VARIoT IoT vulnerabilities database
| VAR-200911-0275 | CVE-2009-2827 | Apple Mac OS X of Disk Image Vulnerable to buffer overflow |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Heap-based buffer overflow in Disk Images in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FAT filesystem on a disk image.
Successfully exploiting this issue may allow attackers to execute arbitrary code with superuser privileges, completely compromising affected computers. Failed exploit attempts will likely result in a denial-of-service condition.
This issue affects the following:
Mac OS X 10.5.8 and prior
Mac OS X Server 10.5.8 and prior
NOTE: This issue was previously covered in BID 36956 (Apple Mac OS X 2009-006 Multiple Security
Vulnerabilities), but has been assigned its own record to better document it. A heap overflow exists when handling disk images containing FAT filesystems
| VAR-200911-0274 | CVE-2009-2826 | Apple Mac OS X of CoreGraphics Integer overflow vulnerability |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Multiple integer overflows in CoreGraphics in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers a heap-based buffer overflow. Apple Mac OS X is prone to multiple memory-corruption vulnerabilities that affect the CoreGraphics component.
Successfully exploiting these issues may allow attackers to execute arbitrary code within the context of the application. Failed exploit attempts will likely result in a denial-of-service condition.
These issues affect the following:
Mac OS X v10.5.8 and prior
Mac OS X Server v10.5.8 and prior
NOTE: These issues were previously covered in BID 36956 (Apple Mac OS X 2009-006 Multiple Security Vulnerabilities), but have been assigned their own record to better document them. There are multiple integer overflows that can lead to heap overflow in CoreGraphics processing PDF files
| VAR-200911-0273 | CVE-2009-2825 | Apple Mac OS X of Certificate Assistant In X.509 Any certificate processing SSL Vulnerability impersonating a server |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
Certificate Assistant in Apple Mac OS X before 10.6.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. This vulnerability CVE-2009-2408 And is related.A crafted certificate allows any man-in-the-middle attacker to SSL There is a possibility of impersonating a server. Apple Mac OS X is prone to multiple security vulnerabilities that have been addressed in Security Update 2009-006.
This BID is being retired; the following individual records now document these issues:
36988 Apple Mac OS X QuickLook Remote Code Execution Vulnerability
36987 Apple Mac OS X Launch Services Remote Security Bypass Vulnerability
36985 Apple Mac OS X QuickDraw Manager Remote Code Execution Vulnerability
36984 Apple Mac OS X Login Window Race Condition Vulnerability
36983 Apple Mac OS X Kernel Multiple Vulnerabilities
36982 Apple Mac OS X International Components for Unicode Buffer Overflow Vulnerability
36978 Apple Mac OS X Dictionary Arbitrary Script Injection Vulnerability
36979 Apple Mac OS X IOKit Keyboard Firmware Local Unauthorized Access Vulnerability
36977 Apple Mac OS X Help Viewer Spoofed HTTP Response Remote Code Execution Vulnerability
36975 Apple Mac OS X FTP Server CWD Command Buffer Overflow Vulnerability
36973 Apple Mac OS X Disk Images FAT Filesystem Heap Buffer Overflow Vulnerability
36974 Apple Mac OS X CDF File Multiple Buffer Overflow Vulnerabilities
36972 Apple Mac OS X DirectoryService Memory Corruption Vulnerability
36961 Apple Mac OS X AFP Client Multiple Remote Code Execution Vulnerabilities
36966 Apple Mac OS X Event Monitor Log Parsing Denial of Service Vulnerability
36967 Apple Mac OS X Spotlight Insecure Temporary File Handling Vulnerability
36964 Apple Mac OS X Screen Sharing Client Multiple Remote Code Execution Vulnerabilities
36963 Apple Mac OS X Adaptive Firewall Security Bypass Vulnerability
36962 Apple Mac OS X CoreGraphics Multiple Heap-Overflow Vulnerabilities
36959 Apple Mac OS X Apple Type Services Multiple Memory Corruption Vulnerabilities
36990 Apple Mac OS X Apache HTTP TRACE Cross Site Scripting Vulnerability. There was a bug in the handling of SSL certificates that contained null characters in the CN field, and users could be misled into accepting a specially crafted certificate that looked like it matched the domain the user was visiting
| VAR-200911-0272 | CVE-2009-2824 | Apple Mac OS X of Apple Type Services (ATS) Vulnerable to buffer overflow |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code via a crafted embedded font in a document.
