Severity: high

Downloads Resources over HTTP

libxl

Overview

Affected versions of libxl insecurely download an executable over an unencrypted HTTP connection.

In scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running libxl.

Remediation

The module author recommends installing the bindings using a pinned and verified version of SDK instead of the automated download. More information is available in the modules README.

Advisory timeline

  1. published

    Advisory published
    Dec 18th, 2016
  2. reported

    Nov 30th, 2016