CVE-2011-1386
published 2012-01-04CVE-2011-1386: IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, and 6.2.1 do not properly handle…
PriorityP426medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.25%
66.0th percentile
IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, and 6.2.1 do not properly handle signature validations based on SAML 1.0, 1.1, and 2.0, which allows remote attackers to bypass intended authentication or authorization requirements via a non-conforming SAML signature.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | tivoli_federated_identity_manager | — | — |
| ibm | tivoli_federated_identity_manager | — | — |
| ibm | tivoli_federated_identity_manager | — | — |
| ibm | tivoli_federated_identity_manager_business_gateway | — | — |
| ibm | tivoli_federated_identity_manager_business_gateway | — | — |
| ibm | tivoli_federated_identity_manager_business_gateway | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-339v-wcxr-4xwf: IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6
ghsa_unreviewed·2022-05-17
CVE-2011-1386 [MEDIUM] GHSA-339v-wcxr-4xwf: IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6
IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, and 6.2.1 do not properly handle signature validations based on SAML 1.0, 1.1, and 2.0, which allows remote attackers to bypass intended authentication or authorization requirements via a non-conforming SAML signature.
Red Hat
kernel: bridge: null pointer dereference in __br_deliver
vendor_redhat·2011-10-20·CVSS 6.8
CVE-2011-2942 [MEDIUM] CWE-476 kernel: bridge: null pointer dereference in __br_deliver
kernel: bridge: null pointer dereference in __br_deliver
A certain Red Hat patch to the __br_deliver function in net/bridge/br_forward.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging connectivity to a network interface that uses an Ethernet bridge device.
Statement: This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 4, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html.
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Affected
Package: realt
Red Hat
kernel: be2net: promiscuous mode and non-member VLAN packets DoS
vendor_redhat·2011-10-20·CVSS 4.6
CVE-2011-3347 [MEDIUM] kernel: be2net: promiscuous mode and non-member VLAN packets DoS
kernel: be2net: promiscuous mode and non-member VLAN packets DoS
A certain Red Hat patch to the be2net implementation in the kernel package before 2.6.32-218.el6 on Red Hat Enterprise Linux (RHEL) 6, when promiscuous mode is enabled, allows remote attackers to cause a denial of service (system crash) via non-member VLAN packets.
Statement: This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not include support for ServerEngines' 10Gbps network adapter - BladeEngine. This has been addressed in Red Hat Enterprise Linux 6 via https://rhn.redhat.com/errata/RHSA-2011-1530.html. A future kernel update in Red Hat Enterprise MRG may
Red Hat
kernel: cifs: signedness issue in CIFSFindNext()
vendor_redhat·2011-08-23·CVSS 8.8
CVE-2011-3191 [HIGH] kernel: cifs: signedness issue in CIFSFindNext()
kernel: cifs: signedness issue in CIFSFindNext()
Integer signedness error in the CIFSFindNext function in fs/cifs/cifssmb.c in the Linux kernel before 3.1 allows remote CIFS servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large length value in a response to a read request for a directory.
Statement: This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG. It has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1386.html, https://rhn.redhat.com/errata/RHSA-2011-1465.html, and https://rhn.redhat.com/errata/RHSA-2012-0010.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, ht
Red Hat
kernel: xen: IOMMU fault livelock
vendor_redhat·2011-08-12·CVSS 4.6
CVE-2011-3131 [MEDIUM] kernel: xen: IOMMU fault livelock
kernel: xen: IOMMU fault livelock
Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] device to cause a denial of service (CPU consumption and host hang) via many crafted DMA requests that are denied by the IOMMU, which triggers a livelock.
Statement: The versions of the Linux kernel as shipped with Red Hat Enterprise Linux 4, 6,
and Red Hat Enterprise MRG are not affected. It has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html.
Red Hat
kernel: net: improve sequence number generation
vendor_redhat·2011-08-07·CVSS 9.1
CVE-2011-3188 [CRITICAL] kernel: net: improve sequence number generation
kernel: net: improve sequence number generation
The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.
