CVE-2012-2013
published 2012-06-29CVE-2012-2013: Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows remote attackers to cause a denial of service, or possibly obtain…
PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.89%
89.1th percentile
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows remote attackers to cause a denial of service, or possibly obtain sensitive information or modify data, via unknown vectors.
Affected
72 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | system_management_homepage | <= 7.1.0-16 | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa4.3MEDIUM
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache ActiveMQ Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet
ghsa·2022-05-17·CVSS 4.3
CVE-2013-1880 [MEDIUM] CWE-79 Apache ActiveMQ Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet
Apache ActiveMQ Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet
Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092.
GHSA
OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function
ghsa·2022-05-17
CVE-2013-1838 [HIGH] CWE-770 OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function
OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
GHSA
GHSA-x95c-rjv7-hrwr: Unspecified vulnerability in HP System Management Homepage (SMH) before 7
ghsa_unreviewed·2022-05-13
CVE-2012-2013 [HIGH] GHSA-x95c-rjv7-hrwr: Unspecified vulnerability in HP System Management Homepage (SMH) before 7
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows remote attackers to cause a denial of service, or possibly obtain sensitive information or modify data, via unknown vectors.
Red Hat
tomcat: incomplete fix for CVE-2012-3544
vendor_redhat·2014-02-25·CVSS 5.0
CVE-2013-4322 [MEDIUM] tomcat: incomplete fix for CVE-2012-3544
tomcat: incomplete fix for CVE-2012-3544
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field, which allows remote attackers to cause a denial of service by streaming data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3544.
It was discovered that the fix for CVE-2012-3544 did not properly resolve a denial of service flaw in the way Tomcat and JBoss Web processed chunk extensions and trailing headers in chunked requests. A remote attacker could use this flaw to send an excessively long request that, when processed by Tomcat, could consume network bandwidth, CPU, and
Red Hat
Keystone: denial of service through invalid token requests
vendor_redhat·2013-02-05·CVSS 5.0
CVE-2013-0247 [MEDIUM] Keystone: denial of service through invalid token requests
Keystone: denial of service through invalid token requests
OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0601 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0605, CVE-2013-0616, CVE-2013-0619, CVE-2013-0620, and CVE-2013-0623.
Red Hat
mysql: unspecified DoS vulnerability in MyISAM (Oracle CPU April 2012)
vendor_redhat·2012-04-17·CVSS 4.0
CVE-2012-0583 [MEDIUM] mysql: unspecified DoS vulnerability in MyISAM (Oracle CPU April 2012)
mysql: unspecified DoS vulnerability in MyISAM (Oracle CPU April 2012)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.60 and earlier, and 5.5.19 and earlier, allows remote authenticated users to affect availability, related to MyISAM.
Statement: On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue. Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5. Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Red Hat
libxslt: DoS when reading unexpected DTD nodes in XSLT in versions prior to 1.1.25
vendor_redhat·2009-09-16·CVSS 5.0
CVE-2013-4520 [MEDIUM] libxslt: DoS when reading unexpected DTD nodes in XSLT in versions prior to 1.1.25
libxslt: DoS when reading unexpected DTD nodes in XSLT in versions prior to 1.1.25
xslt.c in libxslt before 1.1.25 allows context-dependent attackers to cause a denial of service (crash) via a stylesheet that embeds a DTD, which causes a structure to be accessed as a different type. NOTE: this issue is due to an incomplete fix for CVE-2012-2825.
Statement: Not vulnerable. This issue was corrected in Red Hat Enterprise Linux 5 via RHSA-2012:1265. It did not affect Red Hat Enterprise Linux 6.
