CVE-2013-2013
published 2013-10-01CVE-2013-2013: The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.37%
29.6th percentile
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-keystoneclient | < python-keystoneclient 1:0.2.5-1 (bookworm) | python-keystoneclient 1:0.2.5-1 (bookworm) |
| msrc | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
| msrc | sharepoint_server_subscription_edition_language_pack | — | — |
| openstack | python-keystoneclient | <= 0.2.3 | — |
| openstack | python-keystoneclient | — | — |
| openstack | python-keystoneclient | >= 0 < 1:0.2.5-1 | 1:0.2.5-1 |
| openstack | python-keystoneclient | >= 0 < 1:0.2.5-1 | 1:0.2.5-1 |
| openstack | python-keystoneclient | >= 0 < 1:0.2.5-1 | 1:0.2.5-1 |
| openstack | python-keystoneclient | >= 0 < 1:0.2.5-1 | 1:0.2.5-1 |
| openstack | python-keystoneclient | >= 0 < 0.2.4 | 0.2.4 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
ghsa4.3MEDIUM
osv2.1LOW
vendor_redhat10.0CRITICAL
vendor_msrc8.8HIGH
vendor_cisco7.8HIGH
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
python-keystoneclient unsecure user password update
ghsa·2022-05-17
CVE-2013-2013 [LOW] CWE-200 python-keystoneclient unsecure user password update
python-keystoneclient unsecure user password update
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
OSV
python-keystoneclient unsecure user password update
osv·2022-05-17
CVE-2013-2013 [LOW] python-keystoneclient unsecure user password update
python-keystoneclient unsecure user password update
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
GHSA
Apache ActiveMQ Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet
ghsa·2022-05-17·CVSS 4.3
CVE-2013-1880 [MEDIUM] CWE-79 Apache ActiveMQ Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet
Apache ActiveMQ Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet
Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092.
OSV
CVE-2013-2013: The user-password-update command in python-keystoneclient before 0
osv·2013-10-01·CVSS 2.1
CVE-2013-2013 [LOW] CVE-2013-2013: The user-password-update command in python-keystoneclient before 0
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
Red Hat
openstack-nova: RBAC policy not properly enforced in Nova EC2 API
vendor_redhat·2014-04-09·CVSS 6.0
CVE-2014-0167 [MEDIUM] CWE-862 openstack-nova: RBAC policy not properly enforced in Nova EC2 API
openstack-nova: RBAC policy not properly enforced in Nova EC2 API
The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) add_rules, (2) remove_rules, (3) destroy, and other unspecified methods in compute/api.py when using non-default policies, which allows remote authenticated users to gain privileges via these API requests.
It was found that RBAC policies were not enforced in certain methods of the OpenStack Compute EC2 (Amazon Elastic Compute Cloud) API. A remote attacker could use this flaw to escalate their privileges beyond the user group they were originally restricted to. Note that only certain setups using non-default RBAC rules for OpenStack Compute were affected.
Red Hat
php: multiple vulnerabilities in gdImageCrop()
vendor_redhat·2014-02-06·CVSS 6.8
CVE-2014-2020 [MEDIUM] php: multiple vulnerabilities in gdImageCrop()
php: multiple vulnerabilities in gdImageCrop()
ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in place of a numeric data type, as demonstrated by an imagecrop function call with a string for the x dimension value, a different vulnerability than CVE-2013-7226.
Statement: Not vulnerable. This issue did not affect the versions of php or php53 as shipped with Red Hat Enterprise Linux 5 and 6, and the versions of php54-php as shipped with Red Hat Software Collections 1, as they did not include the vulnerable function (it was introduced in PHP 5.5.0).
Package: php (Red Hat Enterprise Linux 4) - Not affected
Package: gd (Red Hat Enterprise Linux 5) - Not affected
Red Hat
krb5: KDC remote DoS (NULL pointer dereference and daemon crash)
vendor_redhat·2013-11-04·CVSS 4.3
CVE-2013-6800 [MEDIUM] CWE-476 krb5: KDC remote DoS (NULL pointer dereference and daemon crash)
krb5: KDC remote DoS (NULL pointer dereference and daemon crash)
An unspecified third-party database module for the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.10.x allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request, a different vulnerability than CVE-2013-1418.
