VARIoT IoT vulnerabilities database

VAR-201808-0436 | CVE-2018-13341 | Crestron TSW-X60 and MC3 Vulnerabilities related to certificate and password management |
CVSS V2: 4.0 CVSS V3: 8.8 Severity: HIGH |
Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts may be calculated using information accessible to those with regular user privileges. Attackers could decipher these passwords, which may allow them to execute hidden API calls and escape the CTP console sandbox environment with elevated privileges. Crestron TSW-X60 and MC3 Contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. This vulnerability allows remote attackers to escalate privileges on affected installations of all Crestron products. Authentication is required to exploit this vulnerability.The specific flaw exists within the two built-in accounts on all Crestron devices. An attacker can leverage this vulnerability to execute arbitrary code under the context of Administrator. Crestron TSW-X60 and MC3 are prone to the following multiple security vulnerabilities:
1. Multiple OS command-injection vulnerabilities.
2. An access-bypass vulnerability.
3. A security-bypass vulnerability.
Attackers can exploit these issues to execute arbitrary OS commands and bypass certain security restrictions, perform unauthorized actions, or gain sensitive information within the context of the affected system. Failed exploit attempts will likely result in denial of service conditions
VAR-201808-0608 | CVE-2018-15137 | CeLa Link CLR-M20 Device unrestricted upload vulnerability type file vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method. CeLa Link CLR-M20 The device contains a vulnerability related to unlimited uploads of dangerous types of files.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. CeLa Link CLR-M20 is a wireless router product. A security vulnerability exists in CeLa Link CLR-M20
VAR-201808-0176 | CVE-2018-10636 | Delta Industrial Automation CNCSoft ScreenEditor DPB File wKPFString Stack-based Buffer Overflow Remote Code Execution Vulnerability |
CVSS V2: 9.3 CVSS V3: 8.8 Severity: HIGH |
CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has multiple stack-based buffer overflow vulnerabilities that could cause the software to crash due to lacking user input validation before copying data from project files onto the stack. Which may allow an attacker to gain remote code execution with administrator privileges if exploited. CNCSoft and ScreenEditor Contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Delta Industrial Automation CNCSoft ScreenEditor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the handling of DPB files. When parsing the wFont attribute of the UserVARComment element, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. Delta Electronics CNCSoft and ScreenEditor are products of Delta Electronics. Delta Electronics CNCSoft is a set of simulation software for CNC machine tools. ScreenEditor is a set of human-machine interface programming software.
A stack buffer overflow vulnerability exists in Delta Electronics CNCSoft 1.00.83 and earlier and ScreenEditor 1.00.54. An attacker could use this vulnerability to cause software to crash. Multiple stack-based buffer-overflow vulnerabilities
2
VAR-201808-0183 | CVE-2018-10598 | CNCSoft and ScreenEditor Vulnerable to out-of-bounds reading |
CVSS V2: 5.8 CVSS V3: 8.1 Severity: MEDIUM |
CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has two out-of-bounds read vulnerabilities could cause the software to crash due to lacking user input validation for processing project files. Which may allow an attacker to gain remote code execution with administrator privileges if exploited. CNCSoft and ScreenEditor Contains an out-of-bounds vulnerability.Information is obtained and service operation is interrupted (DoS) There is a possibility of being put into a state. This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Delta Industrial Automation CNCSoft ScreenEditor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the handling of DPB files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. Delta Electronics CNCSoft and ScreenEditor are products of Delta Electronics. Delta Electronics CNCSoft is a set of simulation software for CNC machine tools. ScreenEditor is a set of human-machine interface programming software.
