CVE-2014-0003
published 2014-03-21CVE-2014-0003: The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java…
PriorityP349high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.35%
93.7th percentile
The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | <= 2.11.3 | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_apache7.5CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Camel's XSLT component allows remote attackers to execute arbitrary Java methods
osv·2018-10-16
CVE-2014-0003 [HIGH] Apache Camel's XSLT component allows remote attackers to execute arbitrary Java methods
Apache Camel's XSLT component allows remote attackers to execute arbitrary Java methods
The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.
GHSA
Apache Camel's XSLT component allows remote attackers to execute arbitrary Java methods
ghsa·2018-10-16
CVE-2014-0003 [HIGH] CWE-502 Apache Camel's XSLT component allows remote attackers to execute arbitrary Java methods
Apache Camel's XSLT component allows remote attackers to execute arbitrary Java methods
The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.
Red Hat
Camel: remote code execution via XSL
vendor_redhat·2014-02-28·CVSS 7.5
CVE-2014-0003 [HIGH] Camel: remote code execution via XSL
Camel: remote code execution via XSL
The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.
Apache
Apache camel: CVE-2014-0003
vendor_apache·CVSS 7.5
CVE-2014-0003 [CRITICAL] Apache camel: CVE-2014-0003
Apache camel: CVE-2014-0003
2.11.0 up to 2.11.3, 2.12.0 up to 2.12.2 2.11.4, 2.12.3, 2.13.0 and newer CRITICAL The Apache Camel XSLT component allows XSL stylesheets to perform calls to external Java methods.
Severity: critical
No detection rules found.
Exploit-DB
FreeBSD - Multiple Vulnerabilities
exploitdb·2015-01-29·CVSS 7.2
CVE-2014-8612 [HIGH] FreeBSD - Multiple Vulnerabilities
FreeBSD - Multiple Vulnerabilities
---
Core Security - Corelabs Advisory
http://corelabs.coresecurity.com/
FreeBSD Kernel Multiple Vulnerabilities
1. *Advisory Information*
Title: FreeBSD Kernel Multiple Vulnerabilities
Advisory ID: CORE-2015-0003
Advisory URL: http://www.coresecurity.com/content/freebsd-kernel-multiple-vulnerabilities
Date published: 2015-01-27
Date of last update: 2015-01-27
Vendors contacted: FreeBSD
Release mode: Coordinated release
2. *Vulnerability Information*
Class: Unsigned to Signed Conversion Error [CWE-196], Improper Validation of Array Index [CWE-129], Improper Validation of Array Index [CWE-129]
Impact: Code execution, Denial of service
Remotely Exploitable: No
Locally Exploitable: Yes
CVE Name: CVE-2014-0998, CVE-2014-8612, CVE-2014-8612
3. *Vulne
Exploit-DB
SAP Router - Timing Attack Password Disclosure
exploitdb·2014-04-17·CVSS 4.3
CVE-2014-0984 [MEDIUM] SAP Router - Timing Attack Password Disclosure
SAP Router - Timing Attack Password Disclosure
---
Core Security - Corelabs Advisory
http://corelabs.coresecurity.com/
SAP Router Password Timing Attack
1. *Advisory Information*
Title: SAP Router Password Timing Attack
Advisory ID: CORE-2014-0003
Advisory URL:
http://www.coresecurity.com/advisories/sap-router-password-timing-attack
Date published: 2014-04-15
Date of last update: 2014-03-06
Vendors contacted: SAP
Release mode: Coordinated release
2. *Vulnerability Information*
Class: Information Exposure Through Timing Discrepancy [CWE-208]
Impact: Security bypass
Remotely Exploitable: Yes
Locally Exploitable: No
CVE Name: CVE-2014-0984
3. *Vulnerability Description*
SAP Router [1] is an application-level gateway used to
connect systems in a SAP infrastructure. A vulnerability
Bugzilla
CVE-2014-8092 xorg-x11-server: integer overflow in X11 core protocol requests when calculating memory needs for requests
bugzilla·2014-11-27·CVSS 6.5
CVE-2014-8092 [MEDIUM] CVE-2014-8092 xorg-x11-server: integer overflow in X11 core protocol requests when calculating memory needs for requests
CVE-2014-8092 xorg-x11-server: integer overflow in X11 core protocol requests when calculating memory needs for requests
ProcPutImage(), GetHosts(), RegionSizeof(), REQUEST_FIXED_SIZE() calls do not check that their calculations for how much memory
is needed to handle the client's request have not overflowed, so can
result in out of bounds reads or writes. These calls all occur only
after a client has successfully authenticated itself.