Successfully exploiting these issues may allow attackers to execute arbitrary code within the context of the application. Failed exploit attempts will likely result in a denial-of-service condition.
These issues affect the following:
Mac OS X v10.5.8 and prior
Mac OS X Server v10.5.8 and prior
NOTE: These issues were previously covered in BID 36956 (Apple Mac OS X 2009-006 Multiple Security Vulnerabilities), but have been assigned their own record to better document them
| VAR-200911-0269 | CVE-2009-2840 | Apple Mac OS X of Spotlight Vulnerable to overwriting arbitrary files |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
Spotlight in Apple Mac OS X 10.5.8 does not properly handle temporary files, which allows local users to overwrite arbitrary files in the context of a different user's privileges via unspecified vectors.
NOTE: This issue was previously covered in BID 36956 (Apple Mac OS X 2009-006 Multiple Security Vulnerabilities), but has been assigned its own record to better document it
| VAR-200911-0268 | CVE-2009-2839 | Apple Mac OS X Vulnerability in arbitrary code execution in screen sharing |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Screen Sharing in Apple Mac OS X 10.5.8 allows remote VNC servers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
An attacker can exploit these issues to execute arbitrary code in the context of the vulnerable process. Failed exploit attempts are likely to result in denial-of-service conditions.
NOTE: These issues were previously covered in BID 36956 (Apple Mac OS X 2009-006 Multiple Security
Vulnerabilities), but have been assigned their own record to better document them
| VAR-200911-0267 | CVE-2009-2838 | Apple Mac OS X Integer Overflow Vulnerability in Quick Look |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Integer overflow in QuickLook in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document that triggers a buffer overflow. Apple Mac OS X is prone to a remote code-execution vulnerability that affects QuickLook.
Successfully exploiting this issue may allow attackers to execute arbitrary code and compromise the affected computer. Failed exploit attempts will likely result in a denial-of-service condition.
NOTE: This issue was previously covered in BID 36956 (Apple Mac OS X 2009-006 Multiple Security
Vulnerabilities), but has been assigned its own record to better document it. An integer overflow exists in QuickLook's handling of Microsoft Office files. Downloading a malicious Microsoft Office file may cause the application to terminate unexpectedly or execute arbitrary code
| VAR-200911-0265 | CVE-2009-2836 | Apple Mac OS X Login window vulnerabilities to log in with arbitrary accounts |
CVSS V2: 6.2 CVSS V3: - Severity: MEDIUM |
Race condition in Login Window in Apple Mac OS X 10.6.x before 10.6.2, when at least one account has a blank password, allows attackers to bypass password authentication and obtain login access to an arbitrary account via unspecified vectors. Apple Mac OS X is prone to a race-condition vulnerability in Login Window.
Under certain circumstances, a local attacker can exploit this issue to access the system with elevated privileges.
This issue affects the following:
Mac OS X 10.6 and 10.6.1
Mac OS X Server 10.6 and 10.6.1
NOTE: This issue was previously covered in BID 36956 (Apple Mac OS X 2009-006 Multiple Security Vulnerabilities), but has been assigned its own record to better document it
| VAR-200911-0264 | CVE-2009-2835 | Apple Mac OS X of Kernel Vulnerability gained in |
CVSS V2: 4.6 CVSS V3: - Severity: MEDIUM |
The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allows local users to gain privileges, cause a denial of service (system crash), or obtain sensitive information via unspecified vectors. Apple Mac OS X kernel is prone to multiple vulnerabilities.
Successfully exploiting these issues may allow local attackers to execute arbitrary code with kernel-level privileges, to completely compromise affected computers, to obtain sensitive information, and to trigger denial-of-service conditions.
NOTE: These issues were previously covered in BID 36956 (Apple Mac OS X 2009-006 Multiple Security Vulnerabilities), but have been assigned their own record to better document them
| VAR-200911-0263 | CVE-2009-2810 | Apple Mac OS X of Launch Services Vulnerable to arbitrary code execution |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Launch Services in Apple Mac OS X 10.6.x before 10.6.2 recursively clears quarantine information upon opening a quarantined folder, which allows user-assisted remote attackers to execute arbitrary code via a quarantined application that does not trigger a "potentially unsafe" warning message. Apple Mac OS X is prone to a remote security-bypass vulnerability that affects the Launch Services API.
