CVE-2011-0833
published 2011-04-20CVE-2011-0833: Unspecified vulnerability in the Siebel CRM Core component in Oracle Siebel CRM 7.8.2, 8.0.0, and 8.1.1 allows remote attackers to affect integrity, related to…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.35%
68.3th percentile
Unspecified vulnerability in the Siebel CRM Core component in Oracle Siebel CRM 7.8.2, 8.0.0, and 8.1.1 allows remote attackers to affect integrity, related to UIF Client.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | siebel_crm | — | — |
| oracle | siebel_crm | — | — |
| oracle | siebel_crm | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-347c-j8p3-3xr4: Unspecified vulnerability in the Siebel CRM Core component in Oracle Siebel CRM 7
ghsa_unreviewed·2022-05-17
CVE-2011-0833 [MEDIUM] GHSA-347c-j8p3-3xr4: Unspecified vulnerability in the Siebel CRM Core component in Oracle Siebel CRM 7
Unspecified vulnerability in the Siebel CRM Core component in Oracle Siebel CRM 7.8.2, 8.0.0, and 8.1.1 allows remote attackers to affect integrity, related to UIF Client.
Red Hat
kernel: corrupted GUID partition tables can cause kernel oops
vendor_redhat·2011-04-13·CVSS 4.9
CVE-2011-1577 [MEDIUM] kernel: corrupted GUID partition tables can cause kernel oops
kernel: corrupted GUID partition tables can cause kernel oops
Heap-based buffer overflow in the is_gpt_valid function in fs/partitions/efi.c in the Linux kernel 2.6.38 and earlier allows physically proximate attackers to cause a denial of service (OOPS) or possibly have unspecified other impact via a crafted size of the EFI GUID partition-table header on removable media.
Statement: This issue affects the versions of Linux kernel as shipped with Red Hat
Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0833.html, https://rhn.redhat.com/errata/RHSA-2011-1465.html, and https://rhn.redhat.com/errata/RHSA-2011-1253.html. Red Hat Enterprise Linux 4 is now in Produ
Red Hat
kernel: drivers/scsi/mpt2sas: prevent heap overflows
vendor_redhat·2011-04-05·CVSS 6.9
CVE-2011-1494 [MEDIUM] CWE-119 kernel: drivers/scsi/mpt2sas: prevent heap overflows
kernel: drivers/scsi/mpt2sas: prevent heap overflows
Integer overflow in the _ctl_do_mpt_command function in drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier might allow local users to gain privileges or cause a denial of service (memory corruption) via an ioctl call specifying a crafted value that triggers a heap-based buffer overflow.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat
Enterprise Linux 4 as it did not provide support for MPT (Message Passing
Technology) based controllers. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0833.html, and https://rhn.redhat.com/errata/RHSA-2011-0542.html, and https://rhn.redhat.com/errata/RHSA-2011-1
Red Hat
kernel: drivers/scsi/mpt2sas: prevent heap overflows
vendor_redhat·2011-04-05·CVSS 7.2
CVE-2011-1495 [HIGH] CWE-119 kernel: drivers/scsi/mpt2sas: prevent heap overflows
kernel: drivers/scsi/mpt2sas: prevent heap overflows
drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier does not validate (1) length and (2) offset values before performing memory copy operations, which might allow local users to gain privileges, cause a denial of service (memory corruption), or obtain sensitive information from kernel memory via a crafted ioctl call, related to the _ctl_do_mpt_command and _ctl_diag_read_buffer functions.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat
Enterprise Linux 4 as it did not provide support for MPT (Message Passing
Technology) based controllers. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0833.html
Red Hat
kernel: fs/partitions: Corrupted OSF partition table infoleak
vendor_redhat·2011-03-15·CVSS 2.1
CVE-2011-1163 [LOW] kernel: fs/partitions: Corrupted OSF partition table infoleak
kernel: fs/partitions: Corrupted OSF partition table infoleak
The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vectors related to partition-table parsing.
Statement: This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0833.html, https://rhn.redhat.com/errata/RHSA-2011-0542.html, and https://rhn.redhat.com/errata/RHSA-2011-0500.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata/, therefore the fix for
this issue is not currently pl
Red Hat
ipv4: netfilter: ipt_CLUSTERIP: fix buffer overflow
vendor_redhat·2011-03-10·CVSS 7.8
CVE-2011-2534 [HIGH] ipv4: netfilter: ipt_CLUSTERIP: fix buffer overflow
ipv4: netfilter: ipt_CLUSTERIP: fix buffer overflow
Buffer overflow in the clusterip_proc_write function in net/ipv4/netfilter/ipt_CLUSTERIP.c in the Linux kernel before 2.6.39 might allow local users to cause a denial of service or have unspecified other impact via a crafted write operation, related to string data that lacks a terminating '\0' character.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not have support for ipt_CLUSTERIP. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via http://rhn.redhat.com/errata/RHSA-2011-0833.html, http://rhn.redhat.com/errata/RHSA-2011-0498.html, and http://rhn.redhat.com/errata/RHSA-2011-0500.html.