An out-of-bounds read vulnerability exists in Delta Electronics CNCSoft 1.00.83 and earlier and ScreenEditor 1.00.54. Multiple stack-based buffer-overflow vulnerabilities
2
VAR-201809-0630 | CVE-2018-0661 | Multiple vulnerabilities in multiple I-O DATA network camera products |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: Medium |
Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) allow an attacker on the same network segment to bypass access restriction to add files on a specific directory that may result in executing arbitrary OS commands/code or information including credentials leakage or alteration. Multiple network camera products provided by I-O DATA DEVICE, INC. contain multiple vulnerabilities listed below. * Permissions, Privileges, and Access Controls (CWE-264) - CVE-2018-0661 * Insufficient Verification of Data Authenticity (CWE-345) - CVE-2018-0662 * Use of Hard-coded Credentials (CWE-798) - CVE-2018-0663 The following researchers reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership. CVE-2018-0661 Yutaka Kokubu, Toshitsugu Yoneyama, and Daiki Ichinose of Mitsui Bussan Secure Directions, Inc. CVE-2018-0662 Daiki Ichinose of Mitsui Bussan Secure Directions, Inc. Several IO DATA products have security vulnerabilities. The following products and versions are affected: IO DATA TS-WRLP with firmware version 1.09.04 and earlier; TS-WRLA with firmware version 1.09.04 and earlier; TS-WRLP/E with firmware version 1.09.04 and earlier
VAR-201808-0173 | CVE-2018-10626 | Medtronic MyCareLink 24950 and 24952 Patient Monitor Vulnerabilities related to insufficient validation of data reliability |
CVSS V2: 3.8 CVSS V3: 4.4 Severity: MEDIUM |
Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network. Medtronic MyCareLink 24950 and 24952 Patient Monitor Contains vulnerabilities related to insufficient validation of data reliability.Information may be obtained and information may be altered.
An attacker can exploit these issues to bypass security restrictions and perform unauthorized actions or obtain sensitive information. This may aid in further attacks. Both Medtronic MyCareLink 24950 Patient Monitor and 24952 Patient Monitor are monitors produced by Medtronic in the United States for monitoring the vital signs of patients
VAR-201808-0171 | CVE-2018-10622 | Medtronic MyCareLink 24950 and 24952 Patient Monitor Vulnerabilities related to certificate and password management |
CVSS V2: 1.9 CVSS V3: 7.1 Severity: HIGH |
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication and encryption of local data at rest. Medtronic MyCareLink 24950 and 24952 Patient Monitor Contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. MedtronicMyCareLink24950PatientMonitor and 24952PatientMonitor are monitor devices used by Medtronic to monitor patient vital signs. An information disclosure vulnerability exists in MedtronicMyCareLink24950PatientMonitor and 24952PatientMonitor (all versions) that the program uses to store credentials in a recoverable format that an attacker can use to authenticate and obtain sensitive information. Medtronic MyCareLink Patient Monitor is prone to security bypass vulnerability and information disclosure vulnerability.
An attacker can exploit these issues to bypass security restrictions and perform unauthorized actions or obtain sensitive information. This may aid in further attacks
VAR-201809-0632 | CVE-2018-0663 | Multiple vulnerabilities in multiple I-O DATA network camera products |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: Medium |
Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) use hardcoded credentials which may allow an remote authenticated attacker to execute arbitrary OS commands on the device via unspecified vector. Multiple network camera products provided by I-O DATA DEVICE, INC. contain multiple vulnerabilities listed below. * Permissions, Privileges, and Access Controls (CWE-264) - CVE-2018-0661 * Insufficient Verification of Data Authenticity (CWE-345) - CVE-2018-0662 * Use of Hard-coded Credentials (CWE-798) - CVE-2018-0663 The following researchers reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership. CVE-2018-0661 Yutaka Kokubu, Toshitsugu Yoneyama, and Daiki Ichinose of Mitsui Bussan Secure Directions, Inc. CVE-2018-0662 Daiki Ichinose of Mitsui Bussan Secure Directions, Inc
VAR-201809-0631 | CVE-2018-0662 | Multiple vulnerabilities in multiple I-O DATA network camera products |
CVSS V2: 7.2 CVSS V3: 6.8 Severity: Medium |
Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) allow an attacker on the same network segment to add malicious files on the device and execute arbitrary code. contain multiple vulnerabilities listed below. * Permissions, Privileges, and Access Controls (CWE-264) - CVE-2018-0661 * Insufficient Verification of Data Authenticity (CWE-345) - CVE-2018-0662 * Use of Hard-coded Credentials (CWE-798) - CVE-2018-0663 The following researchers reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership. CVE-2018-0661 Yutaka Kokubu, Toshitsugu Yoneyama, and Daiki Ichinose of Mitsui Bussan Secure Directions, Inc. CVE-2018-0662 Daiki Ichinose of Mitsui Bussan Secure Directions, Inc. Several IO DATA products have security vulnerabilities
VAR-201808-0370 | CVE-2018-14781 | plural Medtronic Authentication vulnerabilities in products |
CVSS V2: 2.9 CVSS V3: 5.3 Severity: MEDIUM |
Medtronic MiniMed MMT
devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin (bolus) delivery. plural Medtronic The product contains authentication vulnerabilities.Information may be tampered with. MedtronicMMT-508MiniMedinsulinpump and other are different types of insulin pumps from Medtronic Corporation of the United States. Multiple Medtronic Isulin Pumps are prone to an authentication-bypass vulnerability and an information-disclosure vulnerability.
