CVE-2014-2015
published 2014-11-02CVE-2014-2015: Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x…
PriorityP340high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.91%
89.1th percentile
Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and earlier, might allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password hash, as demonstrated by an SSHA hash.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeradius | < freeradius 2.2.5+dfsg-0.1 (bookworm) | freeradius 2.2.5+dfsg-0.1 (bookworm) |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4w6w-6xrm-w35q: Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap
ghsa_unreviewed·2022-05-14
CVE-2014-2015 [HIGH] CWE-119 GHSA-4w6w-6xrm-w35q: Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap
Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and earlier, might allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password hash, as demonstrated by an SSHA hash.
OSV
libvirt vulnerabilities
osv·2016-01-12·CVSS 5.9
CVE-2011-4600 libvirt vulnerabilities
libvirt vulnerabilities
It was discovered that libvirt incorrectly handled the firewall rules on
bridge networks when the daemon was restarted. This could result in an
unintended firewall configuration. This issue only applied to Ubuntu 12.04
LTS. (CVE-2011-4600)
Peter Krempa discovered that libvirt incorrectly handled locking when
certain ACL checks failed. A local attacker could use this issue to cause
libvirt to stop responding, resulting in a denial of service. This issue
only applied to Ubuntu 14.04 LTS. (CVE-2014-8136)
Luyao Huang discovered that libvirt incorrectly handled VNC passwords in
shapshot and image files. A remote authenticated user could use this issue
to possibly obtain VNC passwords. This issue only affected Ubuntu 14.04
LTS. (CVE-2015-0236)
Han Han discovered that
OSV
php5 vulnerabilities
osv·2015-02-17·CVSS 7.5
CVE-2014-8142 php5 vulnerabilities
php5 vulnerabilities
Stefan Esser discovered that PHP incorrectly handled unserializing objects.
A remote attacker could use this issue to cause PHP to crash, resulting in
a denial of service, or possibly execute arbitrary code. (CVE-2014-8142,
CVE-2015-0231)
Brian Carpenter discovered that the PHP CGI component incorrectly handled
invalid files. A local attacker could use this issue to obtain sensitive
information, or possibly execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 14.10. (CVE-2014-9427)
It was discovered that PHP incorrectly handled certain pascal strings in
the fileinfo extension. A remote attacker could possibly use this issue to
cause PHP to crash, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS and Ubuntu 14.10. (CV
OSV
CVE-2014-2015: Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap
osv·2014-11-02·CVSS 7.5
CVE-2014-2015 [HIGH] CVE-2014-2015: Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap
Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and earlier, might allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password hash, as demonstrated by an SSHA hash.
Red Hat
openstack-nova: network security group changes are not applied to running instances
vendor_redhat·2015-10-05·CVSS 5.0
CVE-2015-7713 [MEDIUM] CWE-285 openstack-nova: network security group changes are not applied to running instances
openstack-nova: network security group changes are not applied to running instances
OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.
A vulnerability was discovered in the way OpenStack Compute (nova) networking handled security group updates; changes were not applied to already running VM instances. A remote attacker could use this flaw to access running VM instances.
Red Hat
openstack-nova: Nova instance migration process does not stop when instance is deleted
vendor_redhat·2015-06-15·CVSS 6.8
CVE-2015-3241 [MEDIUM] CWE-400 openstack-nova: Nova instance migration process does not stop when instance is deleted
openstack-nova: Nova instance migration process does not stop when instance is deleted
OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance.
A denial of service flaw was found in the OpenStack Compute (nova) instance migration process. Because the migration process does not terminate when an instance is deleted, an authenticated user could bypass user quota and deplete all available disk space by repeatedly re-sizing and deleting an instance.
Red Hat
Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
vendor_redhat·2015-03-03·CVSS 3.5
CVE-2015-0284 [LOW] CWE-79 Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
A cross-site scripting (XSS) flaw was found in how XML data was handled in Red Hat Satellite. A user able to use the XMLRPC API could exploit this flaw to perform XSS attacks against other Satellite users.
Package: Server (Red Hat Satellite 5.6) - Will not fix
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 6.8
CVE-2014-1323 [MEDIUM] webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 6.8
CVE-2014-1341 [MEDIUM] webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux
Ubuntu
FreeRADIUS vulnerabilities
vendor_ubuntu·2014-02-26·CVSS 6.0
CVE-2011-4966 [MEDIUM] FreeRADIUS vulnerabilities
Title: FreeRADIUS vulnerabilities
Summary: Several security issues were fixed in FreeRADIUS.
It was discovered that FreeRADIUS incorrectly handled unix authentication.
A remote user could successfully authenticate with an expired password.
(CVE-2011-4966)
Pierre Carrier discovered that FreeRADIUS incorrectly handled rlm_pap
hash processing. An authenticated user could use this issue to cause
FreeRADIUS to crash, resulting in a denial of service, or possibly execute
arbitrary code. The default compiler options for affected releases should
reduce the vulnerability to a denial of service. (CVE-2014-2015)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
freeradius: stack-based buffer overflow flaw in rlm_pap module
vendor_redhat·2014-02-12·CVSS 7.5
CVE-2014-2015 [HIGH] CWE-121 freeradius: stack-based buffer overflow flaw in rlm_pap module
freeradius: stack-based buffer overflow flaw in rlm_pap module
Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and earlier, might allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password hash, as demonstrated by an SSHA hash.
A stack-based buffer overflow was found in the way the FreeRADIUS rlm_pap module handled long password hashes. An attacker able to make radiusd process a malformed password hash could cause the daemon to crash.
Statement: This issue affects the versions of freeradius2 as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and mainte
Debian
CVE-2014-2015: freeradius - Stack-based buffer overflow in the normify function in the rlm_pap module (modul...
vendor_debian·2014·CVSS 7.5
CVE-2014-2015 [HIGH] CVE-2014-2015: freeradius - Stack-based buffer overflow in the normify function in the rlm_pap module (modul...
Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and earlier, might allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password hash, as demonstrated by an SSHA hash.
Scope: local
bookworm: resolved (fixed in 2.2.5+dfsg-0.1)
bullseye: resolved (fixed in 2.2.5+dfsg-0.1)
forky: resolved (fixed in 2.2.5+dfsg-0.1)
sid: resolved (fixed in 2.2.5+dfsg-0.1)
trixie: resolved (fixed in 2.2.5+dfsg-0.1)
Suricata
ET WEB_SERVER Possible CVE-2014-6271 Attempt
suricata·2015-11-04·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET WEB_SERVER Possible CVE-2014-6271 Attempt
ET WEB_SERVER Possible CVE-2014-6271 Attempt
Rule: alert tcp any any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SERVER Possible CVE-2014-6271 Attempt"; flow:established,to_server; content:" HTTP/1."; pcre:"/^[^\r\n]*?HTTP\/1(?:(?!\r?\n\r?\n)[\x20-\x7e\s]){1,500}\n[\x20-\x7e]{1,100}\x3a[\x20-\x7e]{0,500}\x28\x29\x20\x7b/s"; content:"|28 29 20 7b|"; fast_pattern; reference:url,blogs.akamai.com/2014/09/environment-bashing.html; classtype:attempted-admin; sid:2022028; rev:2; metadata:created_at 2015_11_04, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2019_10_08;)
Exploit-DB
AirLive (Multiple Products) - OS Command Injection
exploitdb·2015-07-08·CVSS 9.8
CVE-2015-2279 [CRITICAL] AirLive (Multiple Products) - OS Command Injection
AirLive (Multiple Products) - OS Command Injection
---
1. Advisory Information
Title: AirLive Multiple Products OS Command Injection
Advisory ID: CORE-2015-0012
Advisory URL: http://www.coresecurity.com/advisories/airlive-multiple-products-os-command-injection
Date published: 2015-07-06
Date of last update: 2015-07-06
Vendors contacted: AirLive
Release mode: User release
2. Vulnerability Information
Class: OS Command Injection [CWE-78], OS Command Injection [CWE-78]
Impact: Code execution
Remotely Exploitable: Yes
Locally Exploitable: No
CVE Name: CVE-2015-2279, CVE-2014-8389
3. Vulnerability Description
AirLive MD-3025 [3], BU-3026 [4], BU-2015 [2], WL-2000CAM [5] and POE-200CAM [6] are IP cameras designed for professional surveillance and security applications. The built-in IR L
Exploit-DB
Persistent Systems Client Automation - Command Injection Remote Code Execution (Metasploit)
exploitdb·2015-02-27·CVSS 10.0
CVE-2015-1497 [CRITICAL] Persistent Systems Client Automation - Command Injection Remote Code Execution (Metasploit)
Persistent Systems Client Automation - Command Injection Remote Code Execution (Metasploit)
---
# Exploit Title: Persistent Systems Client Automation (PSCA, formerly HPCA or Radia) Command Injection Remote Code Execution Vulnerability
# Date: 2014-10-01
# Exploit Author: Ben Turner
# Vendor Homepage: Previosuly HP, now http://www.persistentsys.com/
# Version: 7.9, 8.1, 9.0, 9.1
# Tested on: Windows XP, Windows 7, Server 2003 and Server 2008
# CVE-2015-1497
# CVSS: 10
require 'msf/core'
class Metasploit3 'Persistent Systems Client Automation (PSCA, formerly HPCA or Radia) Command Injection Remote Code Execution Vulnerability',
'Description' => %Q{
This module exploits PS Client Automation, by sending a remote service install and creating a callback payload.
},
'Author' => [ 'Ben Turner'
Exploit-DB
Lorex LH300 Series - ActiveX Buffer Overflow (PoC)
exploitdb·2015-01-18
CVE-2014-1201 Lorex LH300 Series - ActiveX Buffer Overflow (PoC)
Lorex LH300 Series - ActiveX Buffer Overflow (PoC)
---
Disclosure: 09/01/2014 / Last updated: 18/01/2015
Hi,
I have discovered a buffer overflow vulnerability that allows remote code execution in an ActiveX control bundled by a manufacturer of video surveillance systems.
The company is Lorex Technologies, a major video surveillance manufacturer that is very popular in the US and East Asia. Their affected product range is the EDGE series, which has 16 products in it. I have confirmed that all 16 are vulnerable at this point in time. These security DVR's are remotely accessible, and when you access it on a Windows computer with Internet Explorer, they try to install the vulnerable ActiveX control INetViewX. The Lorex manual[1] instructs the user to blindly accept the ActiveX control ins
Bugzilla
CVE-2015-7540 samba: DoS to AD-DC due to insufficient checking of asn1 memory allocation
bugzilla·2015-12-04·CVSS 7.5
CVE-2015-7540 [HIGH] CVE-2015-7540 samba: DoS to AD-DC due to insufficient checking of asn1 memory allocation
CVE-2015-7540 samba: DoS to AD-DC due to insufficient checking of asn1 memory allocation
A denial-of-service vulnerability for the AD-DC due to insuffiecient checking on asn1 memory allocation was reported.
Upstream bug:
https://bugzilla.samba.org/show_bug.cgi?id=9187
Discussion:
Created samba tracking bugs for this issue:
Affects: fedora-all [bug 1292069]
---
External References:
https://www.samba.org/samba/security/CVE-2015-7540.html
---
Upstream fixes as applied to 4.1.22:
https://git.samba.org/?p=samba.git;a=commitdiff;h=530d50a1abdcdf4d1775652d4c456c1274d83d8d
https://git.samba.org/?p=samba.git;a=commitdiff;h=9d989c9dd7a5b92d0c5d65287935471b83b6e884
Upstream advisory also indicates that newer samba versions (4.2+) were already fixed in Sep 2014.
---
This issue has been
Bugzilla
CVE-2015-5240 openstack-neutron: Firewall rules bypass through port update
bugzilla·2015-08-31·CVSS 3.5
CVE-2015-5240 [LOW] CVE-2015-5240 openstack-neutron: Firewall rules bypass through port update
CVE-2015-5240 openstack-neutron: Firewall rules bypass through port update
It was reported that a vulnerability was found in Neutron. By changing the device owner of an instance's port right after it is created, an authenticated user may prevent application of firewall rules and so avoid IP anti-spoofing controls. All Neutron setups using the ML2 plugin or a plugin that relies on the security groups AMQP API are affected. All Neutron setups using the ML2 plugin or a plugin that relies on the security groups AMQP API are affected.
Vulnerability affects versions through 2014.2.3 and 2015.1 versions through 2015.1.1
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Kevin Benton from Mirantis as the original reporter.
Disc
Bugzilla
CVE-2015-6525 libevent: multiple integer overflows in the evbuffer APIs
bugzilla·2015-08-25·CVSS 7.5
CVE-2015-6525 [HIGH] CVE-2015-6525 libevent: multiple integer overflows in the evbuffer APIs
CVE-2015-6525 libevent: multiple integer overflows in the evbuffer APIs
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the:
(1) evbuffer_add,
(2) evbuffer_prepend,
(3) evbuffer_expand,
(4) exbuffer_reserve_space, or
(5) evbuffer_read function,
which triggers a heap-based buffer overflow or an infinite loop.
NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
References:
http://archives.seul.org/libevent/users/Jan-2015/msg00010.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6525
Discussion:
Created libevent tracking bugs for this issu
Bugzilla
CVE-2015-3221 openstack-neutron: L2 agent DoS through incorrect allowed address pairs
bugzilla·2015-06-16·CVSS 4.0
CVE-2015-3221 [MEDIUM] CVE-2015-3221 openstack-neutron: L2 agent DoS through incorrect allowed address pairs
CVE-2015-3221 openstack-neutron: L2 agent DoS through incorrect allowed address pairs
Title: Neutron L2 agent DoS through incorrect allowed address pairs
Reporter: Darragh O'Reilly (HP)
Products: Neutron
Affects: 2014.2 versions through 2014.2.3 and 2015.1.0 version
Description:
Darragh O'Reilly from HP reported a vulnerability in Neutron. By adding
an address pair which is rejected as invalid by the ipset tool, an
authenticated user may crash the Neutron L2 agent resulting in a denial
of service attack. Neutron setups using the IPTables firewall driver are
affected.
Acknowledgements:
Red Hat would like to thank the OpenStack upstream for reporting this issue. Upstream acknowledges Darragh O'Reilly (HP) as the original reporter.
Discussion:
Created attachment 1040537
cve-2015-3221-ma
Bugzilla
CVE-2014-1308 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 6.8
CVE-2014-1308 [MEDIUM] CVE-2014-1308 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
CVE-2014-1308 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2014-1308
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Statement:
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Se
Bugzilla
CVE-2014-1303 webkitgtk: heap-based buffer overflow (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 10.0
CVE-2014-1303 [CRITICAL] CVE-2014-1303 webkitgtk: heap-based buffer overflow (WSA-2015-0001)
CVE-2014-1303 webkitgtk: heap-based buffer overflow (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2014-1303
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen during a Pwn2Own competition at CanSecWest 2014.
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Statement:
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Bugzilla
CVE-2014-7935 chromium-browser: use-after-free in Speech
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7935 [HIGH] CVE-2014-7935 chromium-browser: use-after-free in Speech
CVE-2014-7935 chromium-browser: use-after-free in Speech
An unspecified use-after-free flaw was found in the Speech component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-6593 OpenJDK: incorrect tracking of ChangeCipherSpec during SSL/TLS handshake (JSSE, 8057555)
bugzilla·2015-01-16·CVSS 4.0
CVE-2014-6593 [MEDIUM] CVE-2014-6593 OpenJDK: incorrect tracking of ChangeCipherSpec during SSL/TLS handshake (JSSE, 8057555)
CVE-2014-6593 OpenJDK: incorrect tracking of ChangeCipherSpec during SSL/TLS handshake (JSSE, 8057555)
It was discovered that the SSL/TLS implementation in the JSSE component in OpenJDK failed to properly check if the ChangeCipherSpec was received during SSL/TLS connection handshake. A man-in-the-middle attacker could possibly use this flaw to force connection to be established without encryption being enabled.
