Vulnerabilities > CVE-2016-6271 - 7PK - Security Features vulnerability in Bzrtp Project Bzrtp 1.0.0/1.0.2/1.0.3

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
bzrtp-project
CWE-254
nessus

Summary

The Bzrtp library (aka libbzrtp) 1.0.x before 1.0.4 allows man-in-the-middle attackers to conduct spoofing attacks by leveraging a missing HVI check on DHPart2 packet reception.

Vulnerable Configurations

Part Description Count
Application
Bzrtp_Project
3

Common Weakness Enumeration (CWE)

Nessus

NASL familySuSE Local Security Checks
NASL idOPENSUSE-2017-193.NASL
descriptionThis update for bzrtp fixes one security issue. The following vulnerability was fixed : - CVE-2016-6271: missing HVI check on DHPart2 packet reception may have allowed man-in-the-middle attackers to conduct spoofing attacks boo#1020844)
last seen2020-06-05
modified2017-02-02
plugin id96944
published2017-02-02
reporterThis script is Copyright (C) 2017-2020 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/96944
titleopenSUSE Security Update : bzrtp (openSUSE-2017-193)