Package: libxslt (Red Hat Enterprise Linux 4) - Will not fix
Package: libxslt (Red Hat Enterprise Linux 5) - Not affected
Package: libxslt (Red Hat Enterprise Linux 6) - Not affected
Cisco
Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities
vendor_cisco
CVE-2012-5963 Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities
CVE-2012-5963: Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities
The Portable Software Developer Kit (SDK) for Universal Plug-n-Play (UPnP) Devices contains a libupnp library, originally known as the Intel SDK for UPnP Devices, which is vulnerable to multiple stack-based buffer overflows when handling malicious Simple Service Discovery Protocol (SSDP) requests. This library is used in several vendor network devices, in addition to media streaming and file sharing applications. These vulnerabilities were disclosed on January 29th, 2013 in a CERT Vulnerability Note, VU#922681, which can be viewed at http://www.kb.cert.org/vuls/id/922681 . Cisco is currently evaluating products for possible exposure to these vulnerabilities. This advisory is available at the following lin
Suricata
ET MALWARE EvilGrab/Vidgrab Checkin
suricata·2013-09-04
CVE-2012-0158 ET MALWARE EvilGrab/Vidgrab Checkin
ET MALWARE EvilGrab/Vidgrab Checkin
Rule: alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE EvilGrab/Vidgrab Checkin"; flow:established,to_server; content:"|7c 28|"; pcre:"/^\d{1,3}\x2e\d{1,3}\x2e\d{1,3}\x2e\d{1,3}/R"; content:"|29 7c|"; within:2; pcre:"/^\d{1,5}/R"; content:"|7c|Win"; within:4; reference:url,contagiodump.blogspot.com.br/2013/09/sandbox-miming-cve-2012-0158-in-mhtml.html; classtype:command-and-control; sid:2017413; rev:4; metadata:created_at 2013_09_04, signature_severity Major, updated_at 2024_03_06;)
Exploit-DB
Java - Web Start Double Quote Injection Remote Code Execution (Metasploit)
exploitdb·2013-06-11
CVE-2012-1533 Java - Web Start Double Quote Injection Remote Code Execution (Metasploit)
Java - Web Start Double Quote Injection Remote Code Execution (Metasploit)
---
##
#
# ========================================================
# Java Web Start Double Quote Inject Remote Code Execution
# ========================================================
#
# Date: Jun 12 2012 (updated: Jun 6 2013)
# Author: Rh0
# Version: At least Java 1.6.31 to 1.6.35 and 1.7.03 to 1.7.07
# Tested on: Windows XP SP3 EN and Windows 7
# CVE: 2012-1533
#
# advisory: http://pastebin.com/eUucVage
#
##
require 'msf/core'
class Metasploit3 'Sun Java Web Start Double Quote Injection',
'Description' => %q{
This module exploits a flaw in the Web Start component of the Sun Java
Runtime Environment. Parameters intial-heap-size and max-heap-size in a JNLP
file can contain a double quote which is not properly
Exploit-DB
Joomla! 3.0.3 - 'remember.php' PHP Object Injection
exploitdb·2013-04-26·CVSS 5.5
CVE-2013-3242 [MEDIUM] Joomla! 3.0.3 - 'remember.php' PHP Object Injection
Joomla! 3.0.3 - 'remember.php' PHP Object Injection
---
Joomla! decrypt($str);
45. $cookieData = @unserialize($str);
User input passed through cookies is not properly sanitized before being used in an unserialize()
call at line 45. This could be exploited to inject arbitrary PHP objects into the application scope.
Successful exploitation of this vulnerability requires authentication because the attacker needs
to know the "hash string" used to read the cookie parameter at line 36.
[-] Solution:
Upgrade to version 2.5.10, 3.0.4 or 3.1.0.
[-] Disclosure Timeline:
[04/12/2012] - Vendor alerted for a possible vulnerability
[13/02/2013] - Vulnerability confirmed and proof of concept sent to the vendor
[24/04/2013] - Vendor update released
[26/04/2013] - Public disclosure
[-] CVE Refer
Exploit-DB
Google AD Sync Tool - Exposure of Sensitive Information
exploitdb·2013-04-08
Google AD Sync Tool - Exposure of Sensitive Information
Google AD Sync Tool - Exposure of Sensitive Information
---
Sense of Security - Security Advisory - SOS-13-001
Release Date. 03-Apr-2013
Last Update. -
Vendor Notification Date. 03-Sep-2012
Product. Google Active Directory Sync (GADS) Tool
Platform. Windows, Linux, Solaris
Affected versions. All versions up to 3.1.3
Severity Rating. High
Impact. Exposure of sensitive information
Attack Vector. From local without authentication
Solution Status. Upgrade to version 3.1.6
CVE reference. CVE - not yet assigned
Details.
