VARIoT IoT vulnerabilities database
| VAR-201905-1045 | CVE-2018-7842 | plural Modicon Vulnerability related to authentication bypass through spoofing in products |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller. plural Modicon The product contains a vulnerability related to authentication bypass through spoofing.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Schneider Electric Modicon M580 and other products are products of Schneider Electric (France). Schneider Electric Modicon M580 is a programmable automation controller. Schneider Electric Modicon Premium is a large programmable logic controller (PLC) for discrete or process applications. Schneider Electric Modicon Quantum is a large programmable logic controller (PLC) for process applications, high availability and safety solutions.
Multiple Schneider Electric products have vulnerabilities in permissions and access control issues. An attacker could exploit this vulnerability through brute force to elevate privileges. The following products and versions are affected: Schneider Electric Modicon M580 (all versions); Modicon M340 (all versions); Modicon Quantum (all versions); Modicon Premium (all versions)
| VAR-201905-1023 | CVE-2018-7821 | SoMachine Basic and Modicon M221 Resource management vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet interface while the Ethernet/IP adapter is activated. SoMachine Basic and Modicon M221 Contains a resource management vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Both Schneider Electric SoMachine Basic and Schneider Electric Modicon M221 are products of French Schneider Electric (Schneider Electric). Schneider Electric SoMachine Basic is a suite of software for programming logic controllers. Schneider Electric Modicon M221 is a programmable logic controller. This vulnerability stems from improper management of system resources (such as memory, disk space, files, etc.) by network systems or products
| VAR-201905-0036 | CVE-2019-6820 | plural Schneider Electric Vulnerability related to lack of certification for critical functions in the product |
CVSS V2: 6.4 CVSS V3: 8.2 Severity: HIGH |
A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2. plural Schneider Electric The product is vulnerable to a lack of authentication for critical functions.Tampering with information and disrupting service operations (DoS) There is a possibility of being put into a state. Schneider Electric Modicon M100 and others are products of Schneider Electric, France. The Schneider Electric Modicon M100 is a programmable logic controller. The Schneider Electric Modicon LMC078 is a motion controller. The Schneider Electric ATV IMC drive controller is a drive controller. An access control error vulnerability exists in several Schneider Electric products. The following products and versions are affected: Schneider Electric Modicon M100 (all versions); Modicon M200 (all versions); Modicon M221 (all versions); ATV IMC drive controller (all versions); Modicon M241 (all versions); Modicon M258 (all versions); Modicon LMC058 (all versions); Modicon LMC078 (all versions); PacDrive Eco (all versions); PacDrive Pro (all versions); PacDrive Pro2 (all versions)
| VAR-201905-1038 | CVE-2018-7856 | plural Modicon Product Exceptional State Check Vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a possible denial of Service when writing invalid memory blocks to the controller over Modbus. plural Modicon The product contains an exceptional state check vulnerability.Service operation interruption (DoS) It may be in a state. Schneider Electric Modicon M580, etc. are all products of French Schneider Electric (Schneider Electric). The Schneider Electric Modicon M580 is a programmable automation controller. Schneider Electric Modicon Premium is a large programmable logic controller (PLC) for discrete or process applications. Schneider Electric Modicon Quantum is a large programmable logic controller (PLC) for process applications, high availability and safety solutions. A security vulnerability exists in several Schneider Electric products. An attacker could exploit this vulnerability to cause a denial of service. The following products and versions are affected: Schneider Electric Modicon M580 (all versions); Modicon M340 (all versions); Modicon Quantum (all versions); Modicon Premium (all versions)
| VAR-201905-0029 | CVE-2019-6807 | plural Modicon Product Exceptional State Handling Vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a possible denial of service when writing sensitive application variables to the controller over Modbus. plural Modicon The product contains an exceptional state handling vulnerability.Service operation interruption (DoS) It may be in a state. Schneider Electric Modicon M580 and others are products of Schneider Electric, France. The Schneider Electric Modicon M580 is a programmable automation controller. Schneider Electric Modicon Premium is a large programmable logic controller (PLC) for discrete or process applications. Schneider Electric Modicon Quantum is a large programmable logic controller (PLC) for process applications, high availability and safety solutions. Security vulnerabilities exist in several Schneider Electric products. An attacker could exploit the vulnerability to cause a denial of service. The following products and versions are affected: Schneider Electric Modicon M580 (all versions); Modicon M340 (all versions); Modicon Quantum (all versions); Modicon Premium (all versions)
