CVE-2009-3516
published 2009-10-01CVE-2009-3516: gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass…
PriorityP423high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.38%
30.1th percentile
gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
Bugzilla
CVE-2009-1416 gnutls: All DSA keys generated using GnuTLS 2.6.x are corrupt [GNUTLS-SA-2009-2]
bugzilla·2009-04-30·CVSS 7.5
CVE-2009-1416 [HIGH] CVE-2009-1416 gnutls: All DSA keys generated using GnuTLS 2.6.x are corrupt [GNUTLS-SA-2009-2]
CVE-2009-1416 gnutls: All DSA keys generated using GnuTLS 2.6.x are corrupt [GNUTLS-SA-2009-2]
Quoting upstream security advisory:
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3516
When investigating the DSA problems reported by Miroslav Kratochvil,
Simon Josefsson discovered that all DSA keys generated by
GnuTLS 2.6.x are corrupt. Rather than generating a DSA key, GnuTLS
will generate a RSA key and store it in a DSA structure.
GnuTLS 2.4.x and earlier did not contain the buggy code.
Fixed upstream in 2.6.6:
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3514
Discussion:
This issue did not affect versions of gnutls shipped in Red Hat Enterprise Linux 4 and 5, and Fedora up to version 10, as they are based on upstream versions prior to 2.6. gnutls 2
http://aix.software.ibm.com/aix/efixes/security/nfs4_advisory.aschttp://www-01.ibm.com/support/docview.wss?uid=isg1IZ49024http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49096http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49278http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50399http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50444http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50496http://www.securityfocus.com/bid/36545http://www.vupen.com/english/advisories/2009/2788https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6318http://aix.software.ibm.com/aix/efixes/security/nfs4_advisory.aschttp://www-01.ibm.com/support/docview.wss?uid=isg1IZ49024http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49096http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49278http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50399http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50444http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50496http://www.securityfocus.com/bid/36545http://www.vupen.com/english/advisories/2009/2788https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6318
2009-10-01
Published