CVE-2018-1364
published 2018-01-29CVE-2018-1364: IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this…
PriorityP347high8.2CVSS 3.0
AVNACLPRNUINSUCHINAL
EPSS
2.37%
81.9th percentile
IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 137449.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | content_navigator | — | — |
| ibm | content_navigator | — | — |
| ibm | content_navigator | — | — |
| ibm | content_navigator | — | — |
| ibm | content_navigator | — | — |
| ibm | content_navigator | — | — |
CVSS provenance
nvdv3.08.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16428 glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c
bugzilla·2018-09-06·CVSS 9.8
CVE-2018-16428 [CRITICAL] CVE-2018-16428 glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c
CVE-2018-16428 glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() function in gmarkup.c has a NULL pointer dereference.
Upstream bug:
https://gitlab.gnome.org/GNOME/glib/issues/1364
Upstream patch:
https://gitlab.gnome.org/GNOME/glib/commit/fccef3cc822af74699cca84cd202719ae61ca3b9
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1626164]
Created firefox tracking bugs for this issue:
Affects: fedora-all [bug 1626165]
Created glib2 tracking bugs for this issue:
Affects: fedora-all [bug 1626162]
Created thunderbird tracking bugs for this issue:
Affects: fedora-all [bug 1626167]
---
Mitigation:
Since the only affected code in this flaw is g_ma
Bugzilla
CVE-2018-1089 389-ds-base: ns-slapd crash via large filter value in ldapsearch
bugzilla·2018-03-23·CVSS 7.5
CVE-2018-1089 [HIGH] CVE-2018-1089 389-ds-base: ns-slapd crash via large filter value in ldapsearch
CVE-2018-1089 389-ds-base: ns-slapd crash via large filter value in ldapsearch
It is possible to crash ns-slapd (and ipa-dnskeysyncd afterwards) with crafted ldapsearch query with very long filter value both as anonymous or authenticated user. The crash can be similarly triggered with a query via the FreeIPA API as an authenticated user.
Discussion:
Acknowledgments:
Name: Greg Kubok
---
Created 389-ds-base tracking bugs for this issue:
Affects: fedora-all [bug 1575671]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1364 https://access.redhat.com/errata/RHSA-2018:1364
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1380 https://access.redhat.com/errata/RHSA-2018:1380
http://www.ibm.com/support/docview.wss?uid=swg22012595http://www.securityfocus.com/bid/102864https://exchange.xforce.ibmcloud.com/vulnerabilities/137449http://www.ibm.com/support/docview.wss?uid=swg22012595http://www.securityfocus.com/bid/102864https://exchange.xforce.ibmcloud.com/vulnerabilities/137449
2018-01-29
Published