| VAR-201905-1026 | CVE-2018-7824 | Schneider Electric Modbus Serial Driver Vulnerable to resource exhaustion |
CVSS V2: 6.8 CVSS V3: 4.9 Severity: MEDIUM |
An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electric Modbus Serial Driver (For 64-bit Windows OS:V3.17 IE 37 and prior , For 32-bit Windows OS:V2.17 IE 27 and prior, and as part of the Driver Suite version:V14.12 and prior) which could allow write access to system files available only to users with SYSTEM privilege or other important user files. Schneider Electric Modbus Serial Driver Contains a resource exhaustion vulnerability.Information may be tampered with. An attacker could exploit this vulnerability to perform write operations to system files or other important user files
| VAR-201905-0095 | CVE-2019-5436 | libcurl Buffer error vulnerability |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. libcurl Contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Haxx libcurl is an open source client URL transfer library from Haxx, Sweden. The product supports protocols such as FTP, SFTP, TFTP and HTTP. This vulnerability stems from the incorrect verification of data boundaries when the network system or product performs operations on the memory, resulting in incorrect read and write operations to other associated memory locations.
Here are the details from the Slackware 14.2 ChangeLog:
+--------------------------+
patches/packages/curl-7.65.0-i586-1_slack14.2.txz: Upgraded.
This release fixes the following security issues:
Integer overflows in curl_url_set
tftp: use the current blksize for recvfrom()
For more information, see:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5435
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5436
(* Security fix *)
+--------------------------+
Where to find the new packages:
+-----------------------------+
Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)
Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.
Updated package for Slackware 14.0:
ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/curl-7.65.0-i486-1_slack14.0.txz
Updated package for Slackware x86_64 14.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/curl-7.65.0-x86_64-1_slack14.0.txz
Updated package for Slackware 14.1:
ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/curl-7.65.0-i486-1_slack14.1.txz
Updated package for Slackware x86_64 14.1:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/curl-7.65.0-x86_64-1_slack14.1.txz
Updated package for Slackware 14.2:
ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/curl-7.65.0-i586-1_slack14.2.txz
Updated package for Slackware x86_64 14.2:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/curl-7.65.0-x86_64-1_slack14.2.txz
Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/curl-7.65.0-i586-1.txz
Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/curl-7.65.0-x86_64-1.txz
MD5 signatures:
+-------------+
Slackware 14.0 package:
6e09fa0f3bf3899629f78338886b8166 curl-7.65.0-i486-1_slack14.0.txz
Slackware x86_64 14.0 package:
55613986ed81a77a573976161b5b76fa curl-7.65.0-x86_64-1_slack14.0.txz
Slackware 14.1 package:
4317a7f249ca9dc8fdd9c4470335c140 curl-7.65.0-i486-1_slack14.1.txz
Slackware x86_64 14.1 package:
1a0cfbced24644f121dcd3140c378d85 curl-7.65.0-x86_64-1_slack14.1.txz
Slackware 14.2 package:
0112a5878893a036364b3792bb62de6c curl-7.65.0-i586-1_slack14.2.txz
Slackware x86_64 14.2 package:
794f036ca4ae31aaad11bdb3e4f1b7d9 curl-7.65.0-x86_64-1_slack14.2.txz
Slackware -current package:
82112f6caf0dc1d94340b4cf6a3eb001 n/curl-7.65.0-i586-1.txz
Slackware x86_64 -current package:
df9c4d1a59fe2f191fd20035c0fcff29 n/curl-7.65.0-x86_64-1.txz
Installation instructions:
+------------------------+
Upgrade the package as root:
# upgradepkg curl-7.65.0-i586-1_slack14.2.txz
+-----+
Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com
+------------------------------------------------------------------------+
| To leave the slackware-security mailing list: |
+------------------------------------------------------------------------+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202003-29
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: cURL: Multiple vulnerabilities
Date: March 15, 2020
Bugs: #686050, #694020
ID: 202003-29
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities have been found in cURL, the worst of which
may lead to arbitrary code execution.
