Junglewise Threat Intelligence

CVE-2016-10573: baryton-saxophone insecure HTTP resource download

CVE-2016-10573 · Severity: info · Published 2019-02-18

Vendors: npm.

Executive brief

baryton-saxophone is a Node.js library that downloads executable resources over unencrypted HTTP connections. An attacker positioned on the network can intercept and replace the downloaded executable with malicious code, achieving remote code execution on systems using the library.

Technical details

The vulnerability stems from insecure HTTP downloads (CWE-311) of executables without encryption or integrity verification. An attacker with network access (man-in-the-middle position) can intercept the HTTP response and serve a malicious executable instead. This requires no authentication or user interaction beyond the application's normal operation. The attack results in arbitrary code execution with the privileges of the process running baryton-saxophone. The fix was released in version 3.0.1 and later, which presumably switched to HTTPS or added integrity verification.

Affected products

  • baryton-saxophone baryton-saxophone < 3.0.1

Timeline

  • 2019-02-18: disclosed: Published to GitHub Advisory Database
  • 2019-02-18: patched: Version 3.0.1 released with fix