Introduced in X11R1 (1987).
Discussion:
Created attachment 962113
0002-dix_integer_overflow_in_ProcPutImage_CVE-2014-8092_1-4.patch
---
Created attachment 962114
0003-dix_integer_overflow_in_GetHosts_CVE-2014-8092_2-4.patch
---
Created attachment 962115
0004-dix_integer_overflow_in_RegionSizeof_CVE-2014-8092_3-4.patch
---
Created attachment 962116
Bugzilla
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw
bugzilla·2014-11-11·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw
Florian Weimer from Red Hat has reported the below issue:
mailx executes shell commands embedded in syntactically valid mail addresses due a not quoted command to prevent word expansion.
fio.c
542 }
543 snprintf(cmdbuf, sizeof cmdbuf, "echo %s", name);
544 if ((shell = value("SHELL")) == NULL)
545 shell = SHELL;
The original report in Debian bugtracker:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278748
Discussion:
Created attachment 958222
0001-outof-Introduce-expandaddr-flag.patch
---
Created attachment 958223
0002-unpack-Disable-option-processing-for-email-addresses.patch
---
Created attachment 958224
0003-fio.c-Unconditionally-require-wordexp-support.patch
---
Created attachment 958225
0004-globname-Invoke-wor
Bugzilla
CVE-2014-0010 moodle: Cross-Site Request Forgery (CSRF) flaws in profile fields (MSA-14-0003)
bugzilla·2014-01-13·CVSS 6.8
CVE-2014-0010 [MEDIUM] CVE-2014-0010 moodle: Cross-Site Request Forgery (CSRF) flaws in profile fields (MSA-14-0003)
CVE-2014-0010 moodle: Cross-Site Request Forgery (CSRF) flaws in profile fields (MSA-14-0003)
Jun Zhu found that some profile fields were vulnerable to Cross-Site Request Forgery (CSRF). An attacker could use these flaws to perform actions on profiles (such as deleting categories). These issues affected Moodle versions 2.6, 2.5 to 2.5.4, 2.4 to 2.4.7, 2.3 to 2.3.10 and earlier unsupported versions. It has been fixed in 2.6.1, 2.5.4, 2.4.8 and 2.3.11.
I have not checked if versions 1.9.19 in EPEL 5 is affected or not.
Patch:
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-42883
Discussion:
Created moodle tracking bugs for this issue:
Affects: fedora-all [bug 1055388]
Affects: epel-all [bug 1055390]
---
Upstream announcement:
https://moodle.org/mod/forum/discu
Bugzilla
CVE-2014-0003 Camel: remote code execution via XSL
bugzilla·2014-01-08·CVSS 7.5
CVE-2014-0003 [HIGH] CVE-2014-0003 Camel: remote code execution via XSL
CVE-2014-0003 Camel: remote code execution via XSL
It was found that the Apache Camel XSLT component allowed XSL stylesheets to perform calls to external Java methods. A remote attacker able to submit messages to an xslt: Camel route could use this flaw to perform arbitrary remote code execution in the context of the Camel server process.
Discussion:
Acknowledgements:
This issue was discovered by David Jorm of the Red Hat Security Response Team.
---
Upstream bugs:
https://issues.apache.org/jira/browse/CAMEL-7123
https://issues.apache.org/jira/browse/CAMEL-7129
Upstream patch commits:
https://fisheye6.atlassian.com/changelog/camel-git?cs=e922f89290f236f3107039de61af0375826bd96d
https://fisheye6.atlassian.com/changelog/camel-git?cs=2639264b28940683dfc808bf8edfb41bbceb7ad7
https://fi
http://camel.apache.org/security-advisories.data/CVE-2014-0003.txt.aschttp://rhn.redhat.com/errata/RHSA-2014-0245.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0254.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0371.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0372.htmlhttp://secunia.com/advisories/57125http://secunia.com/advisories/57716http://secunia.com/advisories/57719http://www.securityfocus.com/bid/65902https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3Ehttp://camel.apache.org/security-advisories.data/CVE-2014-0003.txt.aschttp://rhn.redhat.com/errata/RHSA-2014-0245.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0254.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0371.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0372.htmlhttp://secunia.com/advisories/57125http://secunia.com/advisories/57716http://secunia.com/advisories/57719http://www.securityfocus.com/bid/65902https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
2014-03-21
Published