First published: Fri Jun 01 2018(Updated: )
webrtc-native uses WebRTC from chromium project. webrtc-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Webrtc Webrtc-native | <=1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2016-10600.
The severity of CVE-2016-10600 is critical with a score of 8.1.
Webrtc Webrtc-native version up to 1.4.0 on Node.js is affected by CVE-2016-10600.
CVE-2016-10600 leaves the system vulnerable to MITM attacks by downloading binary resources over HTTP.
CVE-2016-10600 may allow remote code execution (RCE) if an attacker swaps out the requested binary with a malicious one.