Statement: This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG. It has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1386.html, https://rhn.redhat.com/errata/RHSA-2011-1465.html, and https://rhn.redhat.com/errata/RHSA-2012-0010.html. Red Hat Enterprise Linux 4 is now in
Red Hat
kernel: gro: only reset frag0 when skb can be pulled
vendor_redhat·2011-07-27·CVSS 5.7
CVE-2011-2723 [MEDIUM] kernel: gro: only reset frag0 when skb can be pulled
kernel: gro: only reset frag0 when skb can be pulled
The skb_gro_header_slow function in include/linux/netdevice.h in the Linux kernel before 2.6.39.4, when Generic Receive Offload (GRO) is enabled, resets certain fields in incorrect situations, which allows remote attackers to cause a denial of service (system crash) via crafted network traffic.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not backport the upstream commit a5b1cf28 that introduced this issue. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1386.html, https://rhn.redhat.com/errata/RHSA-2011-1350.html, and https://rhn.redhat.com/errata/RHSA-2012-0010.html.
Package: kern
Red Hat
kernel: taskstats: duplicate entries in listener mode can lead to DoS
vendor_redhat·2011-06-16·CVSS 4.9
CVE-2011-2484 [MEDIUM] kernel: taskstats: duplicate entries in listener mode can lead to DoS
kernel: taskstats: duplicate entries in listener mode can lead to DoS
The add_del_listener function in kernel/taskstats.c in the Linux kernel 2.6.39.1 and earlier does not prevent multiple registrations of exit handlers, which allows local users to cause a denial of service (memory and CPU consumption), and bypass the OOM Killer, via a crafted application.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat
Enterprise Linux 4 as it did not provide support for the Taskstats interface. This was fixed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1386.html, https://rhn.redhat.com/errata/RHSA-2011-1350.html and https://rhn.redhat.com/errata/RHSA-2011-1253.html.
Package: kernel (Red Hat Enterpris
Red Hat
kernel: ext4: kernel panic when writing data to the last block of sparse file
vendor_redhat·2011-06-03·CVSS 4.9
CVE-2011-2695 [MEDIUM] kernel: ext4: kernel panic when writing data to the last block of sparse file
kernel: ext4: kernel panic when writing data to the last block of sparse file
Multiple off-by-one errors in the ext4 subsystem in the Linux kernel before 3.0-rc5 allow local users to cause a denial of service (BUG_ON and system crash) by accessing a sparse file in extent format with a write operation involving a block number corresponding to the largest possible 32-bit unsigned integer.
Statement: This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1386.html, https://rhn.redhat.com/errata/RHSA-2011-1189.html, and https://rhn.redhat.com/errata/RHSA-2011-1253.html. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not include support for EXT4 filesystem.
Pa
Red Hat
kernel: cifs session reuse
vendor_redhat·2010-08-02·CVSS 3.3
CVE-2011-1585 [LOW] kernel: cifs session reuse
kernel: cifs session reuse
The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user.
Statement: This issue did not affect the versions of Linux kernel as shipped in Red Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG as they did not ship mount.cifs with root setuid set. However, as a preventive meaasure, we have addressed this in Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1386.html and https://rhn.redhat.com/errata/RHSA-2011-1253.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycl
Red Hat
kernel: usb: buffer overflow in auerswald_probe()
vendor_redhat·2009-10-29·CVSS 6.8
CVE-2009-4067 [MEDIUM] kernel: usb: buffer overflow in auerswald_probe()
kernel: usb: buffer overflow in auerswald_probe()
Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically proximate attackers to execute arbitrary code, cause a denial of service via a crafted USB device, or take full control of the system.
