CVE-2019-0971
published 2019-05-16CVE-2019-0971: An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted…
PriorityP340medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
8.46%
94.4th percentile
An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server, aka 'Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability'.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_devops_server | — | — |
| microsoft | team_foundation_server | — | — |
| microsoft | team_foundation_server_2018 | — | — |
| msrc | azure_devops_server_2019 | — | — |
| msrc | team_foundation_server_2018_update_3.2 | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_msrc6.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
vendor_msrc·2019-05-14·CVSS 6.5
CVE-2019-0971 [MEDIUM] Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server. An attacker who successfully exploited this vulnerability could execute malicious code on a vulnerable server.
To exploit this vulnerability, an authenticated attacker would need to create a page specifically designed to cause a server-side request. The attacker would then send a specially-crafted message to perform a server-side request forgery attack.
The update addresses the vulnerability by modifying how Azure DevOps Server and Microsoft Team Foundation Server manage server authentication.
FA
GHSA
GHSA-858j-7757-pwv6: An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially craf
ghsa_unreviewed·2022-05-24
CVE-2019-0971 [HIGH] GHSA-858j-7757-pwv6: An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially craf
An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server, aka 'Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability'.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116
bugzilla·2019-02-07·CVSS 7.8
CVE-2019-3839 [HIGH] CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116
It was found that some additional operators and dictionaries were needed to be hidden in order to prevent other CVE-2019-6116 attacks.
Discussion:
Mitigation:
Please refer to the "Mitigation" section of CVE-2018-16509 : https://access.redhat.com/security/cve/cve-2018-16509
---
Additional commit required for CVE-2019-6116 :
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=4ec9ca7
+ http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=db24f25 to prevent pdf2dsc regression
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:0971 https://access.redhat.com/errata/RHSA-2019:0971
---
This issue has been addressed in the following products:
Red
Talos
Vulnerability Spotlight: Denial-of-service vulnerability in NVIDIA driver
blogs_talos·2020-06-24·CVSS 5.5
[MEDIUM] Vulnerability Spotlight: Denial-of-service vulnerability in NVIDIA driver
Piotr Bania of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
## Executive summary
The NVWGF2UMX_CFG.DLL driver contains a denial-of-service vulnerability that an attacker could use to disrupt processes over a virtual machine. An adversary could exploit this bug by
providing a specially crafted pixel shader over VMware guests and VMware hosts, leading to VMware to process crash on the host machine.
In accordance with our coordinated disclosure policy, Cisco Talos worked with NVIDIA and VMware to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details
NVIDIA NVWGF2UMX_CFG.DLL shader functionality denial-of-service vulnerability (TALOS-2019-0971/CVE-2020-5965)
An exploitable denial of service vulnerability
2019-05-16
Published