Attackers may exploit these issues to gain unauthorized access to the affected device or to obtain sensitive information that may aid in launching further attacks. An authorization issue vulnerability exists in several Medtronic products. The following products are affected: Medtronic MMT - 508 MiniMed insulin pump; MMT - 522 Paradigm REAL-TIME; MMT - 722 Paradigm REAL-TIME; MMT - 523 Paradigm Revel; MMT - 723 Paradigm Revel; Paradigm Revel; MMT-551 MiniMed 530G; MMT-751 MiniMed 530G
VAR-201808-0175 | CVE-2018-10634 | plural Medtronic Information disclosure vulnerability in products |
CVSS V2: 2.9 CVSS V3: 5.3 Severity: MEDIUM |
Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently skilled attacker could capture these transmissions and extract sensitive information, such as device serial numbers. plural Medtronic The product contains an information disclosure vulnerability.Information may be obtained. MedtronicMMT-508MiniMedinsulinpump and other are different types of insulin pumps from Medtronic Corporation of the United States. An information disclosure vulnerability exists in several Medtronic products that originated in the form of clear text communication between pump and wireless accessories. Multiple Medtronic Isulin Pumps are prone to an authentication-bypass vulnerability and an information-disclosure vulnerability. The following products are affected: Medtronic MMT - 508 MiniMed insulin pump; MMT - 522 Paradigm REAL-TIME; MMT - 722 Paradigm REAL-TIME; MMT - 523 Paradigm Revel; MMT - 723 Paradigm Revel; Paradigm Revel; MMT-551 MiniMed 530G; MMT-751 MiniMed 530G
VAR-201808-0743 | CVE-2018-11453 | SIMATIC STEP 7 and WinCC Vulnerabilities related to authorization, permissions, and access control |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 6), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V15 (All versions < V15 Update 2). Improper file permissions in the default installation of TIA Portal may allow an attacker with local file system access to insert specially crafted files which may prevent TIA Portal startup (Denial-of-Service) or lead to local code execution. No special privileges are required, but the victim needs to attempt to start TIA Portal after the manipulation. SIMATIC STEP 7 and WinCC (TIA Portal ) Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Siemens SIMATIC STEP 7 (TIA Portal) is a set of programming software for SIMATIC controllers. The software provides PLC programming, design option packages and advanced drive technology. WinCC (TIA Portal) is an automated data acquisition and monitoring (SCADA) system. The system provides functions such as process monitoring and data acquisition. The Portal starts, causing a denial of service or execution of code. Siemens SIMATIC STEP 7 and SIMATIC WinCC are prone to multiple insecure file-permissions vulnerabilities.
