CVE-2017-1262
published 2017-12-20CVE-2017-1262: IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to…
PriorityP426medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.22%
65.6th percentile
IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 124737.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_guardium | — | — |
| ibm | security_guardium | — | — |
| ibm | security_guardium | — | — |
| ibm | security_guardium | — | — |
| ibm | security_guardium | — | — |
| ibm | security_guardium | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cg44-83gm-9c7j: IBM Security Guardium 10
ghsa_unreviewed·2022-05-14
CVE-2017-1262 [MEDIUM] CWE-113 GHSA-cg44-83gm-9c7j: IBM Security Guardium 10
IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 124737.
Kernel
mm/slub.c: add a naive detection of double free or corruption
kernel_security·2017-09-06·CVSS 7.0
CVE-2017-2636 [HIGH] mm/slub.c: add a naive detection of double free or corruption
mm/slub.c: add a naive detection of double free or corruption
Add an assertion similar to "fasttop" check in GNU C Library allocator
as a part of SLAB_FREELIST_HARDENED feature. An object added to a
singly linked freelist should not point to itself. That helps to detect
some double free errors (e.g. CVE-2017-2636) without slub_debug and
KASAN.
Link: http://lkml.kernel.org/r/[email protected]
Signed-off-by: Alexander Popov
Acked-by: Christoph Lameter
Cc: Kees Cook
Cc: Pekka Enberg
Cc: David Rientjes
Cc: Joonsoo Kim
Cc: Paul E McKenney
Cc: Ingo Molnar
Cc: Tejun Heo
Cc: Andy Lutomirski
Cc: Nicolas Pitre
Cc: Rik van Riel
Cc: Tycho Andersen
Signed-off-by: Andrew Morton
Signed-off-by: Linus Torvalds
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-12-20
Published