Name | CVE-2016-2141 |
Description | It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 867493 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
libjgroups-java (PTS) | jessie, stretch | 2.12.2.Final-4 | vulnerable |
| sid, trixie, buster, bullseye, bookworm | 2.12.2.Final-5 | vulnerable |
The information below is based on the following data on fixed versions.
Notes
[bookworm] - libjgroups-java <ignored> (Minor issue, only used as build dep)
[bullseye] - libjgroups-java <ignored> (Minor issue, only used as build dep)
[buster] - libjgroups-java <ignored> (Minor issue, only used as build dep)
[stretch] - libjgroups-java <ignored> (Minor issue, only used as build dep)
[jessie] - libjgroups-java <no-dsa> (Minor issue)
[wheezy] - libjgroups-java <no-dsa> (Minor issue, only used as build dependency)