CVE-2015-2233
published 2015-05-12CVE-2015-2233: Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows…
PriorityP338high8.3CVSS 2.0
AVAACLAuNCCICAC
EPSS
0.40%
32.6th percentile
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | system_update | <= 5.06.0027 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8241 tigervnc: NULL pointer dereference flaw in XRegion
bugzilla·2014-10-10·CVSS 7.5
CVE-2014-8241 [HIGH] CVE-2014-8241 tigervnc: NULL pointer dereference flaw in XRegion
CVE-2014-8241 tigervnc: NULL pointer dereference flaw in XRegion
This issue was discovered by Tim Waugh of Red Hat. Tigervnc is affected by same thing as in CVE-2014-6052. A NULL pointer dereference flaw was reported in tigervnc. A malicious VNC server could use this flaw to cause a client to crash.
Discussion:
Created attachment 946490
tigervnc-CVE-2014-8241.patch (proposed RHEL-7.1 patch)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2015:2233 https://rhn.redhat.com/errata/RHSA-2015-2233.html
---
Statement:
This issue affects the version of tigervnc as shipped with Red Hat Enterprise Linux 5 and 6. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates of Red Hat En
Bugzilla
CVE-2014-8240 tigervnc: integer overflow flaw, leading to a heap-based buffer overflow in screen size handling
bugzilla·2014-10-10·CVSS 7.5
CVE-2014-8240 [HIGH] CVE-2014-8240 tigervnc: integer overflow flaw, leading to a heap-based buffer overflow in screen size handling
CVE-2014-8240 tigervnc: integer overflow flaw, leading to a heap-based buffer overflow in screen size handling
This issue was discovered by Tim Waugh of Red Hat. Tigervnc is affected by same thing as in CVE-2014-6051. Integer overflaw leading to a heap-based buffer overflow was found in the way screen sizes were handled. A Malicious VNC server could use this flaw to cause a client to crash or, potentially, execute arbitrary code on the client.
Discussion:
Created attachment 947578
tigervnc-1.3.1-CVE-2014-8240.patch (proposed 1.3.1 patch)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2015:2233 https://rhn.redhat.com/errata/RHSA-2015-2233.html
---
Statement:
This issue affects the version of tigervnc as shipped with Red Hat Enterpr
http://securitytracker.com/id/1032268http://support.lenovo.com/us/en/product_security/lsu_privilegehttp://www.ioactive.com/pdfs/Lenovo_System_Update_Multiple_Privilege_Escalations.pdfhttp://www.securityfocus.com/bid/74642http://securitytracker.com/id/1032268http://support.lenovo.com/us/en/product_security/lsu_privilegehttp://www.ioactive.com/pdfs/Lenovo_System_Update_Multiple_Privilege_Escalations.pdfhttp://www.securityfocus.com/bid/74642
2015-05-12
Published