CVE-2014-3090
published 2014-09-23CVE-2014-3090: IBM Rational ClearCase 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (memory…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.37%
82.0th percentile
IBM Rational ClearCase 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
| ibm | rational_clearcase | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g6x3-992w-85wr: IBM Rational ClearCase 7
ghsa_unreviewed·2022-05-17·CVSS 6.5
CVE-2014-3090 [MEDIUM] GHSA-g6x3-992w-85wr: IBM Rational ClearCase 7
IBM Rational ClearCase 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
OSV
Pillow regression
osv·2016-09-30·CVSS 5.0
CVE-2014-9601 Pillow regression
Pillow regression
USN-3090-1 fixed vulnerabilities in Pillow. The patch to fix CVE-2014-9601
caused a regression which resulted in failures when processing certain
png images. This update temporarily reverts the security fix for CVE-2014-9601
pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that a flaw in processing a compressed text chunk in
a PNG image could cause the image to have a large size when decompressed,
potentially leading to a denial of service. (CVE-2014-9601)
Andrew Drake discovered that Pillow incorrectly validated input. A remote
attacker could use this to cause Pillow to crash, resulting in a denial
of service. (CVE-2014-3589)
Eric Soroos discovered that Pillow incorrectly handled certain malformed
FLI,
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg21677285http://www.securityfocus.com/bid/69964http://www.securitytracker.com/id/1030883https://exchange.xforce.ibmcloud.com/vulnerabilities/94256http://www-01.ibm.com/support/docview.wss?uid=swg21677285http://www.securityfocus.com/bid/69964http://www.securitytracker.com/id/1030883https://exchange.xforce.ibmcloud.com/vulnerabilities/94256
2014-09-23
Published