Due to a weakness in the way the Java encryption algorithm
(PBEwithMD5andDES) has been implemented in the GADS tool all
stored credentials can be decrypted into plain-text. This
includes all of the encrypted passwords stored in any end-users
saved XML configuration file, such
Exploit-DB
Ettercap 0.7.5.1 - Stack Overflow
exploitdb·2013-01-07·CVSS 4.4
CVE-2013-0722 [MEDIUM] Ettercap 0.7.5.1 - Stack Overflow
Ettercap 0.7.5.1 - Stack Overflow
---
Title: Ettercap Stack overflow (CWE-121)
References: CVE-2012-0722
Discovered by: Sajjad Pourali
Vendor: http://www.ettercap.sourceforge.net/
Vendor contact: 13-01-01 21:20 UTC (No response)
Solution: Using the patch
Patch: http://www.securation.com/files/2013/01/ec.patch
Local: Yes
Remote: No
Impact: low
Affected:
- ettercap 0.7.5.1
- ettercap 0.7.5
- ettercap 0.7.4 and earlier
Not affected:
- ettercap 0.7.4.1
---
Trace vulnerable place:
./include/ec_inet.h:27-44
enum {
NS_IN6ADDRSZ = 16,
NS_INT16SZ = 2,
ETH_ADDR_LEN = 6,
TR_ADDR_LEN = 6,
FDDI_ADDR_LEN = 6,
MEDIA_ADDR_LEN = 6,
IP_ADDR_LEN = 4,
IP6_ADDR_LEN = 16,
MAX_IP_ADDR_LEN = IP6_ADDR_LEN,
ETH_ASCII_ADDR_LEN = sizeof("ff:ff:ff:ff:ff:ff")+1,
IP_ASCII_ADDR_LEN = sizeof("255.255.255.255")+1
Bugzilla
CVE-2012-4230 tinymce: XSS attacks via security policy bypass
bugzilla·2014-04-25·CVSS 4.3
CVE-2012-4230 [MEDIUM] CVE-2012-4230 tinymce: XSS attacks via security policy bypass
CVE-2012-4230 tinymce: XSS attacks via security policy bypass
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-4230 to
the following vulnerability:
Name: CVE-2012-4230
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4230
Assigned: 20120809
Reference: FULLDISC:20130311 XSS Vulnerability in TinyMCE
Reference: http://seclists.org/fulldisclosure/2013/Mar/114
Reference: http://packetstormsecurity.com/files/120750/TinyMCE-3.5.8-Cross-Site-Scripting.html
Reference: http://www.madirish.net/554
Reference: http://www.securityfocus.com/bid/58424
Reference: OSVDB:91130
Reference: http://osvdb.org/91130
Reference: XF:tinymce-htmlentities-xss(82744)
Reference: http://xforce.iss.net/xforce/xfdb/82744
The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the
TinyM
Bugzilla
CVE-2012-6612 CVE-2013-6407 Apache Solr: XML eXternal Entity (XXE) flaw in XML and XSLT UpdateRequestHandler
bugzilla·2013-11-29·CVSS 7.5
CVE-2012-6612 [HIGH] CVE-2012-6612 CVE-2013-6407 Apache Solr: XML eXternal Entity (XXE) flaw in XML and XSLT UpdateRequestHandler
CVE-2012-6612 CVE-2013-6407 Apache Solr: XML eXternal Entity (XXE) flaw in XML and XSLT UpdateRequestHandler
It was found that the XML and XSLT UpdateRequestHandler classes in Apache Solr would resolve external entities, permitting XXE attacks. A remote attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Discussion:
Upstream Bug:
https://issues.apache.org/jira/browse/SOLR-3895
Upstream Patch:
https://issues.apache.org/jira/secure/attachment/12546766/SOLR-3895%2B3614.patch
---
This issue has been addressed in following products:
Red Hat JBoss Web Framework Kit 2.4.0
Via RHSA-2013:1844 https://rhn.redhat.com/errata/RHSA-2013-1844.html
---
This issue has been addressed in followi
Bugzilla
CVE-2013-4442 pwgen: silent fallback to insecure entropy
bugzilla·2013-10-17·CVSS 5.0
CVE-2013-4442 [MEDIUM] CVE-2013-4442 pwgen: silent fallback to insecure entropy
CVE-2013-4442 pwgen: silent fallback to insecure entropy
Pwgen was found to silently falling back to use standard pseudo generated numbers on the systems that heavily use entropy.