An attacker can exploit this issue by enticing a user to download a malicious file and launch it without being warned. Successful exploits may bypass the security feature that displays a warning dialog box before executing malicious files from the quarantined directory.
This issue affects the following:
Mac OS X 10.6 and 10.6.1
Mac OS X Server 10.6 and 10.6.1
NOTE: This issue was previously covered in BID 36956 (Apple Mac OS X 2009-006 Multiple Security Vulnerabilities), but has been assigned its own record to better document it. This may allow unsafe items such as applications to be launched without a warning dialog
| VAR-200911-0262 | CVE-2009-2808 | Apple Mac OS X Help Viewer vulnerable to arbitrary code execution |
CVSS V2: 5.4 CVSS V3: - Severity: MEDIUM |
Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help content from a web site, which allows man-in-the-middle attackers to send a crafted help:runscript link, and thereby execute arbitrary code, via a spoofed response. Apple Mac OS X is prone to a remote code-execution vulnerability.
Successful exploits may allow attackers with access to the local area network access to execute arbitrary code within the context of the application.
NOTE: This issue was previously covered in BID 36956 (Apple Mac OS X 2009-006 Multiple Security
Vulnerabilities), but has been assigned its own record to better document it
| VAR-200911-0266 | CVE-2009-2837 | Apple Mac OS X of QuickDraw Manager Vulnerable to buffer overflow |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Heap-based buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image. Apple Mac OS X is prone to a remote code-execution vulnerability that affects the QuickDraw Manager.
Successfully exploiting this issue may allow attackers to execute arbitrary code and compromise the affected computer. Failed exploit attempts will likely result in a denial-of-service condition.
NOTE: This issue was previously covered in BID 36956 (Apple Mac OS X 2009-006 Multiple Security
Vulnerabilities), but has been assigned its own record to better document it. VUPEN Security Research - Apple Quicktime PICT Handling Heap Overflow
Vulnerability
http://www.vupen.com/english/research.php
I. BACKGROUND
---------------------
"Apple QuickTime is software that allows Mac and Windows users to play
back audio and video on their computers. But taking a deeper look,
QuickTime is many things: a file format, an environment for media
authoring and a suite of applications" from Apple.com
II. DESCRIPTION
---------------------
VUPEN Vulnerability Research Team discovered a vulnerability in
Apple Quicktime.
III. AFFECTED PRODUCTS
--------------------------------
Apple QuickTime versions prior to 7.6.6
IV. Exploits - PoCs & Binary Analysis
----------------------------------------
In-depth binary analysis of the vulnerability and an exploit code
have been released by VUPEN through the VUPEN Binary Analysis
& Exploits Service :
http://www.vupen.com/exploits
V. SOLUTION
----------------
Upgrade to Apple QuickTime version 7.6.6 :
http://www.apple.com/quicktime/download/
VI. CREDIT
--------------
The vulnerability was discovered by Nicolas Joly of VUPEN Security
VII. ABOUT VUPEN Security
---------------------------------
VUPEN is a leading IT security research company providing vulnerability
management and security intelligence solutions which enable enterprises
and institutions to eliminate vulnerabilities before they can be exploited,
ensure security policy compliance and meaningfully measure and manage risks.
Governmental and federal agencies, and global enterprises in the financial
services, insurance, manufacturing and technology industries rely on VUPEN
to improve their security, prioritize resources, cut time and costs, and
stay ahead of the latest threats.
* VUPEN Vulnerability Notification Service:
http://www.vupen.com/english/services
* VUPEN Binary Analysis & Exploits Service :
http://www.vupen.com/exploits
VIII. REFERENCES
----------------------
http://www.vupen.com/english/advisories/2010/0746
http://support.apple.com/kb/HT4104
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2837
IX. DISCLOSURE TIMELINE
-----------------------------------
2009-05-28 - Vendor notified
2009-05-28 - Vendor response
2009-07-18 - Status update received
2009-10-30 - Status update received
2010-01-07 - Status update received
2010-03-11 - Status update received
2010-03-31 - Coordinated public Disclosure
| VAR-200911-0180 | CVE-2009-4006 | RhinoSoft Serv-U FTP Server TEA Decoding algorithm stack-based buffer overflow vulnerability |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string. RhinoSoft Serv-U FTP Server is prone to a remote stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Serv-U 9.0.0.5 is vulnerable; other versions may also be affected. ----------------------------------------------------------------------
Do you have VARM strategy implemented?