It was found that if a KDC served multiple realms, certain requests could cause the setup_server_realm() function to dereference a NULL pointer. A remote, unauthenticated attacker could use this flaw to crash the KDC using a specially crafted request.
Package: krb5 (Red Hat Enterprise Linux 7) - Not affected
Red Hat
Gatein: JGroups configurations enable diagnostics without authentication
vendor_redhat·2013-10-16·CVSS 3.3
CVE-2013-2102 [LOW] Gatein: JGroups configurations enable diagnostics without authentication
Gatein: JGroups configurations enable diagnostics without authentication
The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.
Package: Requirements (Red Hat JBoss Portal 5) - Will not fix
Package: Requirements (Red Hat JBoss Portal 6) - Affected
Cisco
Cisco Secure Access Control System Administration Page Cross-Site Scripting Vulnerability
vendor_cisco·2013-07-15·CVSS 4.3
CVE-2013-3422 [MEDIUM] CWE-79 Cisco Secure Access Control System Administration Page Cross-Site Scripting Vulnerability
Cisco Secure Access Control System Administration Page Cross-Site Scripting Vulnerability
A vulnerability in the Administration pages of Cisco Access Control System (ACS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected system.
The vulnerability is due to insufficient input validation of a parameter. An attacker could exploit this vulnerability by convincing the user to access a malicious link.
Cisco has confirmed this vulnerability in a security notice and released software updates.
To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link.
Red Hat
rhevm: insufficient target domain permission check when cloning a VM from a snapshot
vendor_redhat·2013-06-10·CVSS 5.0
CVE-2013-2144 [MEDIUM] rhevm: insufficient target domain permission check when cloning a VM from a snapshot
rhevm: insufficient target domain permission check when cloning a VM from a snapshot
Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attackers to cause a denial of service (disk space consumption) by cloning a VM from a snapshot.
Package: ovirt-engine-backend (Red Hat Enterprise Virtualization 3) - Will not fix
Juniper
CVE-2013-3498: Cross-site scripting (XSS) vulnerability in Juniper SmartPass WLAN Security Management before 7.7 MR3 and 8.0 before MR2 allows remote attackers to in
vendor_juniper·2013-05-08·CVSS 4.3
CVE-2013-3498 [MEDIUM] CWE-79 CVE-2013-3498: Cross-site scripting (XSS) vulnerability in Juniper SmartPass WLAN Security Management before 7.7 MR3 and 8.0 before MR2 allows remote attackers to in
CVE-2013-3498: Cross-site scripting (XSS) vulnerability in Juniper SmartPass WLAN Security Management before 7.7 MR3 and 8.0 before MR2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Red Hat
OpenJDK: MethodUtil trampoline class incorrect restrictions (Libraries, 8009857)
vendor_redhat·2013-04-16·CVSS 10.0
CVE-2013-2422 [CRITICAL] OpenJDK: MethodUtil trampoline class incorrect restrictions (Libraries, 8009857)
OpenJDK: MethodUtil trampoline class incorrect restrictions (Libraries, 8009857)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper method-invocation restrictions by the MethodUtil trampoline class, which allows remote attackers to bypass the Java sandbox.
Cisco
Cisco IOS Software Zone-Based Policy Firewall Session Initiation Protocol Inspection Denial of Service Vulnerability
vendor_cisco·2013-03-27·CVSS 7.8
CVE-2013-1145 [HIGH] CWE-119 Cisco IOS Software Zone-Based Policy Firewall Session Initiation Protocol Inspection Denial of Service Vulnerability
Cisco IOS Software Zone-Based Policy Firewall Session Initiation Protocol Inspection Denial of Service Vulnerability
Cisco IOS Software contains a memory leak vulnerability that could be triggered through the processing of malformed Session Initiation Protocol (SIP) messages. Exploitation of this vulnerability could cause an interruption of services. Only devices that are configured for SIP inspection are affected by this vulnerability.