Background
==========
A command line tool and library for transferring data with URLs.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-misc/curl < 7.66.0 >= 7.66.0
Description
===========
Multiple vulnerabilities have been discovered in cURL. Please review
the CVE identifiers referenced below for details.
Impact
======
A remote attacker could possibly execute arbitrary code with the
privileges of the process or cause a Denial of Service condition.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All cURL users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/curl-7.66.0"
References
==========
[ 1 ] CVE-2019-5435
https://nvd.nist.gov/vuln/detail/CVE-2019-5435
[ 2 ] CVE-2019-5436
https://nvd.nist.gov/vuln/detail/CVE-2019-5436
[ 3 ] CVE-2019-5481
https://nvd.nist.gov/vuln/detail/CVE-2019-5481
[ 4 ] CVE-2019-5482
https://nvd.nist.gov/vuln/detail/CVE-2019-5482
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202003-29
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2020 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
. ==========================================================================
Ubuntu Security Notice USN-3993-1
May 22, 2019
curl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 19.04
- Ubuntu 18.10
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in curl. This issue only affected Ubuntu 19.04. (CVE-2019-5435)
It was discovered that curl incorrectly handled memory when receiving data
from a TFTP server. (CVE-2019-5436)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 19.04:
curl 7.64.0-2ubuntu1.1
libcurl3-gnutls 7.64.0-2ubuntu1.1
libcurl3-nss 7.64.0-2ubuntu1.1
libcurl4 7.64.0-2ubuntu1.1
Ubuntu 18.10:
curl 7.61.0-1ubuntu2.4
libcurl3-gnutls 7.61.0-1ubuntu2.4
libcurl3-nss 7.61.0-1ubuntu2.4
libcurl4 7.61.0-1ubuntu2.4
Ubuntu 18.04 LTS:
curl 7.58.0-2ubuntu3.7
libcurl3-gnutls 7.58.0-2ubuntu3.7
libcurl3-nss 7.58.0-2ubuntu3.7
libcurl4 7.58.0-2ubuntu3.7
Ubuntu 16.04 LTS:
curl 7.47.0-1ubuntu2.13
libcurl3 7.47.0-1ubuntu2.13
libcurl3-gnutls 7.47.0-1ubuntu2.13
libcurl3-nss 7.47.0-1ubuntu2.13
In general, a standard system update will make all the necessary changes. 7.7) - ppc64, ppc64le, s390x, x86_64
3. Description:
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
Security Fix(es):
* golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows
for panic (CVE-2020-9283)
* SSL/TLS: CBC padding timing attack (lucky-13) (CVE-2013-0169)
* grafana: XSS vulnerability via a column style on the "Dashboard > Table
Panel" screen (CVE-2018-18624)
* js-jquery: prototype pollution in object's prototype leading to denial of
service or remote code execution or property injection (CVE-2019-11358)
* npm-serialize-javascript: XSS via unsafe characters in serialized regular
expressions (CVE-2019-16769)
* kibana: Prototype pollution in TSVB could result in arbitrary code
execution (ESA-2020-06) (CVE-2020-7013)
* nodejs-minimist: prototype pollution allows adding or modifying
properties of Object.prototype using a constructor or __proto__ payload
(CVE-2020-7598)
* npmjs-websocket-extensions: ReDoS vulnerability in
Sec-WebSocket-Extensions parser (CVE-2020-7662)
* nodejs-lodash: prototype pollution in zipObjectDeep function
(CVE-2020-8203)
* jquery: Cross-site scripting due to improper injQuery.htmlPrefilter
method (CVE-2020-11022)
* jQuery: passing HTML containing <option> elements to manipulation methods
could result in untrusted code execution (CVE-2020-11023)
* grafana: stored XSS (CVE-2020-11110)
* grafana: XSS annotation popup vulnerability (CVE-2020-12052)
* grafana: XSS via column.title or cellLinkTooltip (CVE-2020-12245)
