CVE-2019-0777
published 2019-04-09CVE-2019-0777: A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server…
PriorityP426medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
1.70%
74.6th percentile
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ehang.io | nps | >= 0 < 0.23.2 | 0.23.2 |
| microsoft | team_foundation_server | — | — |
| microsoft | team_foundation_server | — | — |
| microsoft | team_foundation_server | — | — |
| microsoft | team_foundation_server_2018 | — | — |
| microsoft | team_foundation_server_2018 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_glib_2.58.0-6_on_cbl_mariner_1.0 | — | — |
| msrc | team_foundation_server_2017_update_3.1 | — | — |
| msrc | team_foundation_server_2018_update_1.2 | — | — |
| msrc | team_foundation_server_2018_update_3.2 | — | — |
| netaddr_project | netaddr | >= 0 < 1.5.3 | 1.5.3 |
| netaddr_project | netaddr | >= 2.0.0 < 2.0.4 | 2.0.4 |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat9.8CRITICAL
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
glib2: insecure permissions for files and directories
vendor_redhat·2019-06-28·CVSS 9.8
CVE-2019-13012 [CRITICAL] CWE-732 glib2: insecure permissions for files and directories
glib2: insecure permissions for files and directories
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently, it does not properly restrict directory (and file) permissions. Instead, for directories, 0777 permissions are used; for files, default file permissions are used. This is similar to CVE-2019-12450.
Statement: This issue affects glib2 as shipped with Red Hat Enterprise Linux 6, 7 and 8 and was rated as having a Low security impact by Red Hat Product Security team.
Although Red Hat Enterprise Linux versions above ships the vulnerable
Microsoft
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir NULL NULL) and files using g_file_replace_contents (kfsb-
vendor_msrc·2019-06-11·CVSS 7.5
CVE-2019-13012 [CRITICAL] CWE-732 The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir NULL NULL) and files using g_file_replace_contents (kfsb-
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir NULL NULL) and files using g_file_replace_contents (kfsb->file contents length NULL FALSE G_FILE_CREATE_REPLACE_DESTINATION NULL NULL NULL). Consequently it does not properly restrict directory (and file) permissions. Instead for directories 0777 permissions are used; for files default file permissions are used. This is similar to CVE-2019-12450.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure
Microsoft
Team Foundation Server Cross-site Scripting Vulnerability
vendor_msrc·2019-03-12·CVSS 5.4
CVE-2019-0777 [MEDIUM] Team Foundation Server Cross-site Scripting Vulnerability
Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the Team Foundation Server, which will get executed in the context of the user every time a user visits the compromised page.
The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. The attacks could allow the attacker to read content that the attacker is not authorized to read, execute malicious code, and use the victim's identity to take actions on the site on behalf
GHSA
cnlh nps vulnerable to file overwrite by local user
ghsa·2022-05-24
CVE-2019-15119 [MEDIUM] CWE-732 cnlh nps vulnerable to file overwrite by local user
cnlh nps vulnerable to file overwrite by local user
`lib/install/install.go` in cnlh nps prior to 0.23.2 uses 0777 permissions for `/usr/local/bin/nps and/or /usr/bin/nps`, leading to a file overwrite by a local user.
GHSA
GHSA-5h3x-73w2-c5q7: A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Ser
ghsa_unreviewed·2022-05-14
CVE-2019-0777 [MEDIUM] CWE-79 GHSA-5h3x-73w2-c5q7: A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Ser
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'.
