge.net/p/xymon/code/7859/

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Operating
System
DebianDebian Linux8.0AllAllAll
Operating
System
DebianDebian Linux8.0AllAllAll
ApplicationXymonXymon4.1.0AllAllAll
ApplicationXymonXymon4.1.1AllAllAll
ApplicationXymonXymon4.1.2AllAllAll
ApplicationXymonXymon4.1.2p1AllAll
ApplicationXymonXymon4.1.2p2AllAll
ApplicationXymonXymon4.2alfaAllAll
ApplicationXymonXymon4.2beta20060605AllAll
ApplicationXymonXymon4.2rc20060712AllAll
ApplicationXymonXymon4.2.0AllAllAll
ApplicationXymonXymon4.2.2AllAllAll
ApplicationXymonXymon4.2.2rc1AllAll
ApplicationXymonXymon4.2.3AllAllAll
ApplicationXymonXymon4.2.3rc1AllAll
ApplicationXymonXymon4.3.0AllAllAll
ApplicationXymonXymon4.3.0beta1AllAll
ApplicationXymonXymon4.3.0beta2AllAll
ApplicationXymonXymon4.3.0beta3AllAll
ApplicationXymonXymon4.3.0rc1AllAll
ApplicationXymonXymon4.3.1AllAllAll
ApplicationXymonXymon4.3.10AllAllAll
ApplicationXymonXymon4.3.11AllAllAll
ApplicationXymonXymon4.3.12AllAllAll
ApplicationXymonXymon4.3.13AllAllAll
ApplicationXymonXymon4.3.14AllAllAll
ApplicationXymonXymon4.3.15AllAllAll
ApplicationXymonXymon4.3.16AllAllAll
ApplicationXymonXymon4.3.17AllAllAll
ApplicationXymonXymon4.3.18AllAllAll
ApplicationXymonXymon4.3.19AllAllAll
ApplicationXymonXymon4.3.19rc1AllAll
ApplicationXymonXymon4.3.2AllAllAll
ApplicationXymonXymon4.3.20AllAllAll
ApplicationXymonXymon4.3.21AllAllAll
ApplicationXymonXymon4.3.22AllAllAll
ApplicationXymonXymon4.3.23AllAllAll
ApplicationXymonXymon4.3.24AllAllAll
ApplicationXymonXymon4.3.3AllAllAll
ApplicationXymonXymon4.3.4AllAllAll
ApplicationXymonXymon4.3.5AllAllAll
ApplicationXymonXymon4.3.6AllAllAll
ApplicationXymonXymon4.3.7AllAllAll
ApplicationXymonXymon4.3.8AllAllAll
ApplicationXymonXymon4.3.9AllAllAll
ApplicationXymonXymon4.1.0AllAllAll
ApplicationXymonXymon4.1.1AllAllAll
ApplicationXymonXymon4.1.2AllAllAll
ApplicationXymonXymon4.1.2p1AllAll
ApplicationXymonXymon4.1.2p2AllAll
ApplicationXymonXymon4.2alfaAllAll
ApplicationXymonXymon4.2beta20060605AllAll
ApplicationXymonXymon4.2rc20060712AllAll
ApplicationXymonXymon4.2.0AllAllAll
ApplicationXymonXymon4.2.2AllAllAll
ApplicationXymonXymon4.2.2rc1AllAll
ApplicationXymonXymon4.2.3AllAllAll
ApplicationXymonXymon4.2.3rc1AllAll
ApplicationXymonXymon4.3.0AllAllAll
ApplicationXymonXymon4.3.0beta1AllAll
ApplicationXymonXymon4.3.0beta2AllAll
ApplicationXymonXymon4.3.0beta3AllAll
ApplicationXymonXymon4.3.0rc1AllAll
ApplicationXymonXymon4.3.1AllAllAll
ApplicationXymonXymon4.3.10AllAllAll
ApplicationXymonXymon4.3.11AllAllAll
ApplicationXymonXymon4.3.12AllAllAll
ApplicationXymonXymon4.3.13AllAllAll
ApplicationXymonXymon4.3.14AllAllAll
ApplicationXymonXymon4.3.15AllAllAll
ApplicationXymonXymon4.3.16AllAllAll
ApplicationXymonXymon4.3.17AllAllAll
ApplicationXymonXymon4.3.18AllAllAll
ApplicationXymonXymon4.3.19AllAllAll
ApplicationXymonXymon4.3.19rc1AllAll
ApplicationXymonXymon4.3.2AllAllAll
ApplicationXymonXymon4.3.20AllAllAll
ApplicationXymonXymon4.3.21AllAllAll
ApplicationXymonXymon4.3.22AllAllAll
ApplicationXymonXymon4.3.23AllAllAll
ApplicationXymonXymon4.3.24AllAllAll
ApplicationXymonXymon4.3.3AllAllAll
ApplicationXymonXymon4.3.4AllAllAll
ApplicationXymonXymon4.3.5AllAllAll
ApplicationXymonXymon4.3.6AllAllAll
ApplicationXymonXymon4.3.7AllAllAll
ApplicationXymonXymon4.3.8AllAllAll
ApplicationXymonXymon4.3.9AllAllAll
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.1.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.1.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.1.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.1.2:p1:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.1.2:p2:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2:alfa:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2:beta20060605:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2:rc20060712:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2.2:rc1:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2.3:rc1:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.0:beta1:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.0:beta2:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.0:beta3:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.0:rc1:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.12:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.13:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.14:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.15:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.16:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.17:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.18:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.19:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.19:rc1:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.20:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.21:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.22:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.23:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.24:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.1.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.1.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.1.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.1.2:p1:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.1.2:p2:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2:alfa:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2:beta20060605:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2:rc20060712:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2.2:rc1:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.2.3:rc1:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.0:beta1:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.0:beta2:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.0:beta3:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.0:rc1:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.12:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.13:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.14:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.15:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.16:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.17:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.18:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.19:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.19:rc1:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.20:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.21:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.22:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.23:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.24:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:xymon:xymon:4.3.9:*:*:*:*:*:*:*: