CVE-2019-0001
published 2019-01-15CVE-2019-0001: Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge subscriber…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.05%
86.2th percentile
Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge subscriber management daemon (bbe-smgd), and lead to high CPU usage and a crash of the bbe-smgd service. Repeated receipt of the same packet can result in an extended denial of service condition for the device. Affected releases are Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S1; 16.2 versions prior to 16.2R2-S7; 17.1 versions prior to 17.1R2-S10, 17.1R3; 17.2 versions prior to 17.2R3; 17.3 versions prior to 17.3R3-S1; 17.4 versions prior to 17.4R2; 18.1 versions prior to 18.1R3; 18.2 versions prior to 18.2R2.
Affected
85 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware product updates resolve mishandled file descriptor vulnerability in runc container runtime.
vendor_vmware·2019-02-15·CVSS 8.6
CVE-2019-5736 [HIGH] VMware product updates resolve mishandled file descriptor vulnerability in runc container runtime.
VMSA-2019-0001: VMware product updates resolve mishandled file descriptor vulnerability in runc container runtime.
VMware product updates resolve mishandled file descriptor vulnerability in runc container runtime. Successful exploitation of this issue may allow a malicious container to overwrite the contents of a host's runc binary and execute arbitrary code. Exploitation of this vulnerability requires the attacker to have existing permission to deploy containers or run docker exec. Alternatively, an attacker could trick a user with these permissions into deploying a malicious container or running docker exec for them. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2019-5736 to this issue. Column 5 of the following table lists the action r
Juniper
CVE-2019-0001: Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge su
vendor_juniper·2019-01-15·CVSS 7.5
CVE-2019-0001 [HIGH] CWE-674 CVE-2019-0001: Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge su
CVE-2019-0001: Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge subscriber management daemon (bbe-smgd), and lead to high CPU usage and a crash of the bbe-smgd service. Repeated receipt of the same packet can result in an extended denial of service condition for the device. Affected releases are Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S1; 16.2 versions prior to 16.2R2-S7; 17.1 versions prior to 17.1R2-S10, 17.1R3; 17.2 versions prior to 17.2R3; 17.3 versions prior to 17.3R3-S1; 17.4 versions prior to 17.4R2; 18.1 versions prior to 18.1R3; 18.2 versions prior to 18.2R2.
GHSA
GHSA-ww3g-x39p-r2pw: Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge su
ghsa_unreviewed·2022-05-13
CVE-2019-0001 [HIGH] CWE-674 GHSA-ww3g-x39p-r2pw: Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge su
Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge subscriber management daemon (bbe-smgd), and lead to high CPU usage and a crash of the bbe-smgd service. Repeated receipt of the same packet can result in an extended denial of service condition for the device. Affected releases are Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S1; 16.2 versions prior to 16.2R2-S7; 17.1 versions prior to 17.1R2-S10, 17.1R3; 17.2 versions prior to 17.2R3; 17.3 versions prior to 17.3R3-S1; 17.4 versions prior to 17.4R2; 18.1 versions prior to 18.1R3; 18.2 versions prior to 18.2R2.
No detection rules found.
arXiv
Vulnerability Forecasting: In theory and practice
arxiv_fulltext·2020-12-07
Vulnerability Forecasting: In theory and practice
Vulnerability Forecasting: In theory and practice.
\'Eireann Leverett
Both authors contributed equally to this research.
[email protected]
0000-0001-6586-7359
Matilda Rhode
[1]
[email protected]
Adam Wedgbury
[email protected]
Airbus
Quadrant House, Celtic Springs Business Park, Coedkernew, Duffryn
Newport
U.K.
