CVE-2013-1020
published 2013-05-24CVE-2013-1020: Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JPEG data in a…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.33%
87.4th percentile
Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JPEG data in a movie file.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | quicktime | <= 7.7.3 | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gc6q-4w8w-q6mp: Apple QuickTime before 7
ghsa_unreviewed·2022-05-17
CVE-2013-1020 [HIGH] GHSA-gc6q-4w8w-q6mp: Apple QuickTime before 7
Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JPEG data in a movie file.
Kernel
x86, cpu, amd: Add workaround for family 16h, erratum 793
kernel_security·2014-01-15·CVSS 4.7
CVE-2013-6885 [MEDIUM] x86, cpu, amd: Add workaround for family 16h, erratum 793
x86, cpu, amd: Add workaround for family 16h, erratum 793
This adds the workaround for erratum 793 as a precaution in case not
every BIOS implements it. This addresses CVE-2013-6885.
Erratum text:
[Revision Guide for AMD Family 16h Models 00h-0Fh Processors,
document 51810 Rev. 3.04 November 2013]
793 Specific Combination of Writes to Write Combined Memory Types and
Locked Instructions May Cause Core Hang
Description
Under a highly specific and detailed set of internal timing
conditions, a locked instruction may trigger a timing sequence whereby
the write to a write combined memory type is not flushed, causing the
locked instruction to stall indefinitely.
Potential Effect on System
Processor core hang.
Suggested Workaround
BIOS should set MSR
C001_1020[15] = 1b.
Fix Planned
No
No detection rules found.
Bugzilla
CVE-2014-3464 JBoss WS: Incomplete fix for CVE-2013-2133
bugzilla·2014-05-28·CVSS 5.5
CVE-2014-3464 [MEDIUM] CVE-2014-3464 JBoss WS: Incomplete fix for CVE-2013-2133
CVE-2014-3464 JBoss WS: Incomplete fix for CVE-2013-2133
IssueDescription:
It was found that the fix for CVE-2013-2133 was incomplete: the JAX-WS handlers were being executed for outbound messages even when authorization had failed. A remote attacker who is authorized to access the EJB class, could invoke a JAX-WS handler which they were not authorized to invoke.
Discussion:
Acknowledgement:
This issue was discovered by Tomas Kyjovsky of the Red Hat Quality Engineering Team.
---
This issue has been addressed in following products:
JBoss Enterprise Application Platform 6.3.0
Via RHSA-2014:1021 https://rhn.redhat.com/errata/RHSA-2014-1021.html
---
This issue has been addressed in following products:
JBEAP 6 for RHEL 6
Via RHSA-2014:1020 https://rhn.redhat.com/errata/RHSA-2014-10
Bugzilla
CVE-2013-6885 hw: AMD CPU erratum may cause core hang
bugzilla·2013-11-28·CVSS 4.7
CVE-2013-6885 [MEDIUM] CVE-2013-6885 hw: AMD CPU erratum may cause core hang
CVE-2013-6885 hw: AMD CPU erratum may cause core hang
793 Specific Combination of Writes to Write Combined Memory
Types and Locked Instructions May Cause Core Hang
Under a highly specific and detailed set of internal timing
conditions, a locked instruction may trigger a timing sequence whereby
the write to a write combined memory type is not flushed, causing the
locked instruction to stall indefinitely.
Potential Effect on System
Processor core hang.
Suggested Workaround
BIOS should set MSRC001_1020[15] = 1b.
The vulnerability is applicable only to family 16h model 00h-0fh AMD
CPUs. Non-AMD CPUs are not vulnerable.
References:
http://support.amd.com/TechDocs/51810_16h_00h-0Fh_Rev_Guide.pdf
http://thread.gmane.org/gmane.comp.security.oss.general/11555
Acknowledgements:
Red Hat would
http://lists.apple.com/archives/security-announce/2013/May/msg00001.htmlhttp://support.apple.com/kb/HT5770https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16365http://lists.apple.com/archives/security-announce/2013/May/msg00001.htmlhttp://support.apple.com/kb/HT5770https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16365
2013-05-24
Published