CVE-2019-0553
published 2019-01-08CVE-2019-0553: An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory, aka "Windows Subsystem for Linux…
PriorityP424medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
1.81%
76.2th percentile
An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory, aka "Windows Subsystem for Linux Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2019 | — | — |
| msrc | windows_10_version_1703_for_32-bit_systems | — | — |
| msrc | windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | windows_10_version_1709_for_32-bit_systems | — | — |
| msrc | windows_10_version_1709_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1709_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Subsystem for Linux Information Disclosure Vulnerability
vendor_msrc·2019-01-08·CVSS 4.7
CVE-2019-0553 [MEDIUM] Windows Subsystem for Linux Information Disclosure Vulnerability
Windows Subsystem for Linux Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
A attacker could exploit this vulnerability by running a specially crafted application.
The update addresses the vulnerability by correcting how Windows Subsystem for Linux handles objects in memory.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is Kernel memory read - unintentional read access to memory contents in kernel space from a user mode
GHSA
GHSA-p85g-g2xq-mxcw: An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory, aka "Windows Subsystem for Linux
ghsa_unreviewed·2022-05-13
CVE-2019-0553 [MEDIUM] GHSA-p85g-g2xq-mxcw: An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory, aka "Windows Subsystem for Linux
An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory, aka "Windows Subsystem for Linux Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11291 rabbitmq-server: not properly sanitized user input may lead to XSS
bugzilla·2019-12-13·CVSS 4.8
CVE-2019-11291 [MEDIUM] CVE-2019-11291 rabbitmq-server: not properly sanitized user input may lead to XSS
CVE-2019-11291 rabbitmq-server: not properly sanitized user input may lead to XSS
Two endpoints, federation and shovel, do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.
Discussion:
Created rabbitmq-server tracking bugs for this issue:
Affects: fedora-all [bug 1783329]
Affects: openstack-rdo [bug 1783328]
---
External References:
https://pivotal.io/security/cve-2019-11291
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 15.0 (Stein)
Via RHSA-2020:0553 https://access.redhat.com/errata/RHSA-2020:0553
---
This bug is now closed. Further upda
Bugzilla
CVE-2018-14041 bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy
bugzilla·2018-07-16·CVSS 6.1
CVE-2018-14041 [MEDIUM] CVE-2018-14041 bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy
CVE-2018-14041 bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy
A flaw was found in Bootstrap from version 4.0 and before 4.1.2. A Cross-site Scripting (XSS) is possible in the data-target property of scrollspy.
References:
https://github.com/twbs/bootstrap/issues/26627
Upstream Patch:
https://github.com/twbs/bootstrap/pull/26630
Discussion:
bootstrap 3.3.7 is not affected by this flaw.
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.3.2 zip
Via RHSA-2019:1456 https://access.redhat.com/errata/RHSA-2019:1456
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
Via RHSA-2023:0553 https://access.redhat.com/errata/RHSA-2023:0553
---
This issue
2019-01-08
Published