CVE-2020-4627
published 2020-11-30CVE-2020-4627: IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by…
PriorityP347critical9CVSS 3.1
AVNACLPRLUIRSCCHIHAH
EPSS
1.59%
72.8th percentile
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | cloud_pak_for_security | — | — |
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-7638 SDL: heap-based buffer over-read in Map1toN in video/SDL_pixels.c
bugzilla·2019-02-14·CVSS 8.8
CVE-2019-7638 [HIGH] CVE-2019-7638 SDL: heap-based buffer over-read in Map1toN in video/SDL_pixels.c
CVE-2019-7638 SDL: heap-based buffer over-read in Map1toN in video/SDL_pixels.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a
heap-based buffer over-read in Map1toN in video/SDL_pixels.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4500
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1677144]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7638
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4627
Bugzilla
CVE-2019-7572 SDL: buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c
bugzilla·2019-02-13·CVSS 8.8
CVE-2019-7572 [HIGH] CVE-2019-7572 SDL: buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c
CVE-2019-7572 SDL: buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer
over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4495
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676754]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7572
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4627 https:/
Bugzilla
CVE-2019-7577 SDL: buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c
bugzilla·2019-02-12·CVSS 8.8
CVE-2019-7577 [HIGH] CVE-2019-7577 SDL: buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c
CVE-2019-7577 SDL: buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer
over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.
Reference:
https://bugzilla.libsdl.org/show_bug.cgi?id=4492
Discussion:
Created SDL tracking bugs for this issue:
Affects: fedora-all [bug 1676510]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3868 https://access.redhat.com/errata/RHSA-2020:3868
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-7577
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4627 https://acc
2020-11-30
Published