* nodejs-elliptic: improper encoding checks allows a certain degree of
signature malleability in ECDSA signatures (CVE-2020-13822)
* golang.org/x/text: possibility to trigger an infinite loop in
encoding/unicode could lead to crash (CVE-2020-14040)
* nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate
function (CVE-2020-15366)
* openshift/console: text injection on error page via crafted url
(CVE-2020-10715)
* kibana: X-Frame-Option not set by default might lead to clickjacking
(CVE-2020-10743)
* openshift: restricted SCC allows pods to craft custom network packets
(CVE-2020-14336)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section. Solution:
For OpenShift Container Platform 4.6 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.openshift.com/container-platform/4.6/release_notes/ocp-4-6-rel
ease-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.6/updating/updating-cluster
- -cli.html. Bugs fixed (https://bugzilla.redhat.com/):
907589 - CVE-2013-0169 SSL/TLS: CBC padding timing attack (lucky-13)
1701972 - CVE-2019-11358 jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection
1767665 - CVE-2020-10715 openshift/console: text injection on error page via crafted url
1804533 - CVE-2020-9283 golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic
1813344 - CVE-2020-7598 nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload
1828406 - CVE-2020-11022 jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
1834550 - CVE-2020-10743 kibana: X-Frame-Option not set by default might lead to clickjacking
1845982 - CVE-2020-7662 npmjs-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser
1848089 - CVE-2020-12052 grafana: XSS annotation popup vulnerability
1848092 - CVE-2019-16769 npm-serialize-javascript: XSS via unsafe characters in serialized regular expressions
1848643 - CVE-2020-12245 grafana: XSS via column.title or cellLinkTooltip
1848647 - CVE-2020-13822 nodejs-elliptic: improper encoding checks allows a certain degree of signature malleability in ECDSA signatures
1849044 - CVE-2020-7013 kibana: Prototype pollution in TSVB could result in arbitrary code execution (ESA-2020-06)
1850004 - CVE-2020-11023 jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
1850572 - CVE-2018-18624 grafana: XSS vulnerability via a column style on the "Dashboard > Table Panel" screen
1853652 - CVE-2020-14040 golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash
1857412 - CVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep function
1857977 - CVE-2020-15366 nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function
1858981 - CVE-2020-14336 openshift: restricted SCC allows pods to craft custom network packets
1861044 - CVE-2020-11110 grafana: stored XSS
1874671 - CVE-2020-14336 ose-machine-config-operator-container: openshift: restricted SCC allows pods to craft custom network packets [openshift-4]
5. 8) - aarch64, ppc64le, s390x, x86_64
3. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Low: curl security and bug fix update
Advisory ID: RHSA-2020:1020-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2020:1020
Issue date: 2020-03-31
CVE Names: CVE-2019-5436
=====================================================================
1. Summary:
An update for curl is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact
of Low. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Client (v. 7) - x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - x86_64
3. Description:
The curl packages provide the libcurl library and the curl utility for
downloading files from servers using various protocols, including HTTP,
FTP, and LDAP.