Cisco has released software updates that address this vulnerability. There are no workarounds for devices that must run SIP inspection.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-cce
Note: The March 27, 2013, Cisco IOS Software Security Advisory bundl
Debian
CVE-2013-2013: python-keystoneclient - The user-password-update command in python-keystoneclient before 0.2.4 accepts t...
vendor_debian·2013·CVSS 2.1
CVE-2013-2013 [LOW] CVE-2013-2013: python-keystoneclient - The user-password-update command in python-keystoneclient before 0.2.4 accepts t...
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
Scope: local
bookworm: resolved (fixed in 1:0.2.5-1)
bullseye: resolved (fixed in 1:0.2.5-1)
forky: resolved (fixed in 1:0.2.5-1)
sid: resolved (fixed in 1:0.2.5-1)
trixie: resolved (fixed in 1:0.2.5-1)
Red Hat
keystone: password disclosure on command line
vendor_redhat·2012-02-22·CVSS 2.1
CVE-2013-2013 [LOW] keystone: password disclosure on command line
keystone: password disclosure on command line
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
Statement: The Red Hat Security Response Team has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
No detection rules found.
Exploit-DB
iScripts AutoHoster - 'id' Local File Inclusion
exploitdb·2013-12-15
CVE-2013-7190 iScripts AutoHoster - 'id' Local File Inclusion
iScripts AutoHoster - 'id' Local File Inclusion
---
source: https://www.securityfocus.com/bid/64377/info
iScripts AutoHoster is prone to multiple security vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit these vulnerabilities to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database, to execute arbitrary commands or script code in the context of the application, and obtain sensitive information that may aid in further attacks.
/support/admin/csvdownload.php
$filename="../csvfiles/".addslashes($_GET["id"]).".txt";
header('Content-Description: File Transfer');
header('Content-Type: application/force-download');
header('Content-Length: ' . filesize($filename));
header('Content-Di
Exploit-DB
vBulletin 4.1.x - '/install/upgrade.php' Security Bypass
exploitdb·2013-10-13
CVE-2013-6129 vBulletin 4.1.x - '/install/upgrade.php' Security Bypass
vBulletin 4.1.x - '/install/upgrade.php' Security Bypass
---
source: https://www.securityfocus.com/bid/62909/info
vBulletin is prone to a security-bypass vulnerability.
Successful exploits can allow attackers to bypass certain security restrictions and perform unauthorized actions.
#!/usr/bin/perl
#
# Title: vBulletin remote admin injection exploit
# Author: Simo Ben youssef
# Contact: Simo_at_Morxploit_com
# Coded: 17 September 2013
# Published: 24 October 2013
# MorXploit Research
# http://www.MorXploit.com
#
# Vendor: vBulletin (www.vbulletin.com)
# Version: 4.1.x / 5.x.x
# Vulnerability: Remote admin injection
# Severity: High
# Status: Confirmed
#
# Exploit code description:
# Perl code to inject a new admin account through upgrade.php script.
#
# Vulnerability details:
# upgrade
Bugzilla
CVE-2013-6668 v8: multiple vulnerabilities in v8 fixed in Google Chrome version 3.24.35.10 [epel-6]
bugzilla·2014-03-11·CVSS 7.5
CVE-2013-6668 [HIGH] CVE-2013-6668 v8: multiple vulnerabilities in v8 fixed in Google Chrome version 3.24.35.10 [epel-6]
CVE-2013-6668 v8: multiple vulnerabilities in v8 fixed in Google Chrome version 3.24.35.10 [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2013-7027 Kernel: wireless: radiotap: parsing buffer overrun
bugzilla·2013-12-10·CVSS 6.1
CVE-2013-7027 [MEDIUM] CVE-2013-7027 Kernel: wireless: radiotap: parsing buffer overrun
CVE-2013-7027 Kernel: wireless: radiotap: parsing buffer overrun
Linux kernel built with the cfg80211 - wireless configuration API
support(CONFIG_CFG80211) is vulnerable to a potential DoS caused by buffer
over-read while parsing wireless packet header.