GHSA
netaddr before 1.5.3 and 2.0.4 has Incorrect Default Permissions
ghsa·2019-10-14
CVE-2019-17383 [CRITICAL] CWE-276 netaddr before 1.5.3 and 2.0.4 has Incorrect Default Permissions
netaddr before 1.5.3 and 2.0.4 has Incorrect Default Permissions
The netaddr gem before 1.5.3 and 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
Suricata
ET EXPLOIT Possible CVE-2016-0777 Client Sent Roaming Resume Request
suricata·2016-01-15·CVSS 6.5
CVE-2016-0777 [MEDIUM] ET EXPLOIT Possible CVE-2016-0777 Client Sent Roaming Resume Request
ET EXPLOIT Possible CVE-2016-0777 Client Sent Roaming Resume Request
Rule: alert tcp any any -> any $SSH_PORTS (msg:"ET EXPLOIT Possible CVE-2016-0777 Client Sent Roaming Resume Request"; flow:established,to_server; content:"|14|"; offset:6; content:"[email protected]"; distance:0; content:!"AppGateSSH_5.2"; reference:cve,2016-0777; reference:url,www.qualys.com/2016/01/14/cve-2016-0777-cve-2016-0778/openssh-cve-2016-0777-cve-2016-0778.txt; classtype:attempted-user; sid:2022370; rev:2; metadata:created_at 2016_01_15, cve CVE_2016_0777, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
Suricata
ET EXPLOIT Possible CVE-2016-0777 Server Advertises Suspicious Roaming Support
suricata·2016-01-15·CVSS 6.5
CVE-2016-0777 [MEDIUM] ET EXPLOIT Possible CVE-2016-0777 Server Advertises Suspicious Roaming Support
ET EXPLOIT Possible CVE-2016-0777 Server Advertises Suspicious Roaming Support
Rule: alert ssh any $SSH_PORTS -> any any (msg:"ET EXPLOIT Possible CVE-2016-0777 Server Advertises Suspicious Roaming Support"; flow:established,to_client; content:"|14|"; offset:6; content:"[email protected]"; distance:0; content:!"AppGateSSH_5.2"; reference:cve,2016-0777; reference:url,www.qualys.com/2016/01/14/cve-2016-0777-cve-2016-0778/openssh-cve-2016-0777-cve-2016-0778.txt; classtype:attempted-user; sid:2022369; rev:2; metadata:created_at 2016_01_15, cve CVE_2016_0777, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
No public exploits indexed.
Bugzilla
CVE-2019-5018 sqlite: Use-after-free in window function leading to remote code execution
bugzilla·2019-05-09·CVSS 8.1
CVE-2019-5018 [HIGH] CVE-2019-5018 sqlite: Use-after-free in window function leading to remote code execution
CVE-2019-5018 sqlite: Use-after-free in window function leading to remote code execution
An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.
External References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0777
Discussion:
According to https://www.sqlite.org/windowfunctions.html window functions was first added to SQLite with upstream release version 3.25.0 (2018-09-15).
---
Upstream patch:
https://www.sqlite.org/src/info/1e16d3e8fc60d39c
---
The expression Expr representing the Window function is deleted in s
Bugzilla
CVE-2019-3881 rubygem-bundler: Insecure permissions on directory in /tmp/ allows for execution of malicious code
bugzilla·2018-11-21·CVSS 7.8
CVE-2019-3881 [HIGH] CVE-2019-3881 rubygem-bundler: Insecure permissions on directory in /tmp/ allows for execution of malicious code
CVE-2019-3881 rubygem-bundler: Insecure permissions on directory in /tmp/ allows for execution of malicious code
Bundler through version 1.17.1 creates a directory with insecure permissions in /tmp/ that, in certain circumstances, is used by Bundler to load rubygems, allowing attackers to write malicious libraries to this location and be later executed.
Bundler contains some helper code which creates a temporary directory in case a user's home directory is not present or writeable, however it creates it via non-randomized path, `/tmp/bundler/home/username`. Permissions for this directory are 0777 which allows an attacker to create subdirectory with an arbitrary username. Bundler processes started under an effective user without a home directory will load rubygems from this attacker-writa
Talos
Vulnerability Spotlight: Remote code execution bug in SQLite
blogs_talos·2019-05-09·CVSS 8.1
[HIGH] Vulnerability Spotlight: Remote code execution bug in SQLite
Cory Duplantis of Cisco Talos discovered this vulnerability.
### Executive summary
SQLite contains an exploitable use-after-free vulnerability that could allow an attacker to gain the ability to remotely execute code on the victim machine. SQLite is a client-sidedatabase management system contained in a C programming library. SQLite implements the Window Functions feature of SQL, which allows queries over a subset, or “window,” of rows. This specific vulnerability lies in that “window” function.
In accordance with our coordinated disclosure policy, Cisco Talos worked with SQLite to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability details
SQLite3 window function remote code execution vulnerability (TALOS-2018-0777/CVE-2019-
2019-04-09
Published