Security Fix(es):
* curl: TFTP receive heap buffer overflow in tftp_receive_packet() function
(CVE-2019-5436)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 7.8 Release Notes linked from the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Bugs fixed (https://bugzilla.redhat.com/):
1710620 - CVE-2019-5436 curl: TFTP receive heap buffer overflow in tftp_receive_packet() function
1754736 - curl does not send Authorization header when receiving WWW-Authenticate header twice
1769307 - curl fails while attempting to POST a char device
6. Package List:
Red Hat Enterprise Linux Client (v. 7):
Source:
curl-7.29.0-57.el7.src.rpm
x86_64:
curl-7.29.0-57.el7.x86_64.rpm
curl-debuginfo-7.29.0-57.el7.i686.rpm
curl-debuginfo-7.29.0-57.el7.x86_64.rpm
libcurl-7.29.0-57.el7.i686.rpm
libcurl-7.29.0-57.el7.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
x86_64:
curl-debuginfo-7.29.0-57.el7.i686.rpm
curl-debuginfo-7.29.0-57.el7.x86_64.rpm
libcurl-devel-7.29.0-57.el7.i686.rpm
libcurl-devel-7.29.0-57.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source:
curl-7.29.0-57.el7.src.rpm
x86_64:
curl-7.29.0-57.el7.x86_64.rpm
curl-debuginfo-7.29.0-57.el7.i686.rpm
curl-debuginfo-7.29.0-57.el7.x86_64.rpm
libcurl-7.29.0-57.el7.i686.rpm
libcurl-7.29.0-57.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
x86_64:
curl-debuginfo-7.29.0-57.el7.i686.rpm
curl-debuginfo-7.29.0-57.el7.x86_64.rpm
libcurl-devel-7.29.0-57.el7.i686.rpm
libcurl-devel-7.29.0-57.el7.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
curl-7.29.0-57.el7.src.rpm
ppc64:
curl-7.29.0-57.el7.ppc64.rpm
curl-debuginfo-7.29.0-57.el7.ppc.rpm
curl-debuginfo-7.29.0-57.el7.ppc64.rpm
libcurl-7.29.0-57.el7.ppc.rpm
libcurl-7.29.0-57.el7.ppc64.rpm
libcurl-devel-7.29.0-57.el7.ppc.rpm
libcurl-devel-7.29.0-57.el7.ppc64.rpm
ppc64le:
curl-7.29.0-57.el7.ppc64le.rpm
curl-debuginfo-7.29.0-57.el7.ppc64le.rpm
libcurl-7.29.0-57.el7.ppc64le.rpm
libcurl-devel-7.29.0-57.el7.ppc64le.rpm
s390x:
curl-7.29.0-57.el7.s390x.rpm
curl-debuginfo-7.29.0-57.el7.s390.rpm
curl-debuginfo-7.29.0-57.el7.s390x.rpm
libcurl-7.29.0-57.el7.s390.rpm
libcurl-7.29.0-57.el7.s390x.rpm
libcurl-devel-7.29.0-57.el7.s390.rpm
libcurl-devel-7.29.0-57.el7.s390x.rpm
x86_64:
curl-7.29.0-57.el7.x86_64.rpm
curl-debuginfo-7.29.0-57.el7.i686.rpm
curl-debuginfo-7.29.0-57.el7.x86_64.rpm
libcurl-7.29.0-57.el7.i686.rpm
libcurl-7.29.0-57.el7.x86_64.rpm
libcurl-devel-7.29.0-57.el7.i686.rpm
libcurl-devel-7.29.0-57.el7.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source:
curl-7.29.0-57.el7.src.rpm
x86_64:
curl-7.29.0-57.el7.x86_64.rpm
curl-debuginfo-7.29.0-57.el7.i686.rpm
curl-debuginfo-7.29.0-57.el7.x86_64.rpm
libcurl-7.29.0-57.el7.i686.rpm
libcurl-7.29.0-57.el7.x86_64.rpm
libcurl-devel-7.29.0-57.el7.i686.rpm
libcurl-devel-7.29.0-57.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2019-5436
https://access.redhat.com/security/updates/classification/#low
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.8_release_notes/index
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBXoObWtzjgjWX9erEAQiZbxAAqKGZZqZXMjb1Ia8ST1HZTC8mBxlxQM9Z
qwT3r0czzMc2PaMlmMbvBPr7JLybKl9bxb8ufMhCAQwvOYsIZ6mLlV+dwLVnpDJr
u+I9HhOBjsJgbzspOl8XuyRyylcOXiZmDbuU5JarhGvrMgApHujgzxMwXDedApPP
MvtbhMHNOiTrYXhMy6IrTkPoFdPaziNWLAw1TTbfMSsF2C9CUjXCpmRpv+ttq85q
9Ms3wbGuS2tDm9/6grtarY3SxeSoaMg0VR3YJQ4J7jIXoeeHxQSs0K1mBVekEZ9r
JcqgynjNqEQP1dcfzOxorRcXD7i2NFC1WLGdAM16KlETiN3Fpcb4nVF+0phU3ea+
hJsKwKEAb6CX+qLi/uITr6m0xYy323QTNCvOHX/xtf6EnpJhq1UsltBOzm/KjL1T
N0ClNjEs7/57TEIwE9u3LhDuPfQfdkewRv2QEqLdpNw5JqT8p+dxlrJNzCTkbFPc
bgmHZdvfJ5blQweL/ejCE5zmr9jKYbhqyrdBn7sxKj1gn6R9ZHcX14pljDbLAjp/
