CVE-2016-2141

NameCVE-2016-2141
DescriptionJGroups before 4.0 does not require the proper headers for the ENCRYPT and AUTH protocols from nodes joining the cluster, which allows remote attackers to bypass security restrictions and send and receive messages within the cluster via unspecified vectors.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh (attack range: remote)
Debian Bugs867493

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libjgroups-java (PTS)wheezy2.12.2.Final-2vulnerable
buster, sid, jessie, stretch2.12.2.Final-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libjgroups-javasource(unstable)(unfixed)low867493

Notes

[stretch] - libjgroups-java <no-dsa> (Minor issue)
[jessie] - libjgroups-java <no-dsa> (Minor issue)
[wheezy] - libjgroups-java <no-dsa> (Minor issue, only used as build dependency)

Search for package or bug name: Reporting problems