A local attacker can exploit these issues by gaining access to a world-readable file and extracting sensitive information from it. Information obtained may aid in other attacks
VAR-201808-0744 | CVE-2018-11454 | SIMATIC STEP 7 and WinCC Vulnerabilities related to authorization, permissions, and access control |
CVSS V2: 4.4 CVSS V3: 8.6 Severity: HIGH |
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 6), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V15 (All versions < V15 Update 2). Improper file permissions in the default installation of TIA Portal may allow an attacker with local file system access to manipulate resources which may be transferred to devices and executed there by a different user. No special privileges are required, but the victim needs to transfer the manipulated files to a device. Execution is caused on the target device rather than on the PG device. SIMATIC STEP 7 and WinCC (TIA Portal ) Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Siemens SIMATIC STEP 7 (TIA Portal) is a set of programming software for SIMATIC controllers. The software provides PLC programming, design option packages and advanced drive technology. WinCC (TIA Portal) is an automated data acquisition and monitoring (SCADA) system. The system provides functions such as process monitoring and data acquisition. And resources that are executed by the user. Siemens SIMATIC STEP 7 and SIMATIC WinCC are prone to multiple insecure file-permissions vulnerabilities.
A local attacker can exploit these issues by gaining access to a world-readable file and extracting sensitive information from it. Information obtained may aid in other attacks
VAR-201808-0745 | CVE-2018-11455 | Siemens Automation License Manager Arbitrary code execution vulnerability |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4), Automation License Manager 6 (All versions < 6.0.1). A directory traversal vulnerability could allow a remote attacker to move arbitrary files, which can result in code execution, compromising confidentiality, integrity and availability of the system. Successful exploitation requires a network connection to the affected device. The attacker does not need privileges or special conditions of the system, but user interaction is required. Automation License Manager Contains a path traversal vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. The Siemens Automation License Manager is a Siemens system from Germany that handles remote and local certificates in HMI, SCADA and industrial products.
An attacker can exploit these issues using directory-traversal characters ('../') to access or read arbitrary files that contain sensitive information or to access files outside of the restricted directory or obtain sensitive information and perform other attacks
VAR-201808-0746 | CVE-2018-11456 | Siemens Automation License Manager Information Disclosure Vulnerability |
CVSS V2: 5.0 CVSS V3: 5.8 Severity: MEDIUM |
A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network access to the device could send specially crafted network packets to determine whether or not a network port on another remote system is accessible or not. This allows the attacker to do basic network scanning using the victims machine. Successful exploitation requires a network connection to the affected device. The attacker does not need privileges, no user interaction is required. The impact is limited to determining whether or not a port on a target system is accessible by the affected device. The Siemens Automation License Manager is a Siemens system from Germany that handles remote and local certificates in HMI, SCADA and industrial products.
An attacker can exploit these issues using directory-traversal characters ('../') to access or read arbitrary files that contain sensitive information or to access files outside of the restricted directory or obtain sensitive information and perform other attacks
VAR-201808-0951 | CVE-2018-7070 | HPE CentralView Fraud Risk Management Vulnerable to information disclosure |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
HPE has identified a remote disclosure of information vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version
VAR-201808-0950 | CVE-2018-7069 | HPE CentralView Fraud Risk Management Vulnerabilities in authentication |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
HPE has identified a remote unauthenticated access to files vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version
VAR-201808-0949 | CVE-2018-7068 | HPE CentralView Fraud Risk Management In HTTP Request smuggling vulnerability |
CVSS V2: 5.8 CVSS V3: 6.1 Severity: MEDIUM |