Upstream fix:
-> https://git.kernel.org/linus/f5563318ff1bde15b10e736e97ffce13be08bc1a
Discussion:
Red Hat does not consider this to be a security flaw. The issue is an OOB read of 4 bytes beyond the "radiotap" header. Though this value is out of header bounds, it is well within the network socket buffer(sk_buff) object. It is not an OOB read which would result in a system crash(DoS) due to invalid read access.
Statement:
The Red Hat Security Response Team does not consider this issue to be a security flaw. For more details please ref
Bugzilla
CVE-2013-7040 python: hash secret can be recovered remotely [fedora-all]
bugzilla·2013-12-10·CVSS 4.3
CVE-2013-7040 [MEDIUM] CVE-2013-7040 python: hash secret can be recovered remotely [fedora-all]
CVE-2013-7040 python: hash secret can be recovered remotely [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-4232 libtiff (tiff2pdf): use-after-free in t2p_readwrite_pdf_image()
bugzilla·2013-08-12·CVSS 6.8
CVE-2013-4232 [MEDIUM] CVE-2013-4232 libtiff (tiff2pdf): use-after-free in t2p_readwrite_pdf_image()
CVE-2013-4232 libtiff (tiff2pdf): use-after-free in t2p_readwrite_pdf_image()
Pedro Ribeiro discovered a use-after-free flaw in the t2p_readwrite_pdf_image() function in tiff2pdf, a tool for converting a TIFF image to a PDF document. A remote attacker could provide a specially-crafted TIFF file that, when processed by tiff2pdf, would cause tiff2pdf to crash or, potentially, execute arbitrary code with the privileges of the user running tiff2pdf.
References:
http://www.asmail.be/msg0055359936.html
http://www.openwall.com/lists/oss-security/2013/08/08/6
Discussion:
Upstream bug: http://bugzilla.maptools.org/show_bug.cgi?id=2449
Proposed patch: http://bugzilla.maptools.org/attachment.cgi?id=513&action=diff
---
This issue affects the version of libtiff as shipped with Red Hat Enterprise
Bugzilla
CVE-2013-4202 openstack-cinder: OpenStack: Cinder Denial of Service using XML entities [fedora-all]
bugzilla·2013-08-08·CVSS 4.3
CVE-2013-4202 [MEDIUM] CVE-2013-4202 openstack-cinder: OpenStack: Cinder Denial of Service using XML entities [fedora-all]
CVE-2013-4202 openstack-cinder: OpenStack: Cinder Denial of Service using XML entities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Pleas
Bugzilla
CVE-2013-3795 mysql: unspecified DoS related to Data Manipulation Language (CPU July 2013)
bugzilla·2013-07-18·CVSS 4.0
CVE-2013-3795 [MEDIUM] CVE-2013-3795 mysql: unspecified DoS related to Data Manipulation Language (CPU July 2013)
CVE-2013-3795 mysql: unspecified DoS related to Data Manipulation Language (CPU July 2013)
Unspecified vulnerability in the MySQL Server component in Oracle
MySQL 5.6.11 and earlier allows remote authenticated users to affect
availability via unknown vectors related to Data Manipulation
Language.
External References:
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html#AppendixMSQL
Discussion:
Statement:
Not vulnerable. This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 5 and 6.
---
This issue has been addressed in Fedora-18 (mysql) and Fedora-19 (community-mysql) via the following security updates:
https://admin.fedoraproject.org/updates/FEDORA-2013-11108/mysql-5.5.32-1.fc18
https://admin.fedoraproject.org/updates/FEDORA
Bugzilla
CVE-2013-2157 openstack-keystone: Authentication bypass when using LDAP backend [fedora-all]
bugzilla·2013-06-17·CVSS 4.3
CVE-2013-2157 [MEDIUM] CVE-2013-2157 openstack-keystone: Authentication bypass when using LDAP backend [fedora-all]
CVE-2013-2157 openstack-keystone: Authentication bypass when using LDAP backend [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note:
Bugzilla
CVE-2013-2013 OpenStack keystone: password disclosure on command line [fedora-rawhide]
bugzilla·2013-06-07·CVSS 2.1
CVE-2013-2013 [LOW] CVE-2013-2013 OpenStack keystone: password disclosure on command line [fedora-rawhide]
CVE-2013-2013 OpenStack keystone: password disclosure on command line [fedora-rawhide]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-rawhide tra
Bugzilla
CVE-2013-2013 OpenStack keystone: password disclosure on command line [RDO]
bugzilla·2013-06-07·CVSS 2.1
CVE-2013-2013 [LOW] CVE-2013-2013 OpenStack keystone: password disclosure on command line [RDO]
CVE-2013-2013 OpenStack keystone: password disclosure on command line [RDO]
(Kurt, I hope you're ok with this manual CVE clone, I've edited description to fit RDO i.e. no Bodhi etc.)