cBWx9zscU82xyh49QAl8VHabiHpOU9c7SaUz+9G3WzZboaJNUoBrPTPvsXg1nGW7
0f3qjx/Y3/MRR8qCNL7VtNA+8QCGryMU+Gs5cxNnWmtfW0i5kpHCU7cxk/+ig2JZ
M95S58Xnb8U=
=UHVC
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
| VAR-201905-1065 | CVE-2019-10981 | Vijeo Citect and CitectSCADA Vulnerability regarding insufficient protection of authentication information in |
CVSS V2: 2.1 CVSS V3: 7.8 Severity: HIGH |
In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local user access to Citect user credentials. Vijeo Citect and CitectSCADA There are vulnerabilities in inadequate protection of credentials.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. SchneiderElectricAVEVAVijeoCitect and SchneiderElectricAVEVACitectSCADA are a set of data acquisition and monitoring systems (SCADA) software from Schneider Electric. A security vulnerability exists in SchneiderElectricAVEVAVijeoCitect and SchneiderElectricAVEVACitectSCADA that caused the program to fail to adequately protect the credentials. AVEVA Vijeo Citect and CitectSCADA are prone to an information-disclosure vulnerability.
Attackers can exploit this issue to to obtain the sensitive information.
The following products of AVEVA are vulnerable:
Vijeo Citect 7.30 and 7.40
CitectSCADA 7.30 and 7.40. The following products and versions are affected: Schneider Electric AVEVA Vijeo Citect Version 7.30, Version 7.40; Schneider Electric AVEVA CitectSCADA Version 7.30, Version 7.40
| VAR-201905-1060 | CVE-2019-10977 | Made by Mitsubishi Electric MELSEC-Q series Ethernet Service operation interruption in the interface unit (DoS) Vulnerabilities |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an attacker could send crafted TCP packets against the FTP service, forcing the target devices to enter an error mode and cause a denial-of-service condition. Provided by Mitsubishi Electric Corporation MELSEC-Q Series Ethernet Interface unit FTP Functions include service disruption (DoS) (CWE-400) Vulnerabilities exist. The Mitsubishi Electric MELSEC-QseriesEthernetmoduleQJ71E71-100 is an Ethernet module from Japan's Mitsubishi Electric. A remote denial of service vulnerability exists in MitsubishiElectricMELSEC-QSeriesPLCs that could allow an attacker to cause a denial of service. Mitsubishi Electric MELSEC-Q Series PLCs are prone to an remote denial-of-service vulnerability.
An attacker can exploit this issue to cause a denial-of-service condition.
The following MELSEC-Q series PLCs are affected:
QJ71E71-100 serial number 20121 and prior. This vulnerability stems from improper management of system resources (such as memory, disk space, files, etc.) by network systems or products
| VAR-201905-1254 | CVE-2019-12195 |
TP-Link TL-WR840N Device cross-site scripting vulnerability
Related entries in the VARIoT exploits database: VAR-E-201905-0230 |
CVSS V2: 3.5 CVSS V3: 4.8 Severity: MEDIUM |
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS payload, the network name changed automatically and the internet connection was disconnected. All the users become disconnected from the internet. TP-Link TL-WR840N The device contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. The TP-LinkTL-WR840N is a wireless router from China Unicom (TP-Link). The vulnerability stems from the lack of proper validation of client data for web applications. An attacker could exploit the vulnerability to execute client code
| VAR-201905-1350 | No CVE | XG5000 has dll hijacking vulnerability |
CVSS V2: 7.2 CVSS V3: - Severity: HIGH |
XG5000 is a software for programming and debugging of XGT / XGB series PLC.
