CVE-2016-2057: Debian Linux

Low severity, CVSS 3.3. EPSS: 0.5% chance of exploitation in the next 30 days.

lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to inject arbitrary messages by writing to that queue.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Xymon Xymon: version 4.1.0 only; version 4.1.1 only; version 4.1.2 only; version 4.2 only; version 4.2.0 only; version 4.2.2 only; …

Published 2016-04-13. Last modified 2026-06-17.