Junglewise Threat Intelligence

CVE-2016-10690: openframe-ascii-image insecure HTTP download of executable

CVE-2016-10690 · Severity: low · CVSS 3 · Published 2019-02-18

Vendors: npm.

Executive brief

openframe-ascii-image is a Node.js library that downloads and processes ASCII art images. The library downloads an executable resource over an unencrypted HTTP connection, allowing an attacker positioned on the network path to intercept and replace the executable with malicious code, leading to arbitrary code execution on the host system.

Technical details

The vulnerability is a cleartext download issue (CWE-311: Missing Encryption of Sensitive Data) where openframe-ascii-image retrieves an executable over HTTP instead of HTTPS. An attacker with a privileged network position (man-in-the-middle capability) can intercept the HTTP response and inject a malicious executable, achieving remote code execution on the system running the package. The attack requires no authentication or user interaction and affects all versions up to and including 0.1.0. No patch has been released; the recommended mitigation is to discontinue use of the package or restrict its installation to private networks only.

Affected products

  • openframe openframe-ascii-image <=0.1.0

Timeline

  • 2019-02-18: disclosed