CVE-2015-1569
published 2015-02-10CVE-2015-1569: Fortinet FortiClient 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof SSL VPN servers via a…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.51%
39.7th percentile
Fortinet FortiClient 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof SSL VPN servers via a crafted certificate.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0241 postgresql: buffer overflow in the to_char() function
bugzilla·2015-02-03·CVSS 8.8
CVE-2015-0241 [HIGH] CVE-2015-0241 postgresql: buffer overflow in the to_char() function
CVE-2015-0241 postgresql: buffer overflow in the to_char() function
The PostgreSQL project reports the following issue:
When to_char() processes a numeric formatting template calling for a large number of digits, PostgreSQL would read past the end of a buffer. When processing a crafted timestamp formatting template, PostgreSQL would write past the end of a buffer. Either case could crash the server. We have not ruled out the possibility of attacks that lead to privilege escalation, though they seem unlikely.
Acknowledgements:
Red Hat would like to thank the PostgreSQL project for reporting this issue. Upstream acknowledges Andres Freund, Peter Geoghegan, Bernd Helmle, and Noah Misch as the original reporters.
Discussion:
External References:
http://www.postgresql.org/about/news/1569
Bugzilla
CVE-2015-0243 postgresql: buffer overflow flaws in contrib/pgcrypto
bugzilla·2015-02-03·CVSS 8.8
CVE-2015-0243 [HIGH] CVE-2015-0243 postgresql: buffer overflow flaws in contrib/pgcrypto
CVE-2015-0243 postgresql: buffer overflow flaws in contrib/pgcrypto
The PostgreSQL project reports the following issue:
Errors in memory size tracking within the pgcrypto module permitted stack buffer overruns and improper dependence on the contents of uninitialized memory. The buffer overrun cases can crash the server, and we have not ruled out the possibility of attacks that lead to privilege escalation.
Acknowledgements:
Red Hat would like to thank the PostgreSQL project for reporting this issue. Upstream acknowledges Marko Tiikkaja as the original reporter.
Discussion:
External References:
http://www.postgresql.org/about/news/1569/
---
Upstream commit:
https://github.com/postgres/postgres/commit/1dc75515868454c645ded22d38054ec693e23ec6
---
This issue was addressed in Fedora
http://seclists.org/fulldisclosure/2015/Jan/124http://www.security-assessment.com/files/documents/advisory/Fortinet_FortiClient_Multiple_Vulnerabilities.pdfhttp://seclists.org/fulldisclosure/2015/Jan/124http://www.security-assessment.com/files/documents/advisory/Fortinet_FortiClient_Multiple_Vulnerabilities.pdf
2015-02-10
Published