NP10 8FZ
## Abstract
Why wait for zero-days when you could predict them in advance? It is possible to predict the volume of CVEs released in the NVD as much as a year in advance. This can be done within 3 percent of the actual value, and different predictive algorithms perform well at different lookahead values. It is also possible to estimate the proportions of that total volumn belonging to specific vendors, software, CVSS scores, or vulnerability types
Bugzilla
CVE-2019-18823 htcondor: Incorrect access control in condor_startd
bugzilla·2020-04-27·CVSS 9.8
CVE-2019-18823 [CRITICAL] CVE-2019-18823 htcondor: Incorrect access control in condor_startd
CVE-2019-18823 htcondor: Incorrect access control in condor_startd
HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condor_schedd. (For example to submit or remove jobs)
https://research.cs.wisc.edu/htcondor/
https://research.cs.wisc.edu/htcondor/new.html
https://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2020-0001.html
https://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2020-0002.html
https://research.cs.wisc.edu/htcondor/security/vulnerabiliti
Bugzilla
CVE-2019-8835 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
bugzilla·2020-03-24·CVSS 8.8
CVE-2019-8835 [HIGH] CVE-2019-8835 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
CVE-2019-8835 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
A flaw was found in WebKitGTK before 2.26.3. Processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://www.openwall.com/lists/oss-security/2020/01/23/2
https://webkitgtk.org/security/WSA-2020-0001.html
Discussion:
Created webkit2gtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1816685]
---
External References:
https://webkitgtk.org/security/WSA-2020-0001.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
ht
Bugzilla
CVE-2019-8846 webkitgtk: Use after free issue may lead to remote code execution
bugzilla·2020-03-24·CVSS 8.8
CVE-2019-8846 [HIGH] CVE-2019-8846 webkitgtk: Use after free issue may lead to remote code execution
CVE-2019-8846 webkitgtk: Use after free issue may lead to remote code execution
A flaw was found in WebKitGTK before 2.26.3. Processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://www.openwall.com/lists/oss-security/2020/01/23/2
https://webkitgtk.org/security/WSA-2020-0001.html
Discussion:
Created webkit2gtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1816679]
---
External References:
https://webkitgtk.org/security/WSA-2020-0001.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/s
Bugzilla
CVE-2019-8844 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
bugzilla·2020-03-24·CVSS 8.8
CVE-2019-8844 [HIGH] CVE-2019-8844 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
CVE-2019-8844 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
A flaw was found in WebKitGTK before 2.26.3. Processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://www.openwall.com/lists/oss-security/2020/01/23/2
https://webkitgtk.org/security/WSA-2020-0001.html
Discussion:
Created webkit2gtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1816687]
---
External References:
https://webkitgtk.org/security/WSA-2020-0001.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
ht
Bugzilla
CVE-2019-18801 envoy: an untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1
bugzilla·2019-11-18·CVSS 9.8
CVE-2019-18801 [CRITICAL] CVE-2019-18801 envoy: an untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1
CVE-2019-18801 envoy: an untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1
An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1.
Discussion:
Created attachment 1638035
[PATCH 1/3] http: fix heap overflow vulnerability (CVE-2019-18801)
1.12.2-0001-http-fix-heap-overflow-vulnerability-CVE-2019-18801.patch
---
Created attachment 1638056
[PATCH 1/3] http: fix heap overflow vulnerability (CVE-2019-18801)
master-0001-http-fix-heap-overflow-vulnerability-CVE-2019-18801.patch
---
External References:
https://groups.google.com/forum/#!topic/envoy-users/m7z5fGkCzPI
https://github.com/envoyproxy/envoy/security/advisories/GHSA-gxvv-
Bugzilla
CVE-2019-3866 openstack-mistral: information disclosure in mistral log
bugzilla·2019-11-05·CVSS 5.5
CVE-2019-3866 [MEDIUM] CVE-2019-3866 openstack-mistral: information disclosure in mistral log
CVE-2019-3866 openstack-mistral: information disclosure in mistral log
A vulnerability was discovered that all the data from the TripleO heat stack (user provided and generated passwords, certificates, ssh keys) are available in the mistral logs on the undercloud, in clear text.