Discussion:
Public now via Oracle Critical Patch Update - January 2015. Fixed in Oracle Java SE 5.0u81, 6u91, 7u75, and 8u31.
External References:
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html#AppendixJAVA
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Via RHSA-2015:0068 https://rhn.redhat.com/errata/RHSA-
Bugzilla
CVE-2014-1390 webkitgtk: arbitrary code execution and denial of service
bugzilla·2015-01-12·CVSS 6.8
CVE-2014-1390 [MEDIUM] CVE-2014-1390 webkitgtk: arbitrary code execution and denial of service
CVE-2014-1390 webkitgtk: arbitrary code execution and denial of service
It was reported [1] that WebKit allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs.
Upstream release: http://www.webkitgtk.org/2015/01/07/webkitgtk2.4.8-released.html
[1]: http://support.apple.com/en-us/HT6367
Bugzilla
CVE-2014-1387 webkitgtk: arbitrary code execution and denial of service
bugzilla·2015-01-12·CVSS 6.8
CVE-2014-1387 [MEDIUM] CVE-2014-1387 webkitgtk: arbitrary code execution and denial of service
CVE-2014-1387 webkitgtk: arbitrary code execution and denial of service
It was reported [1] that WebKit allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs.
Upstream release: http://www.webkitgtk.org/2015/01/07/webkitgtk2.4.8-released.html
[1]: http://support.apple.com/en-us/HT6367
Bugzilla
CVE-2014-9585 kernel: ASLR bruteforce possible for vdso library
bugzilla·2015-01-12·CVSS 2.1
CVE-2014-9585 [LOW] CVE-2014-9585 kernel: ASLR bruteforce possible for vdso library
CVE-2014-9585 kernel: ASLR bruteforce possible for vdso library
Linux kernel built with the Virtual Dynamic Shared Object(vDSO) support is
vulnerable to an information leakage flaw. It occurs due to less than perfect
address randomisation, which leads to leakage of vDSO library base address.
An unprivileged user could use this flaw to leak kernel memory addresses.
Upstream fix:
-> https://git.kernel.org/linus/394f56fe480140877304d342dec46d50dc823d46
Reference:
-> http://seclists.org/oss-sec/2015/q1/103
-> https://bugzilla.kernel.org/show_bug.cgi?id=89591
-> http://marc.info/?l=linux-kernel&m=141909723019695&w=2
Discussion:
The fix above is in upstream already:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/arch/x86/vdso/vma.c?id=394f56fe480140877304d342dec46d50
Bugzilla
CVE-2014-9601 python-pillow: potential denial-of-service during PNG decompression
bugzilla·2015-01-06·CVSS 5.0
CVE-2014-9601 [MEDIUM] CVE-2014-9601 python-pillow: potential denial-of-service during PNG decompression
CVE-2014-9601 python-pillow: potential denial-of-service during PNG decompression
Pillow release 2.7.0 fixes a potential denial-of-service issue in PNG decompression code [1].