Systems, such as those with a lot of daemons providing encryption services, the entropy was found to be exhausted, which forces pwgen to fall back to use standard pseudo generated numbers.
There seems to be a patch here saying it fixes most of the issues:
http://marc.info/?l=oss-security&m=137049241132104&w=4
References:
http://seclists.org/oss-sec/2013/q4/116
http://www.openwall.com/lists/oss-security/2012/01/17/12
http://marc.info/?l=oss-security&m=137049241132104&w=4
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=672241
http://comments.gmane.org/gmane.comp.security.oss.general/10265
Discussion:
Created
Bugzilla
CVE-2013-2067 CVE-2012-3544 tomcat6 various flaws [fedora-all]
bugzilla·2013-05-10·CVSS 5.0
CVE-2013-2067 [MEDIUM] CVE-2013-2067 CVE-2012-3544 tomcat6 various flaws [fedora-all]
CVE-2013-2067 CVE-2012-3544 tomcat6 various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple s
Bugzilla
CVE-2013-2051 tomcat: DIGEST authentication vulnerable to replay attacks
bugzilla·2013-05-03·CVSS 5.0
CVE-2013-2051 [MEDIUM] CVE-2013-2051 tomcat: DIGEST authentication vulnerable to replay attacks
CVE-2013-2051 tomcat: DIGEST authentication vulnerable to replay attacks
It was found that the fix for CVE-2012-5887 shipped for tomcat 6 on Red Hat Enterprise Linux 6 (RHSA-2013:0623) was incomplete. The fix only allowed DIGEST authentication to succeed when a stale nonce was provided, rather than when a stale nonce was NOT provided. As a result, DIGEST authentication did not function. However, a man-in-the-middle attacker could record a DIGEST authentication exchange, wait until the associated nonce is marked as stale on the server, then successfully replay this request.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0869 https://rhn.redhat.com/errata/RHSA-2013-0869.html
Bugzilla
CVE-2013-0169 CVE-2013-0169 CVE-2012-4929 mingw-openssl various flaws [fedora-all]
bugzilla·2013-03-12·CVSS 2.6
CVE-2013-0169 [LOW] CVE-2013-0169 CVE-2013-0169 CVE-2012-4929 mingw-openssl various flaws [fedora-all]
CVE-2013-0169 CVE-2013-0169 CVE-2012-4929 mingw-openssl various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issu
Bugzilla
CVE-2012-5633 CVE-2013-0239 jbossws-cxf various flaws [fedora-all]
bugzilla·2013-02-08·CVSS 5.8
CVE-2012-5633 [MEDIUM] CVE-2012-5633 CVE-2013-0239 jbossws-cxf various flaws [fedora-all]
CVE-2012-5633 CVE-2013-0239 jbossws-cxf various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multip
Bugzilla
CVE-2012-1541 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
bugzilla·2013-02-01·CVSS 10.0
CVE-2012-1541 [CRITICAL] CVE-2012-1541 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
CVE-2012-1541 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
Java SE 6 Update 39 and Java SE 7 Update 13 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2012-1541). Upstream has CVSSv2 scored this issue as: 10.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0
Bugzilla
CVE-2012-6115 rhev: rhevm-manage-domains logs admin passwords
bugzilla·2013-01-30·CVSS 2.1
CVE-2012-6115 [LOW] CVE-2012-6115 rhev: rhevm-manage-domains logs admin passwords
CVE-2012-6115 rhev: rhevm-manage-domains logs admin passwords
It was discovered that rhevm-manage-domains, when performing validate action,
logged administrative passwords to a world readable log file. A local
attacker could use this flaw to control systems deployed and managed by RHEV.