(Vulnerability Assessment Remediation Management)
If not, then implement it through the most reliable vulnerability
intelligence source on the market.
Implement it through Secunia.
For more information visit:
http://secunia.com/advisories/business_solutions/
Alternatively request a call from a Secunia representative today to
discuss how we can help you with our capabilities contact us at:
sales@secunia.com
----------------------------------------------------------------------
TITLE:
RhinoSoft Serv-U Cookie Buffer Overflow Vulnerability
SECUNIA ADVISORY ID:
SA37228
VERIFY ADVISORY:
http://secunia.com/advisories/37228/
DESCRIPTION:
Nikolas Rangos has discovered a vulnerability in Serv-U, which can be
exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a boundary error within the
included HTTP server when processing certain cookies. This can be
exploited to cause a stack-based buffer overflow by sending a
malicious HTTP request containing a specially crafted cookie to the
server.
The vulnerability is confirmed in version 9.0.0.5.
SOLUTION:
Filter malicious requests using a proxy.
PROVIDED AND/OR DISCOVERED BY:
Nikolaos Rangos, KC Security.
ORIGINAL ADVISORY:
http://www.rangos.de/ServU-ADV.txt
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
| VAR-200911-0336 | No CVE | Citrix NetScaler and Access Gateway Denial Of Service Vulnerability |
CVSS V2: - CVSS V3: - Severity: - |
Citrix NetScaler and Access Gateway are prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause denial-of-service conditions.
The issue affects the appliance firmware 9.0 (prior to build 70.5) and 9.1 (prior to build 96.4).
The following products are affected:
Citrix NetScaler
NetScaler Application Firewall
Access Gateway Enterprise Edition
| VAR-200912-0194 | CVE-2009-4292 | SEIL/X Series and SEIL/B1 buffer overflow vulnerability |
CVSS V2: 9.3 CVSS V3: - Severity: HIGH |
Buffer overflow in the URL filtering function in Internet Initiative Japan SEIL/X1, SEIL/X2, and SEIL/B1 firmware 2.40 through 2.51 allows remote attackers to execute arbitrary code via unspecified vectors. SEIL/X Series and SEIL/B1 contain a buffer overflow vulnerability. SEIL/X Series and SEIL/B1 are routers.
The following devices are affected:
SEIL/X1 2.40 to 2.51
SEIL/X2 2.40 to 2.51
SEIL/B1 2.40 to 2.51. ----------------------------------------------------------------------
Do you have VARM strategy implemented?
(Vulnerability Assessment Remediation Management)
If not, then implement it through the most reliable vulnerability
intelligence source on the market.
Implement it through Secunia.
For more information visit:
http://secunia.com/advisories/business_solutions/
Alternatively request a call from a Secunia representative today to
discuss how we can help you with our capabilities contact us at:
sales@secunia.com
----------------------------------------------------------------------
TITLE:
SEIL Routers Denial of Service and Buffer Overflow Vulnerabilities
SECUNIA ADVISORY ID:
SA37154
VERIFY ADVISORY:
http://secunia.com/advisories/37154/
DESCRIPTION:
Some vulnerabilities have been reported in the SEIL/X1, X2, and B1
routers, which can be exploited by malicious people to cause a DoS
(Denial of Service) and compromise a vulnerable system.
1) An error exists when processing of certain GRE packets. This can
be exploited to cause the device to restart by sending certain
specially crafted GRE packets.
Note: Successful exploitation requires that the NAT functionality is
enabled.
2) A buffer overflow error exists within the URL filtering
functionality.
Vulnerability #1 is reported in SEIL/X1, X2, and B1 version 2.30 to
2.51 and vulnerability #2 is reported in SEIL/X1, X2, and B1 version
2.40 to 2.51.
SOLUTION:
Update to version 2.52.
PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.
ORIGINAL ADVISORY:
1) http://jvn.jp/jp/JVN13011682/index.html
http://www.seil.jp/seilseries/security/2009/a00674.php
2) http://jvn.jp/jp/JVN06362164/index.html
http://www.seil.jp/seilseries/security/2009/a00669.php
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
| VAR-200912-0195 | CVE-2009-4293 | SEIL/X Series and SEIL/B1 denial of service vulnerability |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
Internet Initiative Japan SEIL/X1, SEIL/X2, and SEIL/B1 firmware 2.30 through 2.51, when NAT is enabled, allows remote attackers to cause a denial of service (system restart) via crafted GRE packets. SEIL/X Series and SEIL/B1 contain a denial of service (DoS) vulnerability. SEIL/X Series and SEIL/B1 are routers.
Successfully exploiting these issues allows remote attackers to execute arbitrary code with administrative privileges or crash the affected device, denying service to legitimate users.
The following devices are affected:
SEIL/X1 2.40 to 2.51
SEIL/X2 2.40 to 2.51
SEIL/B1 2.40 to 2.51. ----------------------------------------------------------------------
Do you have VARM strategy implemented?
(Vulnerability Assessment Remediation Management)
If not, then implement it through the most reliable vulnerability
intelligence source on the market.
Implement it through Secunia.
For more information visit:
http://secunia.com/advisories/business_solutions/
Alternatively request a call from a Secunia representative today to
discuss how we can help you with our capabilities contact us at:
sales@secunia.com
----------------------------------------------------------------------
TITLE:
SEIL Routers Denial of Service and Buffer Overflow Vulnerabilities
SECUNIA ADVISORY ID:
SA37154
VERIFY ADVISORY:
http://secunia.com/advisories/37154/
DESCRIPTION:
Some vulnerabilities have been reported in the SEIL/X1, X2, and B1
routers, which can be exploited by malicious people to cause a DoS
(Denial of Service) and compromise a vulnerable system.
1) An error exists when processing of certain GRE packets.
Note: Successful exploitation requires that the NAT functionality is
enabled.
2) A buffer overflow error exists within the URL filtering
functionality. This can be exploited to cause a buffer overflow and
potentially execute arbitrary code by tricking a user into visiting a
specially crafted website.
Vulnerability #1 is reported in SEIL/X1, X2, and B1 version 2.30 to
2.51 and vulnerability #2 is reported in SEIL/X1, X2, and B1 version
2.40 to 2.51.
SOLUTION:
Update to version 2.52.
PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.
ORIGINAL ADVISORY:
1) http://jvn.jp/jp/JVN13011682/index.html
http://www.seil.jp/seilseries/security/2009/a00674.php
2) http://jvn.jp/jp/JVN06362164/index.html
http://www.seil.jp/seilseries/security/2009/a00669.php
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
| VAR-201008-0395 | No CVE | SEIL IPv6 Denial of Service Vulnerability |
CVSS V2: - CVSS V3: - Severity: - |
The SEIL router has a denial of service attack. The attacker can send a specially constructed IPv6 packet to the router to trigger a denial of service attack condition. SEIL routers are prone to a denial-of-service vulnerability.
The following versions are affected:
SEIL/X1 version 1.00 to 1.22
SEIL/X2 version 1.00 to 1.22
SEIL/Turbo version 1.00 to 1.92
SEIL/neu 2FE Plus version 1.00 to 1.92
SEIL/neu 128, T1 version 1.00 to 2.43
| VAR-201101-0006 | CVE-2009-5039 |
Cisco IOS of H.323 Implementation gk_circuit_info_do_in_acf Service disruption in functions (DoS) Vulnerabilities
Related entries in the VARIoT exploits database: VAR-E-200910-0147 |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Memory leak in the gk_circuit_info_do_in_acf function in the H.323 implementation in Cisco IOS before 15.0(1)XA allows remote attackers to cause a denial of service (memory consumption) via a large number of calls over a long duration, as demonstrated by InterZone Clear Token (IZCT) test traffic, aka Bug ID CSCsz72535. Cisco IOS of H.323 Implementation gk_circuit_info_do_in_acf Function leaks memory and interferes with service operation (DoS) There is a vulnerability that becomes a condition. The problem is Bug ID CSCsz72535 It is a problem.Denial of service by a large number of long-term calls by third parties (DoS) There is a possibility of being put into a state. Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the affected device to consume an excessive amount of memory, denying service to legitimate users.
This issue is being tracked by Cisco Bug ID CSCsz72535. Cisco IOS is an operating system developed by Cisco in the United States for its network equipment
| VAR-200911-0310 | CVE-2009-3896 | nginx of src/http/ngx_http_parse.c Service disruption in (DoS) Vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a long URI. The 'nginx' program is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 201203-22
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: High
Title: nginx: Multiple vulnerabilities
Date: March 28, 2012
Bugs: #293785, #293786, #293788, #389319, #408367
ID: 201203-22
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities have been found in nginx, the worst of which
may allow execution of arbitrary code.
