Buffer overflow in Tenable Nessus in Apple Inc. products - CVE-2016-0718
Published: July 22, 2016 / Updated: January 13, 2017
Vulnerability identifier: #VU200
CSH Severity: Critical
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0718
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error when handling malformed input documents. A remote unauthenticated attacker can trigger a buffer overflow in the Expat XML parser library and execute arbitrary code by sending specially crafted data to vulnerable server.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
The vulnerability exists due to boundary error when handling malformed input documents. A remote unauthenticated attacker can trigger a buffer overflow in the Expat XML parser library and execute arbitrary code by sending specially crafted data to vulnerable server.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Oracle VM Server for x86
Tenable Nessus
Oracle Linux
Oracle Solaris
macOS
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Ubuntu
Slackware Linux
Fedora
Opensuse
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
expat (Alpine package)
libxmltok1t64 (Ubuntu package)
libxmltok1 (Ubuntu package)
expat
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
NetWorker Management Console
Tenable Nessus
Oracle Linux
Oracle Solaris
macOS
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Ubuntu
Slackware Linux
Fedora
Opensuse
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
expat (Alpine package)
libxmltok1t64 (Ubuntu package)
libxmltok1 (Ubuntu package)
expat
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
NetWorker Management Console
How to mitigate CVE-2016-0718
Install the latest version (6.8).
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
expat (Alpine package) - update to 2.1.0-r1
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libxmltok1t64 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2-4.1ubuntu3.1
libxmltok1 (Ubuntu package) - update to Ubuntu Pro
expat - addressed in versions 2.1.1-2.fc22, 2.1.1-2.fc23, 2.1.1-2.fc24
NetWorker Management Console - update to 19.12.0.1
expat (Alpine package) - update to 2.1.0-r1
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libxmltok1t64 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2-4.1ubuntu3.1
libxmltok1 (Ubuntu package) - update to Ubuntu Pro
expat - addressed in versions 2.1.1-2.fc22, 2.1.1-2.fc23, 2.1.1-2.fc24
NetWorker Management Console - update to 19.12.0.1
External References
- http://www.tenable.com/security/tns-2016-11
- http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html
- https://support.apple.com/cs-cz/HT206903
Related Security Bulletins
- Ubuntu update for Expat
- Amazon Linux AMI update for expat
- Slackware Linux update for python
- Red Hat update for expat
- OpenSUSE Linux update for expat
- SUSE Linux update for expat
- SUSE Linux update for expat
- Buffer overflow in Tenable Nessus in expat (Alpine package)
- Gentoo update for Expat
- Slackware Linux update for python
- Multiple vulnerabilities in Dell ThinOS
- Ubuntu update for libxmltok
- Fedora 24 update for expat
- Fedora 23 update for expat
- Fedora 22 update for expat
- Dell NetWorker Management Console update for third-party components