Insecure library loading in Snort - CVE-2016-1417

 

Insecure library loading in Snort - CVE-2016-1417

Published: October 4, 2016 / Updated: October 5, 2016


Vulnerability identifier: #VU738
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1417
CWE-ID: CWE-427
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to absence of validation of search path when loading DLL files. A remote attacker can place malicious 'tcapi.dll' DLL file on the SBM or WebDav share and trick the victim to load a pcap file from that location.

Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.


Affected software

Snort
SUSE Linux Enterprise High Availability Extension 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
openSUSE Leap
crmsh-scripts
crmsh-test
crmsh

How to mitigate CVE-2016-1417

Cybersecurity Help is not aware of any official solution to address this vulnerability.

crmsh-scripts - update to 4.5.1+20240531.f62a43e-150500.3.28.2
crmsh-test - update to 4.5.1+20240531.f62a43e-150500.3.28.2
crmsh - update to 4.5.1+20240531.f62a43e-150500.3.28.2

External References

Related Security Bulletins