+++ This bug was initially created as a clone of Bug #957035 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of RDO.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
Please also mention the CVE IDs being fixed in the RPM changelog.
RDO tracking bug for openstack-keystone: see blocks bug list for full details of the security issue(s).
[bug MANUALLY created by: apevec]
Discussion:
(In reply to Alan Pevec fr
Bugzilla
CVE-2013-1872 Mesa: Memory corruption (OOB read/write) on intel drivers [fedora-all]
bugzilla·2013-06-03·CVSS 6.8
CVE-2013-1872 [MEDIUM] CVE-2013-1872 Mesa: Memory corruption (OOB read/write) on intel drivers [fedora-all]
CVE-2013-1872 Mesa: Memory corruption (OOB read/write) on intel drivers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this is
Bugzilla
CVE-2013-2013 OpenStack keystone: password disclosure on command line [epel-6]
bugzilla·2013-04-26·CVSS 2.1
CVE-2013-2013 [LOW] CVE-2013-2013 OpenStack keystone: password disclosure on command line [epel-6]
CVE-2013-2013 OpenStack keystone: password disclosure on command line [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug f
Bugzilla
CVE-2013-2013 OpenStack keystone: password disclosure on command line
bugzilla·2013-04-26·CVSS 2.1
CVE-2013-2013 [LOW] CVE-2013-2013 OpenStack keystone: password disclosure on command line
CVE-2013-2013 OpenStack keystone: password disclosure on command line
Jake Dahn reports:
Updating password via CLI should be done via a secure password prompt, not text.
current: keystone user-password-update --user=jake --password=foo
expected: keystone user-password-update --user=jake
Password:
Repeat Password:
OpenStack keystone places a username and password on the command line,
which allows local users to obtain credentials by listing the process.
Discussion:
Created openstack-keystone tracking bugs for this issue
Affects: fedora-all [bug 957034]
---
Created openstack-keystone tracking bugs for this issue
Affects: epel-6 [bug 957035]
---
Upstream RFE
https://blueprints.launchpad.net/python-keystoneclient/+spec/prompt-for-password
---
Jeremy Stanley ([email protected]
Bugzilla
CVE-2013-2013 OpenStack keystone: password disclosure on command line [fedora-all]
bugzilla·2013-04-26·CVSS 2.1
CVE-2013-2013 [LOW] CVE-2013-2013 OpenStack keystone: password disclosure on command line [fedora-all]
CVE-2013-2013 OpenStack keystone: password disclosure on command line [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issu
Bugzilla
CVE-2013-1934 mantis: XSS on the Configuration Report page when displaying complex value
bugzilla·2013-04-05·CVSS 5.4
CVE-2013-1934 [MEDIUM] CVE-2013-1934 mantis: XSS on the Configuration Report page when displaying complex value
CVE-2013-1934 mantis: XSS on the Configuration Report page when displaying complex value
A cross-site scripting (XSS) flaw was found in the way MantisBT, a web-based issue tracking system, sanitized content of certain configuration options prior displaying them ('complex' configuration options containing JavaScript were not sanitized properly previously). A remote attacker could provide a specially-crafted URL that, when visited would lead to arbitrary HTML or web script execution in the context of the MantisBT user's session.
