CVE-2023-0006
published 2023-04-12CVE-2023-0006: A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with…
PriorityP428medium6.3CVSS 3.1
AVLACHPRLUINSUCNIHAH
EPSS
0.11%
1.5th percentile
A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| palo_alto_networks | globalprotect_app | >= 5.2 < 5.2.13 | 5.2.13 |
| palo_alto_networks | globalprotect_app | >= 6.0 < 6.0.4 | 6.0.4 |
| palo_alto_networks | globalprotect_app | >= 6.1 < 6.1.1 | 6.1.1 |
| paloalto | globalprotect_app | — | — |
| paloaltonetworks | globalprotect | — | — |
| paloaltonetworks | globalprotect | >= 5.2.0 < 5.2.13 | 5.2.13 |
| paloaltonetworks | globalprotect | >= 6.0.0 < 6.0.4 | 6.0.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g2xf-r6pf-g763: A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endp
ghsa_unreviewed·2023-04-12
CVE-2023-0006 [MEDIUM] CWE-367 GHSA-g2xf-r6pf-g763: A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endp
A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition.
Palo Alto
GlobalProtect App: Local File Deletion Vulnerability
vendor_paloalto·2023-04-12·CVSS 6.3
CVE-2023-0006 [MEDIUM] CWE-367 GlobalProtect App: Local File Deletion Vulnerability
GlobalProtect App: Local File Deletion Vulnerability
A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition.
Affected products: GlobalProtect App
Solution: This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 5.2.13, GlobalProtect app 6.0.4, GlobalProtect app 6.1.1, and all later GlobalProtect app versions on Windows devices.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-45918 ncurses: NULL pointer dereference in tgetstr in tinfo/lib_termcap.c
bugzilla·2024-07-29
CVE-2023-45918 [LOW] CVE-2023-45918 ncurses: NULL pointer dereference in tgetstr in tinfo/lib_termcap.c
CVE-2023-45918 ncurses: NULL pointer dereference in tgetstr in tinfo/lib_termcap.c
ncurses 6.4-20230610 has a NULL pointer dereference in tgetstr in tinfo/lib_termcap.c.
https://lists.gnu.org/archive/html/bug-ncurses/2023-06/msg00005.html
https://security.netapp.com/advisory/ntap-20240315-0006/
Discussion:
I don't see the security impact here. terminfo files are trusted like executables. If an attacker can supply their own terminfo file, they can always prevent the application from working correctly.
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.16
Via RHSA-2024:5107 https://access.redhat.com/errata/RHSA-2024:5107
---
This issue is also affecting the RedHat UBI images.
Currently checked in latest images in
* ubi8: https://cat
Bugzilla
CVE-2023-40474 gstreamer-plugins-bad: Integer overflow leading to heap overwrite in MXF file handling with uncompressed video
bugzilla·2023-12-14·CVSS 8.8
CVE-2023-40474 [HIGH] CVE-2023-40474 gstreamer-plugins-bad: Integer overflow leading to heap overwrite in MXF file handling with uncompressed video
CVE-2023-40474 gstreamer-plugins-bad: Integer overflow leading to heap overwrite in MXF file handling with uncompressed video
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.
The specific flaw exists within the parsing of MXF video files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
https://gstreamer.freedesktop.org/security/sa-2023-0006.html
Discussion:
This issue has been addressed in the following
2023-04-12
Published