HPE has identified a remote HOST header attack vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version
VAR-201808-0934 | CVE-2018-7078 | HPE Integrated Lights-Out 4 and HPE Integrated Lights-Out 5 Vulnerability in |
CVSS V2: 9.0 CVSS V3: 7.2 Severity: HIGH |
A remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integrated Lights-Out 5 (iLO 5) earlier than version v1.30. Through an integrated remote management port, Monitor and maintain the running status of the server, remotely manage and control the server, etc. An attacker could exploit this vulnerability to execute code
VAR-201808-1002 | CVE-2018-5390 | TCP implementations vulnerable to Denial of Service |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. An input validation error vulnerability exists in the Linux kernel version 4.9+. =========================================================================
Ubuntu Security Notice USN-3742-1
August 14, 2018
linux vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the Linux kernel. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker could use this to expose sensitive information (memory from the
kernel or other processes). (CVE-2018-3620)
Andrey Konovalov discovered an out-of-bounds read in the POSIX
timers subsystem in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash) or expose sensitive
information. A remote attacker could use this to cause a
denial of service. A remote attacker could use this to
cause a denial of service. (CVE-2018-5391)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-3.13.0-155-generic 3.13.0-155.205
linux-image-3.13.0-155-generic-lpae 3.13.0-155.205
linux-image-3.13.0-155-lowlatency 3.13.0-155.205
linux-image-3.13.0-155-powerpc-e500 3.13.0-155.205
linux-image-3.13.0-155-powerpc-e500mc 3.13.0-155.205
linux-image-3.13.0-155-powerpc-smp 3.13.0-155.205
linux-image-3.13.0-155-powerpc64-emb 3.13.0-155.205
linux-image-3.13.0-155-powerpc64-smp 3.13.0-155.205
linux-image-generic 3.13.0.155.165
linux-image-generic-lpae 3.13.0.155.165
linux-image-lowlatency 3.13.0.155.165
linux-image-powerpc-e500 3.13.0.155.165
linux-image-powerpc-e500mc 3.13.0.155.165
linux-image-powerpc-smp 3.13.0.155.165
linux-image-powerpc64-emb 3.13.0.155.165
linux-image-powerpc64-smp 3.13.0.155.165
Please note that the recommended mitigation for CVE-2018-3646 involves
updating processor microcode in addition to updating the kernel;
however, the kernel includes a fallback for processors that have not
received microcode updates.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well. (BZ#1625330)
4. Description:
The kernel-rt packages provide the Real Time Linux Kernel, which enables
fine-tuning for systems with extremely high determinism requirements.
Bug Fix(es):
* The kernel-rt packages have been upgraded to the 3.10.0-693.39.1 source
tree, which provides a number of bug fixes over the previous version.
(BZ#1616431)
* Previously, preemption was enabled too early after a context switch. If a
task was migrated to another CPU after a context switch, a mismatch between
CPU and runqueue during load balancing sometimes occurred. Consequently, a
runnable task on an idle CPU failed to run, and the operating system became
unresponsive. As a result, CPU migration during post-schedule processing no
longer occurs, which prevents the above mismatch. (BZ#1618466)
4.
CVE-2018-13405
Jann Horn discovered that the inode_init_owner function in
fs/inode.c in the Linux kernel allows local users to create files
with an unintended group ownership allowing attackers to escalate
privileges by making a plain file executable and SGID.
For the stable distribution (stretch), these problems have been fixed in
version 4.9.110-3+deb9u1. This update includes fixes for several
regressions in the latest point release.
For the detailed security status of linux please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/linux
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAltolY5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0T1cBAAhxrsiYuYMiQj9x+shNxxp6gWEXpDoOCwU0cXzZ2lii2uSPzP5TsIQey3
3nBjPCZthg8Q0fL2m0thbfS+i1HTT9tlJT7EjBGDjA0jm2o/lQCmH5rp8DDPtbwZ
2iZ9HyfosEFnbCd6VHtWIM3NoGZFUjvBWkb29/op800BqkHk69WchT1ZWSE8G85S
NAwG7tf/mfWIc0nYgieFo9i2X2bk0mNUOjC8xnVnK2TZY5jzK7f9fmQzdPAglZaI
t1UoQS4PMl6UTi7AJephorP6+6KJPg3n0rCgJYYXtnRO4PilSLveg7dNniKpCaDo
jJKVIcug8Hqo1zc6Uk0tgdZBPILZULyMGr7XUJ97cyA6i+9xhDpGPmqH6pbWQ+YZ
JplAY4PHZ2PUi+6is4LE7kYQfPk8+KvvshUB8Qr2Xa61GUDcgpdcaTmNmFYH3EAF
St27o/Nbs8WsKNzkOMxtyva88YJr7RDHr+nX/I1fKlI8zC8k3gHYYtJ11QhCDWKT
1O42ppxxaBUMo5ns0ZCjNBaMFPTaKrDYocAzhVot94I2++8InhFWbAzRq7B44fKe
E4Q6jDXY3x5MexSyZG3sGc6EwUtr/Gr8trB4TZkvNrQtZ9WBh28TOsldecGsncqw
I62eV7vx701dQDjtcDy/yZlGDjFTULQkyX8GPL9hIBeRjCFRhrA=
=h8it
-----END PGP SIGNATURE-----
. 6.5) - x86_64
3.