Package: kernel (Red Hat Enterprise Linux
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1763 kernel: xen: improper upper boundary check in get_free_port() function
bugzilla·2011-05-02·CVSS 7.7
CVE-2011-1763 [HIGH] CVE-2011-1763 kernel: xen: improper upper boundary check in get_free_port() function
CVE-2011-1763 kernel: xen: improper upper boundary check in get_free_port() function
Description:
A flaw was found in the way Xen hypervisor checked for upper boundary when
getting a new event channel port. A privileged DomU user could use this
flaws to cause denial of service or, possibly, increase his privileges.
Discussion:
This issue does not affect upstream.
---
Statement:
This issue only affects Red Hat Enterprise Linux 5 as we did not backport upstream Xen unstable commit 2dcdd2fcb945. The versions of the Linux kernel as shipped with Red Hat Enterprise Linux 4, 6, and Red Hat Enterprise MRG are not affected.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2011:0833 https://rhn.redhat.com/errata/RHSA-2011-0833.html
Bugzilla
CVE-2011-1577 kernel: corrupted GUID partition tables can cause kernel oops
bugzilla·2011-04-13·CVSS 4.9
CVE-2011-1577 [MEDIUM] CVE-2011-1577 kernel: corrupted GUID partition tables can cause kernel oops
CVE-2011-1577 kernel: corrupted GUID partition tables can cause kernel oops
The Linux kernel automatically evaluates partition tables of storage devices. The code for evaluating EFI GUID partitions (in fs/partitions/efi.c) contains a bug that causes a kernel oops on certain corrupted GUID partition tables.
Proposed patch:
http://www.spinics.net/lists/mm-commits/msg83274.html
Acknowledgements:
Red Hat would like to thank Timo Warns for reporting this issue.
Discussion:
Statement:
This issue affects the versions of Linux kernel as shipped with Red Hat
Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0833.html, https://rhn.redhat.com/errata/RHSA-2011-1465
Bugzilla
CVE-2011-1166 kernel: xen: x86_64: fix error checking in arch_set_info_guest()
bugzilla·2011-03-17·CVSS 5.5
CVE-2011-1166 [MEDIUM] CVE-2011-1166 kernel: xen: x86_64: fix error checking in arch_set_info_guest()
CVE-2011-1166 kernel: xen: x86_64: fix error checking in arch_set_info_guest()
Cannot specify user mode execution without specifying user-mode pagetables.
The problem is that a 64-bit guest can get one of its vcpus into non-kernel mode without first providing a valid non-kernel pagetable. The iret-into-userspace path has the right checks, but just setting the context on a fresh vcpu doesn't. :( The observed failure mode is usually a hard lockup of the host. This affects 64-bit version of kernel-xen.
Upstream commit:
http://xenbits.xen.org/hg/staging/xen-unstable.hg/rev/c79aae866ad8
Reference:
https://bugzilla.novell.com/show_bug.cgi?id=679344
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2011:0833 https://rhn.redhat.com/errata/
Bugzilla
CVE-2011-1078 kernel: bt sco_conninfo infoleak
bugzilla·2011-03-01·CVSS 1.9
CVE-2011-1078 [LOW] CVE-2011-1078 kernel: bt sco_conninfo infoleak
CVE-2011-1078 kernel: bt sco_conninfo infoleak
Description of problem:
struct sco_conninfo has one padding byte in the end. Local variable
cinfo of type sco_conninfo is copied to userspace with this uninizialized
one byte, leading to old stack contents leak.
Reference:
http://seclists.org/oss-sec/2011/q1/309
https://lkml.org/lkml/2011/2/14/49
Acknowledgements:
Red Hat would like to thank Vasiliy Kulikov of Openwall for reporting this issue.
Discussion:
Upstream commit:
http://git.kernel.org/linus/c4c896e1471aec3b004a693c689f60be3b17ac86
---
This issue has been addressed in following products:
MRG for RHEL-5
Via RHSA-2011:0500 https://rhn.redhat.com/errata/RHSA-2011-0500.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2011:0833
2011-04-20
Published