Background
==========
nginx is a robust, small, and high performance HTTP and reverse proxy
server.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 www-servers/nginx < 1.0.14 >= 1.0.14
Description
===========
Multiple vulnerabilities have been found in nginx:
* The TLS protocol does not properly handle session renegotiation
requests (CVE-2009-3555).
* The "ngx_http_process_request_headers()" function in ngx_http_parse.c
could cause a NULL pointer dereference (CVE-2009-3896).
* nginx does not properly sanitize user input for the the WebDAV COPY
or MOVE methods (CVE-2009-3898).
* The "ngx_resolver_copy()" function in ngx_resolver.c contains a
boundary error which could cause a heap-based buffer overflow
(CVE-2011-4315).
* nginx does not properly parse HTTP header responses which could
expose sensitive information (CVE-2012-1180).
Impact
======
A remote attacker could possibly execute arbitrary code with the
privileges of the nginx process, cause a Denial of Service condition,
create or overwrite arbitrary files, or obtain sensitive information.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All nginx users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-servers/nginx-1.0.14"
References
==========
[ 1 ] CVE-2009-3555
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3555
[ 2 ] CVE-2009-3896
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3896
[ 3 ] CVE-2009-3898
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3898
[ 4 ] CVE-2011-4315
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4315
[ 5 ] CVE-2012-1180
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1180
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
http://security.gentoo.org/glsa/glsa-201203-22.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2012 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
http://creativecommons.org/licenses/by-sa/2.5
. ----------------------------------------------------------------------
Become a PSI 3.0 beta tester!
Test-drive the new beta version and tell us what you think about its extended automatic update function and significantly enhanced user-interface.
Download it here!
http://secunia.com/psi_30_beta_launch
----------------------------------------------------------------------
TITLE:
Gentoo update for nginx
SECUNIA ADVISORY ID:
SA48577
VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/48577/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=48577
RELEASE DATE:
2012-03-28
DISCUSS ADVISORY:
http://secunia.com/advisories/48577/#comments
AVAILABLE ON SITE AND IN CUSTOMER AREA:
* Last Update
* Popularity
* Comments
* Criticality Level
* Impact
* Where
* Solution Status
* Operating System / Software
* CVE Reference(s)
http://secunia.com/advisories/48577/
ONLY AVAILABLE IN CUSTOMER AREA:
* Authentication Level
* Report Reliability
* Secunia PoC
* Secunia Analysis
* Systems Affected
* Approve Distribution
* Remediation Status
* Secunia CVSS Score
* CVSS
https://ca.secunia.com/?page=viewadvisory&vuln_id=48577
ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI:
* AUTOMATED SCANNING
http://secunia.com/vulnerability_scanning/personal/
http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/
DESCRIPTION:
Gentoo has issued an update for nginx. This fixes a weakness, a
security issue, and multiple vulnerabilities, which can be exploited
by malicious people to disclose certain sensitive information, bypass
certain security restrictions, cause a DoS (Denial of Service),
manipulate certain data, and potentially compromise a vulnerable
system.
For more information:
SA36751
SA36818
SA37291
SA46798
SA48366
SOLUTION:
Update to "www-servers/nginx-1.0.14" or later.
ORIGINAL ADVISORY:
GLSA 201203-22:
http://www.gentoo.org/security/en/glsa/glsa-201203-22.xml
OTHER REFERENCES:
Further details available in Customer Area:
http://secunia.com/vulnerability_intelligence/
DEEP LINKS:
Further details available in Customer Area:
http://secunia.com/vulnerability_intelligence/
EXTENDED DESCRIPTION:
Further details available in Customer Area:
http://secunia.com/vulnerability_intelligence/
EXTENDED SOLUTION:
Further details available in Customer Area:
http://secunia.com/vulnerability_intelligence/
EXPLOIT:
Further details available in Customer Area:
http://secunia.com/vulnerability_intelligence/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
| VAR-201001-0064 | CVE-2009-4587 |
Cherokee Web Server GET request Denial of Service Vulnerability
Related entries in the VARIoT exploits database: VAR-E-200910-0315 |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word. Cherokee Web Server is a flexible, fast, lightweight web server.
An attacker could exploit this issue to crash the affected application, denying service to legitimate users.
Cherokee Web Server 0.5.4 is vulnerable; other versions may also be affected
NOTE: This BID is being retired because the vulnerability is caused by a problem in Microsoft Windows when handling DOS-style device names; it is not specific to this application