Bug Fix(es):
* Previously, invalid headers in the sk_buff struct led to an indefinite
loop in the tcp_collapse() function. (BZ#1619630)
* After updating the system to prevent the L1 Terminal Fault (L1TF)
vulnerability, only one thread was detected on systems that offer
processing of two threads on a single processor core. With this update, the
"__max_smt_threads()" function has been fixed. (BZ#1625333)
* Previously, a kernel panic occurred when the kernel tried to make an out
of bound access to the array that describes the L1 Terminal Fault (L1TF)
mitigation state on systems without Extended Page Tables (EPT) support.
This update extends the array of mitigation states to cover all the states,
which effectively prevents out of bound array access. Also, this update
enables rejecting invalid, irrelevant values, that might be erroneously
provided by the userspace. (BZ#1629632)
4. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Important: kernel security and bug fix update
Advisory ID: RHSA-2018:2785-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2018:2785
Issue date: 2018-09-25
CVE Names: CVE-2018-5390 CVE-2018-5391 CVE-2018-10675
====================================================================
1. Summary:
An update for kernel is now available for Red Hat Enterprise Linux 7.3
Extended Update Support.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux ComputeNode EUS (v. 7.3) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.3) - x86_64
Red Hat Enterprise Linux Server EUS (v. 7.3) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional EUS (v. 7.3) - ppc64, ppc64le, x86_64
3. Description:
The kernel packages contain the Linux kernel, the core of any Linux
operating system.
Security Fix(es):
* A flaw named SegmentSmack was found in the way the Linux kernel handled
specially crafted TCP packets. A remote attacker could use this flaw to
trigger time and calculation expensive calls to tcp_collapse_ofo_queue()
and tcp_prune_ofo_queue() functions by sending specially modified packets
within ongoing TCP sessions which could lead to a CPU saturation and hence
a denial of service on the system. Maintaining the denial of service
condition requires continuous two-way TCP sessions to a reachable open
port, thus the attacks cannot be performed using spoofed IP addresses.
(CVE-2018-5390)
* A flaw named FragmentSmack was found in the way the Linux kernel handled
reassembly of fragmented IPv4 and IPv6 packets. A remote attacker could use
this flaw to trigger time and calculation expensive fragment reassembly
algorithm by sending specially crafted packets which could lead to a CPU
saturation and hence a denial of service on the system. (CVE-2018-5391)
* kernel: mm: use-after-free in do_get_mempolicy function allows local DoS
or other unspecified impact (CVE-2018-10675)
For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.
Red Hat would like to thank Juha-Matti Tilli (Aalto University - Department
of Communications and Networking and Nokia Bell Labs) for reporting
CVE-2018-5390 and CVE-2018-5391.
Bug Fix(es):
* On systems running Red Hat Enterprise Linux 7 with Red Hat OpenShift
Container Platform 3.5, a node sometimes got into "NodeNotReady" state
after a CPU softlockup. Consequently, the node was not available. This
update fixes an irq latency source in memory compaction. As a result, nodes
no longer get into "NodeNotReady" state under the described circumstances.
(BZ#1596281)
* Previously, the kernel source code was missing support to report the
Speculative Store Bypass Disable (SSBD) vulnerability status on IBM Power
Systems and the little-endian variants of IBM Power Systems. As a
consequence, the /sys/devices/system/cpu/vulnerabilities/spec_store_bypass
file incorrectly reported "Not affected" on both CPU architectures. This
fix updates the kernel source code to properly report the SSBD status
either as "Vulnerable" or "Mitigation: Kernel entry/exit barrier (TYPE)"
where TYPE is one of "eieio", "hwsync", "fallback", or "unknown".