Statement: This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as the affected code has been removed. It was addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata/, therefore the fix for this issue is not currently planned to be included i
Red Hat
kernel: panic occurs when clock_gettime() is called
vendor_redhat·2008-05-01·CVSS 4.9
CVE-2011-3209 [MEDIUM] kernel: panic occurs when clock_gettime() is called
kernel: panic occurs when clock_gettime() is called
The div_long_long_rem implementation in include/asm-x86/div64.h in the Linux kernel before 2.6.26 on the x86 platform allows local users to cause a denial of service (Divide Error Fault and panic) via a clock_gettime system call.
Statement: This issue did not affect the Linux kernels as shipped with Red Hat Enterprise Linux 4, 6, and Red Hat Enterprise MRG, as they either do not have the sample_to_timespec() function, or have already backported upstream commit f8bd2258, which addresses this issue. It was addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html.
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (R
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3347 kernel: be2net: promiscuous mode and non-member VLAN packets DoS
bugzilla·2011-09-07·CVSS 4.6
CVE-2011-3347 [MEDIUM] CVE-2011-3347 kernel: be2net: promiscuous mode and non-member VLAN packets DoS
CVE-2011-3347 kernel: be2net: promiscuous mode and non-member VLAN packets DoS
When interface is put in promiscuous mode and it receives VLAN packets, but no VLANS are configured on that interface , then the kernel crashes in the 8021q module.
Acknowledgements:
Red Hat would like to thank Somnath Kotur for reporting this issue.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2011:1386 https://rhn.redhat.com/errata/RHSA-2011-1386.html
---
Statement:
This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not include support for ServerEngines' 10Gbps network adapter - Bla
Bugzilla
CVE-2011-2942 kernel: bridge: null pointer dereference in __br_deliver
bugzilla·2011-08-16·CVSS 6.8
CVE-2011-2942 [MEDIUM] CVE-2011-2942 kernel: bridge: null pointer dereference in __br_deliver
CVE-2011-2942 kernel: bridge: null pointer dereference in __br_deliver
In the br_forward_finish() function, we may call kfree() on the skb we are forwarding, and so, after it, we should not dereference skb->dev pointer. With the fix, we save skb->dev before calling the br_forward_finish() function, so that we can use it afterwards.
Discussion:
Statement:
This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 4, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2011:1386 https://rhn.redhat.com/errata/RHSA-2011-1386.html
---
Created kernel tracking bugs for this issue
Affe
Bugzilla
CVE-2011-2695 kernel: ext4: kernel panic when writing data to the last block of sparse file
bugzilla·2011-07-15·CVSS 4.9
CVE-2011-2695 [MEDIUM] CVE-2011-2695 kernel: ext4: kernel panic when writing data to the last block of sparse file
CVE-2011-2695 kernel: ext4: kernel panic when writing data to the last block of sparse file
If an extent exists which includes the block right before the maximum file offset, and the block for the maximum file offset is written, the kernel panics. For 4KB block size, the problem only occurs on x86_64 architecture. For 1KB or 2KB block size, the problem occurs on both i386 and x86_64.
Local unprivileged users can use this flaw to crash the system when ext4 filesystem is in use.
Upstream fix:
http://git.kernel.org/linus/f17722f917b2f21497deb6edc62fb1683daa08e6
References:
http://www.spinics.net/lists/linux-ext4/msg25697.html
Discussion:
Statement:
This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1386.html,
http://www-01.ibm.com/support/docview.wss?uid=swg1IV10793http://www-01.ibm.com/support/docview.wss?uid=swg1IV10801http://www-01.ibm.com/support/docview.wss?uid=swg1IV10813http://www.ibm.com/support/docview.wss?uid=swg21575309https://exchange.xforce.ibmcloud.com/vulnerabilities/71686http://www-01.ibm.com/support/docview.wss?uid=swg1IV10793http://www-01.ibm.com/support/docview.wss?uid=swg1IV10801http://www-01.ibm.com/support/docview.wss?uid=swg1IV10813http://www.ibm.com/support/docview.wss?uid=swg21575309https://exchange.xforce.ibmcloud.com/vulnerabilities/71686
2012-01-04
Published