Discussion:
Created openstack-mistral-3 tracking bugs for this issue:
Affects: openstack-rdo [bug 1770043]
---
Upstream bug: https://bugs.launchpad.net/tripleo/+bug/1850843
Patch for Pike and newer: https://launchpadlibrarian.net/449472809/0001-Ensure-we-mask-sensitive-data-from-Mistral-Action-lo.patch
---
Acknowledgments:
Name: the OpenStack project
Upstream: Gauvain Pocentek and Clément Beaufils (Kindred Group PLC)
---
Patch for Ocata and older: https://launchpadlibrarian.net/449473654/0001-Ensure-we-m
Bugzilla
CVE-2019-16231 kernel: null-pointer dereference in drivers/net/fjes/fjes_main.c
bugzilla·2019-10-10·CVSS 4.1
CVE-2019-16231 [MEDIUM] CVE-2019-16231 kernel: null-pointer dereference in drivers/net/fjes/fjes_main.c
CVE-2019-16231 kernel: null-pointer dereference in drivers/net/fjes/fjes_main.c
A NULL pointer dereference flaw was found in fjes_probe in drivers/net/fjes/fjes_main.c in FUJITSU Extended Socket Network driver. Here a call to alloc_workqueue return was not validated and can cause a denial of service at the time of failure. This could allow an attacker to crash the system or leak kernel internal information.
Reference:
https://security.netapp.com/advisory/ntap-20191004-0001/
https://lkml.org/lkml/2019/9/9/487
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1760314]
---
This was fixed for Fedora in the 5.3.11 stable kernel update
---
Mitigation:
Mitigation for this issue is either not available or the currently available options don't meet the Red
Bugzilla
CVE-2019-16232 kernel: null-pointer dereference in drivers/net/wireless/marvell/libertas/if_sdio.c
bugzilla·2019-10-10·CVSS 4.1
CVE-2019-16232 [MEDIUM] CVE-2019-16232 kernel: null-pointer dereference in drivers/net/wireless/marvell/libertas/if_sdio.c
CVE-2019-16232 kernel: null-pointer dereference in drivers/net/wireless/marvell/libertas/if_sdio.c
A vulnerability was found in drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
Reference:
https://lkml.org/lkml/2019/9/9/487
https://security.netapp.com/advisory/ntap-20191004-0001/
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1760352]
---
Mitigation:
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
---
Statement:
There was no shipped kernel version were seen a
Bugzilla
CVE-2019-9928 GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution
bugzilla·2019-06-28·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928 GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution
CVE-2019-9928 GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution
GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.
References:
https://gstreamer.freedesktop.org/security/sa-2019-0001.html
Upstream MR:
https://gitlab.freedesktop.org/gstreamer/gst-plugins-base/merge_requests/157
Discussion:
External References:
https://gstreamer.freedesktop.org/security/sa-2019-0001.html
---
Created gstreamer-plugins-base tracking bugs for this issue:
Affects: fedora-all [bug 1725261]
Created mingw-gstreamer1-plugins-base tracking bugs for this issue:
Affects: fedora-all [bug 1725262]
---
Upstream c
Bugzilla
CVE-2019-3808 moodle: Manage groups capability is missing XSS risk flag (MSA-19-0001)
bugzilla·2019-01-21·CVSS 5.4
CVE-2019-3808 [MEDIUM] CVE-2019-3808 moodle: Manage groups capability is missing XSS risk flag (MSA-19-0001)
CVE-2019-3808 moodle: Manage groups capability is missing XSS risk flag (MSA-19-0001)
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.
References:
https://moodle.org/mod/forum/discuss.php?d=381228#p1536765
Upstream Patch:
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64395
Discussion:
Created moodle tracking bugs for this issue:
Affects: epel-all [bug 1668066]
Affects: fedora-all [bug 1668065]
---
This CVE Bugzilla entry is for community su
http://www.securityfocus.com/bid/106541https://kb.juniper.net/JSA10900https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RMKFSHPMOZL7MDWU5RYOTIBTRWSZ4Z6X/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W7CPKBW4QZ4VIY4UXIUVUSHRJ4R2FROE/http://www.securityfocus.com/bid/106541https://kb.juniper.net/JSA10900https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RMKFSHPMOZL7MDWU5RYOTIBTRWSZ4Z6X/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W7CPKBW4QZ4VIY4UXIUVUSHRJ4R2FROE/
2019-01-15
Published