References:
[1] http://www.openwall.com/lists/oss-security/2013/04/04/8
Upstream ticket:
[2] http://www.mantisbt.org/bugs/view.php?id=15416
Upstream patch:
[3] http://github.com/mantisbt/mantisbt/commit/5858a659efe12743b4360da11e9320c7f6ac6e82 (against 1.2.x bran
Bugzilla
CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems [fedora-all]
bugzilla·2013-03-25·CVSS 5.0
CVE-2013-0211 [MEDIUM] CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems [fedora-all]
CVE-2013-0211 libarchive: read buffer overflow on 64-bit systems [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue aff
Bugzilla
CVE-2013-0312 389-ds: unauthenticated denial of service vulnerability in handling of LDAPv3 control data [fedora-all]
bugzilla·2013-03-11·CVSS 5.0
CVE-2013-0312 [MEDIUM] CVE-2013-0312 389-ds: unauthenticated denial of service vulnerability in handling of LDAPv3 control data [fedora-all]
CVE-2013-0312 389-ds: unauthenticated denial of service vulnerability in handling of LDAPv3 control data [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when
Bugzilla
CVE-2013-1828 kernel: sctp: SCTP_GET_ASSOC_STATS stack buffer overflow [fedora-all]
bugzilla·2013-03-08·CVSS 6.9
CVE-2013-1828 [MEDIUM] CVE-2013-1828 kernel: sctp: SCTP_GET_ASSOC_STATS stack buffer overflow [fedora-all]
CVE-2013-1828 kernel: sctp: SCTP_GET_ASSOC_STATS stack buffer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this iss
Bugzilla
CVE-2013-1828 kernel: sctp: SCTP_GET_ASSOC_STATS stack buffer overflow
bugzilla·2013-03-08·CVSS 6.9
CVE-2013-1828 [MEDIUM] CVE-2013-1828 kernel: sctp: SCTP_GET_ASSOC_STATS stack buffer overflow
CVE-2013-1828 kernel: sctp: SCTP_GET_ASSOC_STATS stack buffer overflow
A local user could use the missing size check in sctp_getsockopt_assoc_stats() function to escalate their privileges. On x86 this might be mitigated by destination object size check as the destination size is known at compile time.
Upstream fix:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=726bc6b0
Introduced by:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=196d6759
Introduced in:
v3.8-rc1
References:
https://twitter.com/grsecurity/status/309805924749541376
http://grsecurity.net/~spender/sctp.c
Discussion:
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 919316]
---
Statement:
Not vulnerable.
This issue did not affect the versions
Bugzilla
CVE-2013-0231 kernel: xen: pciback DoS via not rate limited log messages [fedora-all]
bugzilla·2013-02-13·CVSS 4.9
CVE-2013-0231 [MEDIUM] CVE-2013-0231 kernel: xen: pciback DoS via not rate limited log messages [fedora-all]
CVE-2013-0231 kernel: xen: pciback DoS via not rate limited log messages [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this i
Bugzilla
CVE-2013-0159 predictable file name used in /tmp to generate pdf output [fedora-all]
bugzilla·2013-01-06·CVSS 7.1
CVE-2013-0159 [HIGH] CVE-2013-0159 predictable file name used in /tmp to generate pdf output [fedora-all]
CVE-2013-0159 predictable file name used in /tmp to generate pdf output [fedora-all]
Created attachment 673347
use a proper temporary random filename, and clean file after
fedora-business-cards use a temporary file named /tmp/fedora-business-cards-buffer.svg.
Since /tmp is world writable, anyone could either block the script with a suitable file ( ie, the same filename, with restrictive permission ), or using symlink, could overwrite one of the file of someone else running the script ( ln -s ~yourlogin/.ssh/id_rsa.pub /tmp/fedora-business-cards-buffer.svg )
( for the record, the last case should be blocked on Linux with 3.6 and fs.protected_symlinks turned on ).
Here is a patch that should fix the issue against latest HEAD.
No CVE have been assigned so far, and AFAIK, packager is al
http://www.openwall.com/lists/oss-security/2013/05/23/4https://bugs.launchpad.net/python-keystoneclient/+bug/938315https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16937http://www.openwall.com/lists/oss-security/2013/05/23/4https://bugs.launchpad.net/python-keystoneclient/+bug/938315https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16937
2013-10-01
Published