(BZ#1612351)
* The hypervisors of Red Hat Enterprise Linux 7 virtual machines (VMs) in
certain circumstances mishandled the microcode update in the kernel. As a
consequence, the VMs sometimes became unresponsive when booting. This
update applies an upstream patch to avoid early microcode update when
running under a hypervisor. As a result, kernel hangs no longer occur in
the described scenario. (BZ#1618388)
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
5. Bugs fixed (https://bugzilla.redhat.com/):
1575065 - CVE-2018-10675 kernel: mm: use-after-free in do_get_mempolicy function allows local DoS or other unspecified impact
1601704 - CVE-2018-5390 kernel: TCP segments with random offsets allow a remote denial of service (SegmentSmack)
1609664 - CVE-2018-5391 kernel: IP fragments with random offsets allow a remote denial of service (FragmentSmack)
6. Package List:
Red Hat Enterprise Linux ComputeNode EUS (v. 7.3):
Source:
kernel-3.10.0-514.58.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-514.58.1.el7.noarch.rpm
kernel-doc-3.10.0-514.58.1.el7.noarch.rpm
x86_64:
kernel-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debug-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-514.58.1.el7.x86_64.rpm
kernel-devel-3.10.0-514.58.1.el7.x86_64.rpm
kernel-headers-3.10.0-514.58.1.el7.x86_64.rpm
kernel-tools-3.10.0-514.58.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-514.58.1.el7.x86_64.rpm
perf-3.10.0-514.58.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
python-perf-3.10.0-514.58.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.3):
x86_64:
kernel-debug-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-514.58.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-514.58.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
Red Hat Enterprise Linux Server EUS (v. 7.3):
Source:
kernel-3.10.0-514.58.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-514.58.1.el7.noarch.rpm
kernel-doc-3.10.0-514.58.1.el7.noarch.rpm
ppc64:
kernel-3.10.0-514.58.1.el7.ppc64.rpm
kernel-bootwrapper-3.10.0-514.58.1.el7.ppc64.rpm
kernel-debug-3.10.0-514.58.1.el7.ppc64.rpm
kernel-debug-debuginfo-3.10.0-514.58.1.el7.ppc64.rpm
kernel-debug-devel-3.10.0-514.58.1.el7.ppc64.rpm
kernel-debuginfo-3.10.0-514.58.1.el7.ppc64.rpm
kernel-debuginfo-common-ppc64-3.10.0-514.58.1.el7.ppc64.rpm
kernel-devel-3.10.0-514.58.1.el7.ppc64.rpm
kernel-headers-3.10.0-514.58.1.el7.ppc64.rpm
kernel-tools-3.10.0-514.58.1.el7.ppc64.rpm
kernel-tools-debuginfo-3.10.0-514.58.1.el7.ppc64.rpm
kernel-tools-libs-3.10.0-514.58.1.el7.ppc64.rpm
perf-3.10.0-514.58.1.el7.ppc64.rpm
perf-debuginfo-3.10.0-514.58.1.el7.ppc64.rpm
python-perf-3.10.0-514.58.1.el7.ppc64.rpm
python-perf-debuginfo-3.10.0-514.58.1.el7.ppc64.rpm
ppc64le:
kernel-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-bootwrapper-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-debug-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-debug-debuginfo-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-debuginfo-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-debuginfo-common-ppc64le-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-devel-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-headers-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-tools-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-tools-debuginfo-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-tools-libs-3.10.0-514.58.1.el7.ppc64le.rpm
perf-3.10.0-514.58.1.el7.ppc64le.rpm
perf-debuginfo-3.10.0-514.58.1.el7.ppc64le.rpm
