Junglewise Threat Intelligence

CVE-2016-10603: air-sdk insecure HTTP download of executable

CVE-2016-10603 · Severity: info · Published 2019-02-18

Vendors: Adobe, npm.

Executive brief

air-sdk is a JavaScript library that downloads compiler executables needed to build Adobe AIR applications. The library downloads these executables over unencrypted HTTP instead of HTTPS, allowing attackers on the network (such as compromised WiFi or ISP-level actors) to intercept and replace the executable with malicious code, leading to arbitrary code execution during the build process.

Technical details

The vulnerability is a missing encryption issue (CWE-311) where air-sdk downloads essential executables over HTTP rather than HTTPS. An attacker with a privileged network position—such as control of a router, compromised network, or rogue ISP access—can perform a man-in-the-middle attack to intercept the download and substitute a malicious executable. This results in arbitrary code execution on the developer's machine at build time. No patch has been released since the package's last update in 2015, and the maintainers recommend discontinuing use of this package.

Affected products

  • Adobe air-sdk <= 16.0.0-272-9

Timeline

  • 2019-02-18: disclosed
  • 2016: advisory: CVE-2016-10603 assigned