Vulnerability Name:

CVE-2016-10375 (CCN-126660)

Assigned:2016-02-04
Published:2016-02-04
Updated:2020-04-30
Summary:Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2016-10375

Source: XF
Type: UNKNOWN
yodl-cve201610375-bo(126660)

Source: CONFIRM
Type: Patch, Third Party Advisory
https://github.com/fbb-git/yodl/commit/fd85f8c94182558ff1480d06a236d6fb927979a3

Source: CCN
Type: Yodl GIT Repository
nvalid memory read in queuepush.c / function queue_push() #1

Source: CONFIRM
Type: Patch, Third Party Advisory
https://github.com/fbb-git/yodl/issues/1

Source: MLIST
Type: UNKNOWN
[debian-lts-announce] 20200430 [SECURITY] [DLA 2194-1] yodl security update

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2016-10375

Vulnerable Configuration:Configuration 1:
  • cpe:/a:yodl_project:yodl:*:*:*:*:*:*:*:* (Version <= 3.06.00)

  • Configuration CCN 1:
  • cpe:/a:yodl_project:yodl:3.06.00:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201610375
    V
    CVE-2016-10375
    2022-09-02
    oval:org.opensuse.security:def:9886
    P
    Security update for MozillaFirefox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:9894
    P
    Security update for libvirt (Important)
    2022-01-11
    oval:org.opensuse.security:def:10436
    P
    Security update for libsndfile (Important)
    2022-01-11
    oval:org.opensuse.security:def:10194
    P
    Security update for xorg-x11-server (Important)
    2021-12-20
    oval:org.opensuse.security:def:11160
    P
    Security update for nextcloud (Important)
    2021-12-20
    oval:org.opensuse.security:def:10187
    P
    Security update for MozillaFirefox (Important)
    2021-12-10
    oval:org.opensuse.security:def:10185
    P
    Security update for clamav (Moderate)
    2021-12-06
    oval:org.opensuse.security:def:10179
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:11138
    P
    Security update for mupdf (Important)
    2021-10-11
    oval:org.opensuse.security:def:10336
    P
    Security update for ffmpeg (Important)
    2021-09-02
    oval:org.opensuse.security:def:10143
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:10317
    P
    Security update for libsndfile (Critical)
    2021-08-17
    oval:org.opensuse.security:def:10118
    P
    Security update for nodejs10 (Important)
    2021-07-15
    oval:org.opensuse.security:def:10302
    P
    Security update for dbus-1 (Important)
    2021-07-12
    oval:org.opensuse.security:def:17193
    P
    libosip2-3.5.0-20.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11476
    P
    wireshark-1.10.9-1.11 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:17278
    P
    libsilc-1_1-2-1.1.10-24.128 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:124680
    P
    yodl-3.03.0-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16380
    P
    yodl-3.03.0-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:17151
    P
    typelib-1_0-Gtk-2_0-2.24.31-7.11 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:17159
    P
    dia-0.97.3-15.63 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16674
    P
    yodl-3.03.0-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11454
    P
    rsync-3.1.0-2.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:10411
    P
    Security update for openldap2 (Important)
    2021-03-08
    oval:org.opensuse.security:def:10207
    P
    Security update for salt (Critical)
    2021-02-26
    oval:org.opensuse.security:def:10209
    P
    Security update for python-Jinja2 (Important)
    2021-02-26
    oval:org.opensuse.security:def:10652
    P
    Security update for MozillaThunderbird (Important)
    2021-02-01
    oval:org.opensuse.security:def:10255
    P
    Security update for ImageMagick (Moderate)
    2021-01-18
    oval:org.opensuse.security:def:10633
    P
    Security update for MozillaThunderbird (Critical)
    2020-12-25
    oval:org.opensuse.security:def:16990
    P
    yodl-3.03.0-3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:17335
    P
    libIlmImf-Imf_2_1-21-32bit-2.1.0-6.13.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:17366
    P
    libserf-1-1-1.3.7-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:10024
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-02
    oval:org.opensuse.security:def:17613
    P
    Security update for subversion (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17635
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9916
    P
    libsndfile1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18273
    P
    Security update for libosip2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9962
    P
    perl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10478
    P
    libXv-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10727
    P
    libcurl-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18299
    P
    Security update for yodl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10009
    P
    vino on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10845
    P
    rrdtool-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10487
    P
    libbz2-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10495
    P
    libfbembed-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10752
    P
    libjson-c-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17402
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:10867
    P
    yodl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10500
    P
    libgpgme-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10503
    P
    libgypsy-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10794
    P
    libssh-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17512
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10043
    P
    cifs-utils-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10525
    P
    libopenssl-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10803
    P
    libtool on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17544
    P
    Security update for libjpeg-turbo, libjpeg62-turbo (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10571
    P
    mozilla-nspr-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10816
    P
    libzip-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17601
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10618
    P
    LibVNCServer-devel on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:2016103750000000
    V
    CVE-2016-10375 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-05-26
    oval:com.ubuntu.artful:def:201610375000
    V
    CVE-2016-10375 on Ubuntu 17.10 (artful) - medium.
    2017-05-26
    oval:com.ubuntu.xenial:def:201610375000
    V
    CVE-2016-10375 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-05-26
    oval:com.ubuntu.xenial:def:2016103750000000
    V
    CVE-2016-10375 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-05-26
    oval:com.ubuntu.bionic:def:201610375000
    V
    CVE-2016-10375 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-05-26
    oval:com.ubuntu.disco:def:2016103750000000
    V
    CVE-2016-10375 on Ubuntu 19.04 (disco) - medium.
    2017-05-26
    oval:com.ubuntu.cosmic:def:201610375000
    V
    CVE-2016-10375 on Ubuntu 18.10 (cosmic) - medium.
    2017-05-26
    oval:com.ubuntu.cosmic:def:2016103750000000
    V
    CVE-2016-10375 on Ubuntu 18.10 (cosmic) - medium.
    2017-05-26
    oval:com.ubuntu.trusty:def:201610375000
    V
    CVE-2016-10375 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-05-26
    BACK
    yodl_project yodl *
    yodl_project yodl 3.06.00