XG5000 has a dll hijacking vulnerability that can be used by an attacker to execute malicious code
| VAR-201905-1344 | No CVE | Century Star mo *** server in heap overflow vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
Century Star configuration software is a blocking software launched by Beijing Century Changqiu Technology Co., Ltd. It is a real-time human-machine interface utility generator, composed of CSMaker development system and CSViewer operating system.
The Century Star mo *** server has a heap overflow vulnerability. An attacker can remotely execute malicious code on the user system through an open protocol port, and finally gain control of the user system. CSMaker Development system and CSViewer Composition of the operating system
| VAR-201905-1343 | No CVE | InotouchEditor has a memory corruption vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
InotouchEditor is an HMI programming software produced by Shenzhen Huichuan Technology Co., Ltd.
InotouchEditor has a memory corruption vulnerability when processing afs project files. Attackers can use this vulnerability to gain control of the user system or crash the program
| VAR-201905-1340 | No CVE | Century Star WebViewer.ocx Control Fl *** Method Has Stack Overflow Vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
Century Star configuration software is a blocking software launched by Beijing Century Changqiu Technology Co., Ltd. It is a real-time human-machine interface utility generator, composed of CSMaker development system and CSViewer operating system.
There is a stack overflow vulnerability in the Fl *** method of the CenturyStar WebViewer.ocx control. An attacker can trick users who have installed this control to visit a malicious webpage, trigger a vulnerability, execute malicious code remotely on the user system, and finally gain control of the user system. CSMaker Development system and CSViewer Composition of the operating system
| VAR-201905-1325 | No CVE | Memory corruption vulnerability in SAMSoar Developer |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
SAMSoar Developer is a configuration software produced by Shenzhen Xiankong Technology Co., Ltd.
SAMSoar Developer has a memory corruption vulnerability when processing ssp project files. Attackers can use this vulnerability to gain control of the user system or crash the program
| VAR-201905-1338 | No CVE | Display Control Remote HMI has a memory corruption vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
Display Control Remote HMI is a configuration software produced by Shenzhen Display Control Technology Co., Ltd.
Display Control Remote HMI has a memory corruption vulnerability when processing smc project files. Attackers can use this vulnerability to gain control of the user system or crash the program
| VAR-201905-1341 | No CVE | Display Control Remote HMI has dll hijacking vulnerability |
CVSS V2: 7.2 CVSS V3: - Severity: HIGH |
Shenzhen Xiankong Technology is a national high-tech enterprise specializing in R & D, production, sales and service of core products of Industry 4.0.
Display Control Remote HMI has dll hijacking vulnerability. An attacker can maliciously load and execute a DLL by constructing a malicious application and placing it in a specific path. DLL And execute
| VAR-201905-1349 | No CVE | xp-builder has dll hijacking vulnerability |
CVSS V2: 7.2 CVSS V3: - Severity: HIGH |
xp-builder is an XGT HMI editing software.
There is a dll hijacking vulnerability in xp-builder, which can be used by an attacker to execute malicious code
| VAR-201905-1348 | No CVE | KGL_WIN has a memory corruption vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
KGL_WIN is a PLC programming software.
KGL_WIN has a memory corruption vulnerability when processing kpr project files. Attackers can use this vulnerability to gain control of the user system or crash the program
| VAR-201905-1339 | No CVE | SKWorkshop has a memory corruption vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
SKWorkshop is a configuration software produced by Shenzhen Xiankong Technology Co., Ltd.
SKWorkshop has a memory corruption vulnerability when processing shm project files. Attackers can use this vulnerability to gain control of the user system or crash the program