Exact upstream commit that resolves this:
https://github.com/python-pillow/Pillow/commit/b3e09122e527ae554eb590741bbd7611d5710e40
[1]: http://pillow.readthedocs.org/releasenotes/2.7.0.html#png-text-chunk-size-limits
Discussion:
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-9601 to
the following vulnerability:
Name: CVE-2014-9601
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9601
Assigned: 20150116
Reference: https://www.djangoproject.com/weblog/2015/jan/02/pillow-security-release/
Pillow before 2.7.0 allows remote attackers to cause a denial of
service via a compressed text
Bugzilla
CVE-2014-2015 freeradius: stack-based buffer overflow flaw in rlm_pap module [fedora-all]
bugzilla·2014-02-26·CVSS 7.5
CVE-2014-2015 [HIGH] CVE-2014-2015 freeradius: stack-based buffer overflow flaw in rlm_pap module [fedora-all]
CVE-2014-2015 freeradius: stack-based buffer overflow flaw in rlm_pap module [fedora-all]
+++ This bug was initially created as a clone of Bug #1066763 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM
Bugzilla
CVE-2014-2015 freeradius: stack-based buffer overflow flaw in rlm_pap module
bugzilla·2014-02-19·CVSS 7.5
CVE-2014-2015 [HIGH] CVE-2014-2015 freeradius: stack-based buffer overflow flaw in rlm_pap module
CVE-2014-2015 freeradius: stack-based buffer overflow flaw in rlm_pap module
Pierre Carrier reported a stack-based buffer overflow flaw in the FreeRADIUS rlm_pap module. An authenticated user could trigger this issue by creating a large password, causing FreeRADIUS to crash. The stack protector and SSP variable re-ordering protections should help prevent this issue from being used to execute arbitrary code.
Upstream fixes:
2.x: https://github.com/FreeRADIUS/freeradius-server/commit/0d606cfc29a
3.x: https://github.com/FreeRADIUS/freeradius-server/commit/ff5147c9e5088c7
master: https://github.com/FreeRADIUS/freeradius-server/commit/f610864d4c8f51d
References:
http://lists.freebsd.org/pipermail/freebsd-bugbusters/2014-February/000610.html
Discussion:
Created freeradius tracking bugs for
Bugzilla
CVE-2014-2015 freeradius: stack-based buffer overflow flaw in rlm_pap module [fedora-all]
bugzilla·2014-02-19·CVSS 7.5
CVE-2014-2015 [HIGH] CVE-2014-2015 freeradius: stack-based buffer overflow flaw in rlm_pap module [fedora-all]
CVE-2014-2015 freeradius: stack-based buffer overflow flaw in rlm_pap module [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: th
Unit42
Attack on French Diplomat Linked to Operation Lotus Blossom
blogs_unit42·2015-12-18·CVSS 8.8
[HIGH] Attack on French Diplomat Linked to Operation Lotus Blossom
## Attack on French Diplomat Linked to Operation Lotus Blossom
Robert Falcone
Jen Miller-Osborn
Published: December 18, 2015
Malware
Threat Research
Email
Emissary
Lotus Blossom
Spear Phishing
We observed a targeted attack in November directed at an individual working for the French Ministry of Foreign Affairs. The attack involved a spear-phishing email sent to a single French diplomat based in Taipei, Taiwan and contained an invitation to a Science and Technology support group event.
The actors attempted to exploit CVE-2014-6332 using a slightly modified version of the proof-of-concept (POC) code to install a Trojan called Emissary, which is related to the Operation Lotus Blossom campaign. The TTPs used in this attack also match those detailed in the paper. The targeting of th
http://lists.freebsd.org/pipermail/freebsd-bugbusters/2014-February/000610.htmlhttp://lists.freebsd.org/pipermail/freebsd-bugbusters/2014-February/000612.htmlhttp://lists.freebsd.org/pipermail/freebsd-bugbusters/2014-February/000616.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1287.htmlhttp://ubuntu.com/usn/usn-2122-1http://www.openwall.com/lists/oss-security/2014/02/18/3http://www.securityfocus.com/bid/65581https://bugzilla.redhat.com/show_bug.cgi?id=1066761http://lists.freebsd.org/pipermail/freebsd-bugbusters/2014-February/000610.htmlhttp://lists.freebsd.org/pipermail/freebsd-bugbusters/2014-February/000612.htmlhttp://lists.freebsd.org/pipermail/freebsd-bugbusters/2014-February/000616.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1287.htmlhttp://ubuntu.com/usn/usn-2122-1http://www.openwall.com/lists/oss-security/2014/02/18/3http://www.securityfocus.com/bid/65581https://bugzilla.redhat.com/show_bug.cgi?id=1066761
2014-11-02
Published