Upstream commit:
http://gerrit.ovirt.org/gitweb?p=ovirt-engine.git;a=commit;h=e8c72daec4efa8be0fcd8ea55c41e855ddd8eedf
Acknowledgements:
This issue was discovered by Andrew Cathrow of Red Hat.
Discussion:
This issue has been addressed in following products:
RHEV Manager version 3.1
Via RHSA-2013:0211 https://rhn.redhat.com/errata/RHSA-2013-0211.html
Bugzilla
CVE-2013-0199 CVE-2012-4546 freeipa various flaws [fedora-all]
bugzilla·2013-01-23·CVSS 4.3
CVE-2013-0199 [MEDIUM] CVE-2013-0199 CVE-2012-4546 freeipa various flaws [fedora-all]
CVE-2013-0199 CVE-2012-4546 freeipa various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-18 tracking bug for freeipa: see bl
Bugzilla
CVE-2012-5060 mysql: unspecified DoS vulnerability related to GIS (CPU Jan 2013)
bugzilla·2013-01-16·CVSS 6.8
CVE-2012-5060 [MEDIUM] CVE-2012-5060 mysql: unspecified DoS vulnerability related to GIS (CPU Jan 2013)
CVE-2012-5060 mysql: unspecified DoS vulnerability related to GIS (CPU Jan 2013)
An unspecified vulnerability in the GIS extension subcomponent of the MySQL protocol component of the Oracle MySQL server allows remote authenticated attackers to alter availability via unspecified vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Discussion:
According to Oracle CPU data, this issue affected "5.1.65 and earlier, 5.5.27 and earlier", hence it should be fixed in 5.1.66. MySQL packages in Red Hat Enterprise Linux 6 were updated to 5.1.66 via RHSA-2012:1462:
https://rhn.redhat.com/errata/RHSA-2012-1462.html
Bugzilla
CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls
bugzilla·2013-01-04·CVSS 7.5
CVE-2012-6497 [HIGH] CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls
CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-6497 to
the following vulnerability:
Name: CVE-2012-6497
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6497
Assigned: 20130103
Reference: http://openwall.com/lists/oss-security/2013/01/03/12
Reference: http://blog.phusion.nl/2013/01/03/rails-sql-injection-vulnerability-hold-your-horses-here-are-the-facts/
Reference: http://phenoelit.org/blog/archives/2012/12/21/let_me_github_that_for_you/index.html
The Authlogic gem for Ruby on Rails, when used with certain versions
before 3.2.10, makes potentially unsafe find_by_id method calls, which
might allow remote attackers to conduct CVE-2012-6496 SQL injection
attacks via a crafted paramete
Bugzilla
CVE-2012-5604 rubygem-ldap_fluff: CloudForms authentication bypass when handling anonymous LDAP bind
bugzilla·2012-11-30·CVSS 4.3
CVE-2012-5604 [MEDIUM] CVE-2012-5604 rubygem-ldap_fluff: CloudForms authentication bypass when handling anonymous LDAP bind
CVE-2012-5604 rubygem-ldap_fluff: CloudForms authentication bypass when handling anonymous LDAP bind
Og Maciel of Red Hat reports:
After configuring my system to use ActiveDirectory as the authentication
method, I was able to login via the web ui without having to provide a
password when using Windows ADS as the LDAP authentication backend.
Discussion:
Acknowledgements:
This issue was discovered by Og Maciel of Red Hat.
---
This issue did not affect CloudForms 1.0, which did not include this component. The issue is fixed in CloudFroms 1.1. No released version of CloudFroms was affected by this issue.
---
This issue has been addressed in following products:
Red Hat Subscription Asset Manager 1.2
Via RHSA-2013:0544 https://rhn.redhat.com/errata/RHSA-2013-0544.html
2012-06-29
Published