CVE-2012-1694
published 2012-05-03CVE-2012-1694: Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality and integrity, related to libsasl.
PriorityP432medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.07%
79.3th percentile
Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality and integrity, related to libsasl.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | sunos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6088 rpm: Signature checking function returned success on (possibly malicious ) rpm packages
bugzilla·2023-02-14·CVSS 4.3
CVE-2012-6088 [MEDIUM] CVE-2012-6088 rpm: Signature checking function returned success on (possibly malicious ) rpm packages
CVE-2012-6088 rpm: Signature checking function returned success on (possibly malicious ) rpm packages
The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package.
http://rpm.org/wiki/Releases/4.10.2
http://secunia.com/advisories/51706
https://bugzilla.novell.com/show_bug.cgi?id=796375
http://www.securityfocus.com/bid/57138
http://www.openwall.com/lists/oss-security/2013/01/03/9
http://www.ubuntu.com/usn/USN-1694-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/80953
http://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=3d74c43
Discussion:
This bug is now closed. Further updates for individual products wi
Bugzilla
CVE-2010-5077 quake3: DDoS via getstatus and rcon requests
bugzilla·2012-03-26·CVSS 7.8
CVE-2010-5077 [HIGH] CVE-2010-5077 quake3: DDoS via getstatus and rcon requests
CVE-2010-5077 quake3: DDoS via getstatus and rcon requests
A distributed denial of service flaw was found in the way Quake3 Arena / OpenArena servers used to handle 'getstatus' and 'rcon' (remote command) connectionless requests. A remote attacker could use this flaw to perform distributed denial of service attack against the target server IP gameserver by spoofing certain packets.
References:
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=665656
[2] http://openarena.ws/board/index.php?topic=4391.0
[3] http://www.ioquake.org/forums/viewtopic.php?f=12&t=1694
[4] http://www.urbanterror.info/forums/topic/27825-drdos/
[5] http://lists.ioquake.org/pipermail/ioquake3-ioquake.org/2012-January/004778.html
Relevant upstream patch:
[6] http://icculus.org/pipermail/quake3-commits/2010-Januar
http://secunia.com/advisories/48809http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.securitytracker.com/id?1026940http://secunia.com/advisories/48809http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.securitytracker.com/id?1026940
2012-05-03
Published