CVE-2011-0396
published 2011-02-25CVE-2011-0396: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1 before 8.1(2.49), 8.2 before 8.2(4.1), and 8.3 before…
PriorityP341high7.8CVSS 2.0
AVNACLAuNCCINAN
EPSS
1.40%
69.5th percentile
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1 before 8.1(2.49), 8.2 before 8.2(4.1), and 8.3 before 8.3(2.13), when a Certificate Authority (CA) is configured, allow remote attackers to read arbitrary files via unspecified vectors, aka Bug ID CSCtk12352.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | asa_5500_series_adaptive_security_appliances | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
vendor_cisco·2011-02-23·CVSS 7.8
CVE-2011-0393 [HIGH] CWE-399 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Cisco ASA 5500 Series Adaptive Security Appliances are affected by the
following vulnerabilities:
Transparent Firewall Packet Buffer Exhaustion Vulnerability
Skinny Client Control Protocol (SCCP) Inspection Denial of Service
Vulnerability
Routing Information Protocol (RIP) Denial of Service
Vulnerability
Unauthorized File System Access Vulnerability
These vulnerabilities are independent; a release that is affected by
one vulnerability is not necessarily affected by the others.
Cisco has released software updates that address these vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110223-asa.
Note: The Cisco Firewall Serv
Cisco
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
vendor_cisco
CVE-2011-0396 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
CVE-2011-0396: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Cisco ASA 5500 Series Adaptive Security Appliances are affected by the following vulnerabilities: Transparent Firewall Packet Buffer Exhaustion Vulnerability Skinny Client Control Protocol (SCCP) Inspection Denial of Service Vulnerability Routing Information Protocol (RIP) Denial of Service Vulnerability Unauthorized File System Access Vulnerability These vulnerabilities are independent; a release that is affected by one vulnerability is not necessarily affected by the others. Cisco has released software updates that address these vulnerabilities. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110223-asa . Note: The Cisco Firewal
GHSA
GHSA-hmmq-hjh9-ghq8: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8
ghsa_unreviewed·2022-05-14
CVE-2011-0396 [HIGH] GHSA-hmmq-hjh9-ghq8: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1 before 8.1(2.49), 8.2 before 8.2(4.1), and 8.3 before 8.3(2.13), when a Certificate Authority (CA) is configured, allow remote attackers to read arbitrary files via unspecified vectors, aka Bug ID CSCtk12352.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0721 shadow: Multiple CRLF injections in chfn and chsh
bugzilla·2011-02-20·CVSS 6.4
CVE-2011-0721 [MEDIUM] CVE-2011-0721 shadow: Multiple CRLF injections in chfn and chsh
CVE-2011-0721 shadow: Multiple CRLF injections in chfn and chsh
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-0721 to
the following vulnerability:
Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in
shadow 1:4.1.4 allow local users to add new users or groups to
/etc/passwd via the GECOS field.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0721
[2] http://www.debian.org/security/2011/dsa-2164
[3] http://www.ubuntu.com/usn/USN-1065-1
[4] http://www.securityfocus.com/bid/46426
[5] http://secunia.com/advisories/42505
[6] http://secunia.com/advisories/43345
[7] http://www.vupen.com/english/advisories/2011/0396
[8] http://www.vupen.com/english/advisories/2011/0398
Discussion:
This issue did NOT affect the versions of util-linux
Bugzilla
CVE-2010-0396 dpkg: path traversal issue
bugzilla·2010-03-11·CVSS 5.8
CVE-2010-0396 [MEDIUM] CVE-2010-0396 dpkg: path traversal issue
CVE-2010-0396 dpkg: path traversal issue
Dpkg upstream has recently addressed:
[1] http://www.debian.org/security/2010/dsa-2011
one path traversal issue by unpacking source packages.
More issue details from [1]:
William Grant discovered that the dpkg-source component
of dpkg, the low-level infrastructure for handling the
installation and removal of Debian software packages, is
vulnerable to path traversal attacks. A specially crafted
Debian source package can lead to file modification outside
of the destination directory when extracting the package
content.
References:
[2] http://seclists.org/fulldisclosure/2010/Mar/201
Upstream patches:
[3] http://git.debian.org/?p=dpkg/dpkg.git;a=commit;h=2cb3d5d38fbe937280a8875b79a7247ac37a383d
[4] http://git.debian.org/?p=dpkg/dpkg.git;a=commit;h=
http://secunia.com/advisories/43488http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14d.shtmlhttp://www.securitytracker.com/id?1025108http://www.vupen.com/english/advisories/2011/0493https://exchange.xforce.ibmcloud.com/vulnerabilities/65591http://secunia.com/advisories/43488http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14d.shtmlhttp://www.securitytracker.com/id?1025108http://www.vupen.com/english/advisories/2011/0493https://exchange.xforce.ibmcloud.com/vulnerabilities/65591
2011-02-25
Published