python-perf-3.10.0-514.58.1.el7.ppc64le.rpm
python-perf-debuginfo-3.10.0-514.58.1.el7.ppc64le.rpm
s390x:
kernel-3.10.0-514.58.1.el7.s390x.rpm
kernel-debug-3.10.0-514.58.1.el7.s390x.rpm
kernel-debug-debuginfo-3.10.0-514.58.1.el7.s390x.rpm
kernel-debug-devel-3.10.0-514.58.1.el7.s390x.rpm
kernel-debuginfo-3.10.0-514.58.1.el7.s390x.rpm
kernel-debuginfo-common-s390x-3.10.0-514.58.1.el7.s390x.rpm
kernel-devel-3.10.0-514.58.1.el7.s390x.rpm
kernel-headers-3.10.0-514.58.1.el7.s390x.rpm
kernel-kdump-3.10.0-514.58.1.el7.s390x.rpm
kernel-kdump-debuginfo-3.10.0-514.58.1.el7.s390x.rpm
kernel-kdump-devel-3.10.0-514.58.1.el7.s390x.rpm
perf-3.10.0-514.58.1.el7.s390x.rpm
perf-debuginfo-3.10.0-514.58.1.el7.s390x.rpm
python-perf-3.10.0-514.58.1.el7.s390x.rpm
python-perf-debuginfo-3.10.0-514.58.1.el7.s390x.rpm
x86_64:
kernel-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debug-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-514.58.1.el7.x86_64.rpm
kernel-devel-3.10.0-514.58.1.el7.x86_64.rpm
kernel-headers-3.10.0-514.58.1.el7.x86_64.rpm
kernel-tools-3.10.0-514.58.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-514.58.1.el7.x86_64.rpm
perf-3.10.0-514.58.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
python-perf-3.10.0-514.58.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
Red Hat Enterprise Linux Server Optional EUS (v. 7.3):
ppc64:
kernel-debug-debuginfo-3.10.0-514.58.1.el7.ppc64.rpm
kernel-debuginfo-3.10.0-514.58.1.el7.ppc64.rpm
kernel-debuginfo-common-ppc64-3.10.0-514.58.1.el7.ppc64.rpm
kernel-tools-debuginfo-3.10.0-514.58.1.el7.ppc64.rpm
kernel-tools-libs-devel-3.10.0-514.58.1.el7.ppc64.rpm
perf-debuginfo-3.10.0-514.58.1.el7.ppc64.rpm
python-perf-debuginfo-3.10.0-514.58.1.el7.ppc64.rpm
ppc64le:
kernel-debug-debuginfo-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-debug-devel-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-debuginfo-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-debuginfo-common-ppc64le-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-tools-debuginfo-3.10.0-514.58.1.el7.ppc64le.rpm
kernel-tools-libs-devel-3.10.0-514.58.1.el7.ppc64le.rpm
perf-debuginfo-3.10.0-514.58.1.el7.ppc64le.rpm
python-perf-debuginfo-3.10.0-514.58.1.el7.ppc64le.rpm
x86_64:
kernel-debug-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-514.58.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-514.58.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-514.58.1.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2018-5390
https://access.redhat.com/security/cve/CVE-2018-5391
https://access.redhat.com/security/cve/CVE-2018-10675
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2018 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBW6qe7NzjgjWX9erEAQjNbQ/+IKrFgUV0KKr007GhsyzJeLCUqTrNBcio
bsIWQDFE/sV/deohMIBHybvxBeiZkUe8D+d/IcNS/0a1+jSNWytdahR8AO5PdjF1
QxXXnteY7glupPg7oBJzNVtrfWmvo6M7jH2U+EQ0w5agSIBQ+WFChXH5hMwXxx8f
nW7hs3ToSWJyrAo6VRQ9IX3goBskn6qIcbTsp4lMNhGa1gQPOFvoT0DyK7V32TWT
KmNAK13XYd8nP402PUUyN72HksPwW5fJNG5bQIYUp07WGOgiKt0X8vAgzaSX9srd
LBxMG+TP8IJjrNe3RUC/kD3BJ+n7BYp0hnYr1y2k09qHDrDP7K0qP63fRBPQ+xPs
3gQmmz9AICgF+xA95onoREUJp6rqydFb92OsebwRb2aZ4ho084M7GTsKe7cZn4zL
oUXFafA7Tjir+K0oyOLsAF/ieIvzHt35IJKFECXZuAuomgsTTh92DLnMurszyNmi
IzIZbenNNhPV6qGLD1gANzvaaRKZNhJVh1DAZgWaMqOf/xZYE2n1mO8XAj5/m97T
Sz4RCOUVFMTgcFAQFWv29uLtV0c8gd6X9QNiYeDGqoADskwGpSdBKuNlnHFaOv86
gWhCLv9cY+N8IbrjtSSugY6zzBStigEQ+2BSrqh7YvVjkRhpIqHql0yJzCknPtIh
un3AsdlsrV4=O9gE
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce