Bug 1584893 (CVE-2016-10659) - CVE-2016-10659 poco: MITM due to resources download over HTTP
Summary: CVE-2016-10659 poco: MITM due to resources download over HTTP
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2016-10659
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1584894 1584895
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-05-31 21:27 UTC by Laura Pardo
Modified: 2019-09-29 14:40 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-01-29 01:22:34 UTC
Embargoed:


Attachments (Terms of Use)

Description Laura Pardo 2018-05-31 21:27:58 UTC
A flaw was found in the POCO libraries, downloads source file resources used for compliation over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.


References:
https://nodesecurity.io/advisories/271

Comment 1 Laura Pardo 2018-05-31 21:28:20 UTC
Created poco tracking bugs for this issue:

Affects: epel-all [bug 1584894]
Affects: fedora-all [bug 1584895]

Comment 2 Scott Talbert 2018-06-11 00:53:43 UTC
I believe this can be closed out as the CVE doesn't apply to the Fedora/EPEL packages, but to a Node package of poco.

Comment 3 Scott Talbert 2019-01-29 01:22:34 UTC
Closing as this does not apply to the Fedora/EPEL packages.


Note You need to log in before you can comment on or make changes to this bug.