CVE-2016-2141

NameCVE-2016-2141
DescriptionIt was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs867493

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libjgroups-java (PTS)jessie, stretch2.12.2.Final-4vulnerable
sid, trixie, buster, bullseye, bookworm2.12.2.Final-5vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libjgroups-javasource(unstable)(unfixed)low867493

Notes

[bookworm] - libjgroups-java <ignored> (Minor issue, only used as build dep)
[bullseye] - libjgroups-java <ignored> (Minor issue, only used as build dep)
[buster] - libjgroups-java <ignored> (Minor issue, only used as build dep)
[stretch] - libjgroups-java <ignored> (Minor issue, only used as build dep)
[jessie] - libjgroups-java <no-dsa> (Minor issue)
[wheezy] - libjgroups-java <no-dsa> (Minor issue, only used as build dependency)

Search for package or bug name: Reporting problems