VARIoT IoT vulnerabilities database
| VAR-201812-0271 | CVE-2018-18311 | Perl Multiple Buffer Overflow Vulnerabilities |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. Perl is prone to the following multiple buffer-overflow vulnerabilities because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
1. An integer-overflow vulnerability
2. A heap-based buffer-overflow vulnerability
Attackers can exploit these issues to execute arbitrary code on the affected application. Failed attempts will likely cause a denial-of-service condition. 7.4) - ppc64, ppc64le, s390x, x86_64
3. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Important: rh-perl526-perl security and enhancement update
Advisory ID: RHSA-2019:0001-01
Product: Red Hat Software Collections
Advisory URL: https://access.redhat.com/errata/RHSA-2019:0001
Issue date: 2019-01-02
CVE Names: CVE-2018-18311 CVE-2018-18312 CVE-2018-18313
CVE-2018-18314
====================================================================
1. Summary:
An update for rh-perl526-perl and rh-perl526-perl-Module-CoreList is now
available for Red Hat Software Collections.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section. Relevant releases/architectures:
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - aarch64, noarch, ppc64le, s390x, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4) - noarch, ppc64le, s390x, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - noarch, ppc64le, s390x, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch, ppc64le, s390x, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
3. Description:
Perl is a high-level programming language that is commonly used for system
administration utilities and web programming.
The following packages have been upgraded to a later upstream version:
rh-perl526-perl (5.26.3), rh-perl526-perl-Module-CoreList (5.20181130).
Red Hat would like to thank the Perl project for reporting these issues.
Upstream acknowledges Jayakrishna Menon as the original reporter of
CVE-2018-18311; Eiichi Tsukata as the original reporter of CVE-2018-18312
and CVE-2018-18313; and Jakub Wilk as the original reporter of
CVE-2018-18314. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Package List:
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source:
rh-perl526-perl-5.26.3-405.el7.src.rpm
rh-perl526-perl-Module-CoreList-5.20181130-1.el7.src.rpm
aarch64:
rh-perl526-perl-debuginfo-5.26.3-405.el7.aarch64.rpm
noarch:
rh-perl526-perl-ExtUtils-Miniperl-1.06-405.el7.noarch.rpm
rh-perl526-perl-Module-CoreList-tools-5.20181130-1.el7.noarch.rpm
ppc64le:
rh-perl526-perl-debuginfo-5.26.3-405.el7.ppc64le.rpm
s390x:
rh-perl526-perl-debuginfo-5.26.3-405.el7.s390x.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source:
rh-perl526-perl-5.26.3-405.el7.src.rpm
rh-perl526-perl-Module-CoreList-5.20181130-1.el7.src.rpm
aarch64:
rh-perl526-perl-debuginfo-5.26.3-405.el7.aarch64.rpm
noarch:
rh-perl526-perl-ExtUtils-Miniperl-1.06-405.el7.noarch.rpm
rh-perl526-perl-Module-CoreList-tools-5.20181130-1.el7.noarch.rpm
ppc64le:
rh-perl526-perl-debuginfo-5.26.3-405.el7.ppc64le.rpm
s390x:
rh-perl526-perl-debuginfo-5.26.3-405.el7.s390x.rpm
x86_64:
rh-perl526-perl-debuginfo-5.26.3-405.el7.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4):
Source:
rh-perl526-perl-5.26.3-405.el7.src.rpm
rh-perl526-perl-Module-CoreList-5.20181130-1.el7.src.rpm
noarch:
rh-perl526-perl-ExtUtils-Miniperl-1.06-405.el7.noarch.rpm
rh-perl526-perl-Module-CoreList-tools-5.20181130-1.el7.noarch.rpm
ppc64le:
rh-perl526-perl-debuginfo-5.26.3-405.el7.ppc64le.rpm
s390x:
rh-perl526-perl-debuginfo-5.26.3-405.el7.s390x.rpm
x86_64:
rh-perl526-perl-debuginfo-5.26.3-405.el7.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5):
Source:
rh-perl526-perl-5.26.3-405.el7.src.rpm
rh-perl526-perl-Module-CoreList-5.20181130-1.el7.src.rpm
noarch:
rh-perl526-perl-ExtUtils-Miniperl-1.06-405.el7.noarch.rpm
rh-perl526-perl-Module-CoreList-tools-5.20181130-1.el7.noarch.rpm
ppc64le:
rh-perl526-perl-debuginfo-5.26.3-405.el7.ppc64le.rpm
s390x:
rh-perl526-perl-debuginfo-5.26.3-405.el7.s390x.rpm
x86_64:
rh-perl526-perl-debuginfo-5.26.3-405.el7.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6):
Source:
rh-perl526-perl-5.26.3-405.el7.src.rpm
rh-perl526-perl-Module-CoreList-5.20181130-1.el7.src.rpm
noarch:
rh-perl526-perl-ExtUtils-Miniperl-1.06-405.el7.noarch.rpm
rh-perl526-perl-Module-CoreList-tools-5.20181130-1.el7.noarch.rpm
ppc64le:
rh-perl526-perl-debuginfo-5.26.3-405.el7.ppc64le.rpm
s390x:
rh-perl526-perl-debuginfo-5.26.3-405.el7.s390x.rpm
x86_64:
rh-perl526-perl-debuginfo-5.26.3-405.el7.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):
Source:
rh-perl526-perl-5.26.3-405.el7.src.rpm
rh-perl526-perl-Module-CoreList-5.20181130-1.el7.src.rpm
noarch:
rh-perl526-perl-ExtUtils-Miniperl-1.06-405.el7.noarch.rpm
rh-perl526-perl-Module-CoreList-tools-5.20181130-1.el7.noarch.rpm
x86_64:
rh-perl526-perl-debuginfo-5.26.3-405.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2018-18311
https://access.redhat.com/security/cve/CVE-2018-18312
https://access.redhat.com/security/cve/CVE-2018-18313
https://access.redhat.com/security/cve/CVE-2018-18314
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2019 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBXCy849zjgjWX9erEAQiXIg//cI7ip/fpdKxDY3ocRErsTuP56XwJMm/P
f7yqJCsxgc+wNRoRVH+w7YuZbRrBK6PCIyVLJQrel6KLhA6ighkcZ06QqpnfqGzw
vTBd12DkswFHOE9YqTrsNoTOGA1NDJMcAWiNYqLb94fa8tyIBCqZvqyc03xx8AZ4
DhBiP/mH8kPoE6PSy8lF6rHUeQ+ZOfIRtY4SQMhch93+Dy1p+C8ZAQoFSaxEMcJA
2F9HHGHdVKevL410rIZGS/ajFTvK8equ8tJrF4E522z8TJaLpG5mED3qP55n9bL2
lT11Bw0H6pWPHj79j/kJEvgO/Sj8TvRYh42gFfTO70qS/J+Dry+uk8DJ8Fgbz9m5
1m7GKDZQbFRsENINJ6UW5gYBWqXlyMXFtKSk8mCFskRiu6qgYEg1FC4Tx3Mc/ol4
6rIpTzD4aOm1GnoZTd0dVr07d1PVlnent+e7rUTOXLsSfrNfqdHzbvBWbaDiO3Uf
m2s12eX5FG1LVQfgBHbQZSp5DRy6nc026D5k3ZT8kBxT8iamGQ6ViviN8rgGAVbp
GAcetodEj9RWOqVtuAIk1Qy6u05m/IIMiwwenMLwpIFpLU8doLXEmdXsMOH+FFQ8
b0+CXdpeJYZCWxf1eeEGP3viRw1oCadJ8dc2ryS1UKFmkDkfXyGPWqXJucwmJGeb
pIOXYDWz3Ao=jT/b
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
. The Common Vulnerabilities and Exposures
project identifies the following problems:
CVE-2018-18311
Jayakrishna Menon and Christophe Hauser discovered an integer
overflow vulnerability in Perl_my_setenv leading to a heap-based
buffer overflow with attacker-controlled input.
For the stable distribution (stretch), these problems have been fixed in
version 5.24.1-3+deb9u5.
We recommend that you upgrade your perl packages. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 201909-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: Perl: Multiple vulnerabilities
Date: September 06, 2019
Bugs: #653432, #670190
ID: 201909-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities have been found in Perl, the worst of which
could result in the arbitrary execution of code.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-lang/perl < 5.28.2 >= 5.28.2
Description
===========
Multiple vulnerabilities have been discovered in Perl. Please review
the CVE identifiers referenced below for details.
Impact
======
Please review the referenced CVE identifiers for details.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All Perl users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/perl-5.28.2"
References
==========
[ 1 ] CVE-2018-18311
https://nvd.nist.gov/vuln/detail/CVE-2018-18311
[ 2 ] CVE-2018-18312
https://nvd.nist.gov/vuln/detail/CVE-2018-18312
[ 3 ] CVE-2018-18313
https://nvd.nist.gov/vuln/detail/CVE-2018-18313
[ 4 ] CVE-2018-18314
https://nvd.nist.gov/vuln/detail/CVE-2018-18314
[ 5 ] CVE-2018-6797
https://nvd.nist.gov/vuln/detail/CVE-2018-6797
[ 6 ] CVE-2018-6798
https://nvd.nist.gov/vuln/detail/CVE-2018-6798
[ 7 ] CVE-2018-6913
https://nvd.nist.gov/vuln/detail/CVE-2018-6913
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/201909-01
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2019 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
APPLE-SA-2019-3-25-2 macOS Mojave 10.14.4, Security Update
2019-002 High Sierra, Security Update 2019-002 Sierra
macOS Mojave 10.14.4, Security Update 2019-002 High Sierra,
Security Update 2019-002 Sierra are now available and
addresses the following:
AppleGraphicsControl
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A malicious application may be able to execute arbitrary code
with kernel privileges
Description: A buffer overflow was addressed with improved size
validation.
CVE-2019-8555: Zhiyi Zhang of 360 ESG Codesafe Team, Zhuo Liang and
shrek_wzw of Qihoo 360 Nirvan Team
Bom
Available for: macOS Mojave 10.14.3
Impact: A malicious application may bypass Gatekeeper checks
Description: This issue was addressed with improved handling of file
metadata.
CVE-2019-6239: Ian Moorhouse and Michael Trimm
CFString
Available for: macOS Mojave 10.14.3
Impact: Processing a maliciously crafted string may lead to a denial
of service
Description: A validation issue was addressed with improved logic.
CVE-2019-8516: SWIPS Team of Frifee Inc.
configd
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to elevate privileges
Description: A memory initialization issue was addressed with
improved memory handling.
CVE-2019-8552: Mohamed Ghannam (@_simo36)
Contacts
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to elevate privileges
Description: A buffer overflow issue was addressed with improved
memory handling.
CVE-2019-8511: an anonymous researcher
CoreCrypto
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to elevate privileges
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2019-8542: an anonymous researcher
DiskArbitration
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: An encrypted volume may be unmounted and remounted by a
different user without prompting for the password
Description: A logic issue was addressed with improved state
management.
CVE-2019-8522: Colin Meginnis (@falc420)
FaceTime
Available for: macOS Mojave 10.14.3
Impact: A user's video may not be paused in a FaceTime call if they
exit the FaceTime app while the call is ringing
Description: An issue existed in the pausing of FaceTime video. The
issue was resolved with improved logic.
CVE-2019-8550: Lauren Guzniczak of Keystone Academy
Feedback Assistant
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to gain root privileges
Description: A race condition was addressed with additional
validation.
CVE-2019-8565: CodeColorist of Ant-Financial LightYear Labs
Feedback Assistant
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A malicious application may be able to overwrite arbitrary
files
Description: This issue was addressed with improved checks.
CVE-2019-8521: CodeColorist of Ant-Financial LightYear Labs
file
Available for: macOS Mojave 10.14.3
Impact: Processing a maliciously crafted file might disclose user
information
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2019-6237: an anonymous researcher
Graphics Drivers
Available for: macOS Mojave 10.14.3
Impact: An application may be able to read restricted memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2019-8519: Aleksandr Tarasikov (@astarasikov), Juwei Lin
(@panicaII) and Junzhi Lu of Trend Micro Research working with Trend
Micro's Zero Day Initiative
iAP
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to elevate privileges
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2019-8542: an anonymous researcher
IOGraphics
Available for: macOS Mojave 10.14.3
Impact: A Mac may not lock when disconnecting from an external
monitor
Description: A lock handling issue was addressed with improved lock
handling.
CVE-2019-8533: an anonymous researcher, James Eagan of Télécom
ParisTech, R. Scott Kemp of MIT, Romke van Dijk of Z-CERT
IOHIDFamily
Available for: macOS Mojave 10.14.3
Impact: A local user may be able to cause unexpected system
termination or read kernel memory
Description: A memory corruption issue was addressed with improved
state management.
CVE-2019-8545: Adam Donenfeld (@doadam) of the Zimperium zLabs Team
IOKit
Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.3
Impact: A local user may be able to read kernel memory
Description: A memory initialization issue was addressed with
improved memory handling.
CVE-2019-8504: an anonymous researcher
IOKit SCSI
Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.3
Impact: An application may be able to execute arbitrary code with
kernel privileges
Description: A memory corruption issue was addressed with improved
input validation.
CVE-2019-8529: Juwei Lin (@panicaII) of Trend Micro
Kernel
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A remote attacker may be able to cause unexpected system
termination or corrupt kernel memory
Description: A buffer overflow was addressed with improved size
validation.
CVE-2019-8527: Ned Williamson of Google and derrek (@derrekr6)
Kernel
Available for: macOS Sierra 10.12.6, macOS Mojave 10.14.3
Impact: Mounting a maliciously crafted NFS network share may lead to
arbitrary code execution with system privileges
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2019-8508: Dr. Silvio Cesare of InfoSect
Kernel
Available for: macOS Mojave 10.14.3
Impact: An application may be able to gain elevated privileges
Description: A logic issue was addressed with improved state
management.
CVE-2019-8514: Samuel Groß of Google Project Zero
Kernel
Available for: macOS Sierra 10.12.6, macOS Mojave 10.14.3
Impact: A malicious application may be able to determine kernel
memory layout
Description: A memory initialization issue was addressed with
improved memory handling.
CVE-2019-8540: Weibo Wang (@ma1fan) of Qihoo 360 Nirvan Team
Kernel
Available for: macOS Mojave 10.14.3
Impact: A local user may be able to read kernel memory
Description: A memory corruption issue was addressed with improved
memory handling.
CVE-2019-7293: Ned Williamson of Google
Kernel
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A malicious application may be able to determine kernel
memory layout
Description: An out-of-bounds read issue existed that led to the
disclosure of kernel memory. This was addressed with improved input
validation.
CVE-2019-6207: Weibo Wang of Qihoo 360 Nirvan Team (@ma1fan)
CVE-2019-8510: Stefan Esser of Antid0te UG
Messages
Available for: macOS Mojave 10.14.3
Impact: A local user may be able to view sensitive user information
Description: An access issue was addressed with additional sandbox
restrictions.
CVE-2019-8546: ChiYuan Chang
Notes
Available for: macOS Mojave 10.14.3
Impact: A local user may be able to view a user's locked notes
Description: An access issue was addressed with improved memory
management.
CVE-2019-8537: Greg Walker (gregwalker.us)
PackageKit
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A malicious application may be able to elevate privileges
Description: A logic issue was addressed with improved validation.
CVE-2019-8561: Jaron Bradley of Crowdstrike
Perl
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: Multiple issues in Perl
Description: Multiple issues in Perl were addressed in this update.
CVE-2018-12015: Jakub Wilk
CVE-2018-18311: Jayakrishna Menon
CVE-2018-18313: Eiichi Tsukata
Power Management
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to execute arbitrary code
with system privileges
Description: Multiple input validation issues existed in MIG
generated code. These issues were addressed with improved validation.
CVE-2019-8549: Mohamed Ghannam (@_simo36) of SSD Secure Disclosure
(ssd-disclosure.com)
QuartzCore
Available for: macOS Mojave 10.14.3
Impact: Processing malicious data may lead to unexpected application
termination
Description: Multiple memory corruption issues were addressed with
improved input validation.
CVE-2019-8507: Kai Lu or Fortinet's FortiGuard Labs
Security
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: An application may be able to gain elevated privileges
Description: A use after free issue was addressed with improved
memory management.
CVE-2019-8526: Linus Henze (pinauten.de)
Security
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A malicious application may be able to read restricted memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2019-8520: Antonio Groza, The UK's National Cyber Security Centre
(NCSC)
Siri
Available for: macOS Mojave 10.14.3
Impact: A malicious application may be able to initiate a Dictation
request without user authorization
Description: An API issue existed in the handling of dictation
requests. This issue was addressed with improved validation.
CVE-2019-8502: Luke Deshotels of North Carolina State University,
Jordan Beichler of North Carolina State University, William Enck of
North Carolina State University, Costin Carabaș of University
POLITEHNICA of Bucharest, and Răzvan Deaconescu of University
POLITEHNICA of Bucharest
Time Machine
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14.3
Impact: A local user may be able to execute arbitrary shell commands
Description: This issue was addressed with improved checks.
CVE-2019-8513: CodeColorist of Ant-Financial LightYear Labs
TrueTypeScaler
Available for: macOS Mojave 10.14.3
Impact: Processing a maliciously crafted font may result in the
disclosure of process memory
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2019-8517: riusksk of VulWar Corp working with Trend Micro Zero
Day Initiative
XPC
Available for: macOS Sierra 10.12.6, macOS Mojave 10.14.3
Impact: A malicious application may be able to overwrite arbitrary
files
Description: This issue was addressed with improved checks.
CVE-2019-8530: CodeColorist of Ant-Financial LightYear Labs
Additional recognition
Accounts
We would like to acknowledge Milan Stute of Secure Mobile Networking
Lab at Technische Universität Darmstadt for their assistance.
Books
We would like to acknowledge Yiğit Can YILMAZ (@yilmazcanyigit) for
their assistance.
Kernel
We would like to acknowledge Brandon Azad of Google Project Zero for
their assistance.
Mail
We would like to acknowledge Craig Young of Tripwire VERT and Hanno
Böck for their assistance.
Time Machine
We would like to acknowledge CodeColorist of Ant-Financial LightYear
Labs for their assistance.
Installation note:
macOS Mojave 10.14.4, Security Update 2019-002 High Sierra,
Security Update 2019-002 Sierra may be obtained from the
Mac App Store or Apple's Software Downloads web site:
https://support.apple.com/downloads/
Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222
This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----
iQJdBAEBCABHFiEEDNXJVNCJJEAVmJdZeC9tht7TK3EFAlyZWQgpHHByb2R1Y3Qt
c2VjdXJpdHktbm9yZXBseUBsaXN0cy5hcHBsZS5jb20ACgkQeC9tht7TK3E4zA/9
FvnChJHCmmH34DmCi+LGXO/fatCVVvvSHDWm1+bPjl8CeYcF+zZYACkQKxFoNpDT
vyiBJnNveCQEHeBvqSyRF8dfsTf4fr0MrFS1uIQVRPf2St6fZ27vDnC6fg269r0D
Eqnz0raFUa3bLUirteRMJwAqdGaVKwsNzM13qP4QEdrB14XkwZA0yQBunltFYU33
iAesKeejDLdhwkjfhmmjTlVPZmnABx2ZCfj2v7TiPxTOjfYbXcN8sY2LDHEOWNaM
ucrGBMfGH/ehStXAsIArwcLGOl6SI+6JywWVcm9lG6jUHSeSk9BPF6R4JzGrEHZB
sSo87+U8b63KA2GkYecwh6xvE5EchQku/fj0d2zbOlg+T2bMbyc6Al2nefsYnX5p
7BuhdZxqq3m3Gme2qRY0eye6wch1BTHhK+zctrVH2XeMaUpeanopVRI8AD+hZJ1J
+9oQX8kSa7hzJYPmohA4Wi/Rp9FpKpgXYNBn1A9DgSAvf+eyfWJX0aZXmQZfn/k7
OLz3EmSKvXv0i67L9g2XYeX7GFBMqf4xWeztKLUYFafu73t1mTxZJICcYeTxebS0
zBJdkOHwP9GxsSonblDgPScQPdW85l0fangn7qqiexCVp4JsCGBc0Wuy1lc+MyzS
1YmrDRhRl4aYOf4UGgtKI6ncvM77Y30ECPV3A6vl+wk=
=QV0f
-----END PGP SIGNATURE-----
. ==========================================================================
Ubuntu Security Notice USN-3834-1
December 03, 2018
perl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.10
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in Perl.
Software Description:
- perl: Practical Extraction and Report Language
Details:
Jayakrishna Menon discovered that Perl incorrectly handled Perl_my_setenv. (CVE-2018-18311)
Eiichi Tsukata discovered that Perl incorrectly handled certain regular
expressions. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 18.10.
(CVE-2018-18312)
Eiichi Tsukata discovered that Perl incorrectly handled certain regular
expressions. An attacker could use this issue to cause Perl to crash,
resulting in a denial of service. (CVE-2018-18313)
Jakub Wilk discovered that Perl incorrectly handled certain regular
expressions. An attacker could use this issue to cause Perl to crash,
resulting in a denial of service. This issue only affected Ubuntu 16.04
LTS, Ubuntu 18.04 LTS, and Ubuntu 18.10. (CVE-2018-18314)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.10:
perl 5.26.2-7ubuntu0.1
Ubuntu 18.04 LTS:
perl 5.26.1-6ubuntu0.3
Ubuntu 16.04 LTS:
perl 5.22.1-9ubuntu0.6
Ubuntu 14.04 LTS:
perl 5.18.2-2ubuntu1.7
In general, a standard system update will make all the necessary changes. This update provides
the corresponding update for Ubuntu 12.04 ESM
| VAR-201811-0567 | CVE-2018-7811 | plural Modicon Vulnerability related to password management function in products |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web server. plural Modicon The product contains a vulnerability related to the password management function.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Schneider Electric Modicon M340 and other are programmable logic controller products of Schneider Electric (France).
A number of Schneider Electric products have licensing issues. An attacker could use the / unsecure / embedded / builtin endpoint to exploit this vulnerability to change a user's password without authentication
| VAR-201901-0829 | CVE-2018-16183 | Panasonic applications register unquoted service paths |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
An unquoted search path vulnerability in some pre-installed applications on Panasonic PC run on Windows 7 (32bit), Windows 7 (64bit), Windows 8 (64bit), Windows 8.1 (64bit), Windows 10 (64bit) delivered in or later than October 2009 allow local users to gain privileges via a Trojan horse executable file and execute arbitrary code with eleveted privileges. Some pre-installed applications on Panasonic PCs register Windows services with unquoted file paths (CWE-428). Panasonic Corporation reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and Panasonic Corporation coordinated under the Information Security Early Warning Partnership.If a malicious executable is placed on a certain path, it may be executed with the elevated privilege. PanasonicPC is a computer device from Matsushita Electric Industrial Co., Ltd. of Japan. An attacker could exploit the vulnerability to execute files with elevated privileges
| VAR-201811-0569 | CVE-2018-7831 | plural Modicon Product cross-site request forgery vulnerability |
CVSS V2: 4.3 CVSS V3: 8.8 Severity: HIGH |
An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to send a specially crafted URL to a currently authenticated web server user to execute a password change on the web server. plural Modicon The product contains a cross-site request forgery vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. SchneiderElectricModiconM340 and others are programmable logic controller products from Schneider Electric of France
| VAR-201812-0945 | CVE-2018-7987 | Huawei P20 Smartphone out-of-bounds vulnerability |
CVSS V2: 4.3 CVSS V3: 5.9 Severity: MEDIUM |
There is an out-of-bounds write vulnerability on Huawei P20 smartphones with versions before 8.1.0.171(C00). The software does not handle the response message properly when the user doing certain inquiry operation, an attacker could send crafted message to the device, successful exploit could cause a denial of service condition. HuaweiP20 is a smartphone of Huawei. HuaweiP20 has a memory write cross-border vulnerability. The successful use of this vulnerability can cause the mobile phone to refuse service
| VAR-201811-0566 | CVE-2018-7810 | plural Modicon Product cross-site scripting vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to craft a URL containing JavaScript that will be executed within the user's browser, potentially impacting the machine the browser is running on. plural Modicon The product contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. SchneiderElectricModiconM340 and others are programmable logic controller products from Schneider Electric of France
| VAR-201811-0565 | CVE-2018-7809 | plural Modicon Vulnerability related to password management function in products |
CVSS V2: 6.4 CVSS V3: 9.8 Severity: CRITICAL |
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the password delete function of the web server. plural Modicon The product contains a vulnerability related to the password management function.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Schneider Electric Modicon M340 and other are programmable logic controller products of Schneider Electric (France).
Unknown vulnerabilities in multiple Schneider Electric products. An attacker could use this vulnerability to delete or reset an existing username and password
| VAR-201811-0568 | CVE-2018-7830 | plural Modicon In product HTTP Response splitting vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a denial of service can occur for ~1 minute by sending a specially crafted HTTP request. plural Modicon The product includes HTTP A vulnerability related to response splitting exists.Service operation interruption (DoS) There is a possibility of being put into a state. SchneiderElectricModiconM340 and others are programmable logic controller products from Schneider Electric of France
| VAR-201811-0501 | CVE-2018-9072 | Vmware for LXCI Input validation vulnerability |
CVSS V2: 4.0 CVSS V3: 6.5 Severity: MEDIUM |
In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file downloads. Vmware for LXCI Contains an input validation vulnerability.Information may be obtained. Lenovo XClarity Integrator is prone to multiple security vulnerabilities:
1. An arbitrary-file-download vulnerability
2. An arbitrary file-overwrite vulnerability
Attackers can overwrite arbitrary files on an unsuspecting user's computer in the context of the vulnerable application or download arbitrary files from the device filesystem and obtain potentially sensitive information..
The following versions of Lenovo XClarity Integrator are vulnerable:
Lenovo XClarity Integrator for VMware versions prior to 5.5 are vulnerable.Lenovo XClarity Integrator for Microsoft System Center versions prior to 3.5 are vulnerable. Lenovo XClarity Integrator (LXCI) for Vmware is an application for Vmware from China Lenovo (Lenovo). The program offers extended capabilities such as infrastructure resource management, automation and IT service management. The vulnerability stems from the fact that the program does not adequately filter the input when downloading files
| VAR-201811-0333 | CVE-2018-16093 | Vmware for LXCI Vulnerable to unlimited upload of dangerous types of files |
CVSS V2: 4.0 CVSS V3: 6.5 Severity: MEDIUM |
In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient sanitization during the upload of a backup file. Vmware for LXCI Contains a vulnerability related to unlimited uploads of dangerous types of files.Information may be tampered with. Lenovo XClarity Integrator is prone to multiple security vulnerabilities:
1. An arbitrary-file-download vulnerability
2. An arbitrary file-overwrite vulnerability
Attackers can overwrite arbitrary files on an unsuspecting user's computer in the context of the vulnerable application or download arbitrary files from the device filesystem and obtain potentially sensitive information..
The following versions of Lenovo XClarity Integrator are vulnerable:
Lenovo XClarity Integrator for VMware versions prior to 5.5 are vulnerable.Lenovo XClarity Integrator for Microsoft System Center versions prior to 3.5 are vulnerable. Lenovo XClarity Integrator (LXCI) for Vmware is an application for Vmware from China Lenovo (Lenovo). The program offers extended capabilities such as infrastructure resource management, automation and IT service management. The vulnerability stems from the fact that the program does not perform sufficient filtering when uploading backup files
| VAR-201811-0337 | CVE-2018-16097 | VMware For and Microsoft System Center for LXCI Vulnerable to unlimited upload of dangerous types of files |
CVSS V2: 4.0 CVSS V3: 6.5 Severity: MEDIUM |
LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate. VMware For and Microsoft System Center for LXCI Contains a vulnerability related to unlimited uploads of dangerous types of files.Information may be tampered with. Lenovo XClarity Integrator is prone to multiple security vulnerabilities:
1. An arbitrary-file-download vulnerability
2. An arbitrary file-overwrite vulnerability
Attackers can overwrite arbitrary files on an unsuspecting user's computer in the context of the vulnerable application or download arbitrary files from the device filesystem and obtain potentially sensitive information.. Lenovo XClarity Integrator (LXCI) for Vmware is an application for Vmware from China Lenovo (Lenovo). The program offers extended capabilities such as infrastructure resource management, automation and IT service management. LXCI for Microsoft System Center is the version for Microsoft System Center. The vulnerability stems from insufficient verification when uploading certificates
| VAR-201812-0558 | CVE-2018-19665 | QEMU Integer overflow vulnerability |
CVSS V2: 2.7 CVSS V3: 5.7 Severity: MEDIUM |
The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption. QEMU Contains an integer overflow vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. QEMU is prone to an integer-overflow vulnerability because it fails to adequately bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
Attackers can exploit this issue to crash the QEMU instance, resulting in a denial-of-service condition. Due to the nature of this issue, code execution may be possible but this has not been confirmed
| VAR-201811-0075 | CVE-2018-12239 | plural Symantec Vulnerabilities related to security functions in products |
CVSS V2: 4.6 CVSS V3: 6.8 Severity: MEDIUM |
Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to NIS-22.15.1.8 & SEP-12.1.7454.7000; and Symantec Endpoint Protection Cloud (SEP Cloud) prior to 22.15.1 may be susceptible to an AV bypass issue, which is a type of exploit that works to circumvent one of the virus detection engines to avoid a specific type of virus protection. One of the antivirus engines depends on a signature pattern from a database to identify malicious files and viruses; the antivirus bypass exploit looks to alter the file being scanned so it is not detected. plural Symantec The product contains vulnerabilities related to security functions.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Multiple Symantec Products are prone to an local security-bypass vulnerability.
Local attackers can exploit this issue to bypass certain security restrictions to perform unauthorized actions. This may aid in further attacks. Symantec Norton and others are products of Symantec Corporation of the United States. Symantec Norton is an antivirus program. Endpoint Protection (SEP) is an endpoint protection program. Attackers can exploit this vulnerability to bypass detection by virus detection engines
| VAR-201811-0074 | CVE-2018-12238 | plural Symantec Vulnerabilities related to security functions in products |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to NIS-22.15.1.8 & SEP-12.1.7454.7000; and Symantec Endpoint Protection Cloud (SEP Cloud) prior to 22.15.1 may be susceptible to an AV bypass issue, which is a type of exploit that works to circumvent one of the virus detection engines to avoid a specific type of virus protection. One of the antivirus engines depends on a signature pattern from a database to identify malicious files and viruses; the antivirus bypass exploit looks to alter the file being scanned so it is not detected. plural Symantec The product contains vulnerabilities related to security functions.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Multiple Symantec Products are prone to an local security-bypass vulnerability.
Local attackers can exploit this issue to bypass certain security restrictions to perform unauthorized actions. This may aid in further attacks. Symantec Norton and others are products of Symantec Corporation of the United States. Symantec Norton is an antivirus program. Endpoint Protection (SEP) is an endpoint protection program. Attackers can exploit this vulnerability to bypass detection by virus detection engines
| VAR-201811-0194 | CVE-2018-18203 | Subaru StarLink Harman head units Vulnerability in digital signature verification |
CVSS V2: 6.9 CVSS V3: 6.4 Severity: MEDIUM |
A vulnerability in the update mechanism of Subaru StarLink Harman head units 2017, 2018, and 2019 may give an attacker (with physical access to the vehicle's USB ports) the ability to rewrite the firmware of the head unit. This occurs because the device accepts modified QNX6 filesystem images (as long as the attacker obtains access to certain Harman decryption/encryption code) as a consequence of a bug where unsigned images pass a validity check. An attacker could potentially install persistent malicious head unit firmware and execute arbitrary code as the root user. The FHI Subaru StarLink Harman is a vehicle produced by the Japanese company Fuji Heavy Industries (FHI)
| VAR-201811-0125 | CVE-2018-11921 | plural Snapdragon Product error handling vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Failure condition is not handled properly and the correct error code is not returned. It could cause unintended SUI behavior and create unintended SUI display in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDA845, SDX24, SXR1130. Snapdragon Automobile , Snapdragon Mobile , Snapdragon Wear Contains an error handling vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities.
An attacker can exploit these issues to perform unauthorized actions. This may aid in further attacks.
These issues are being tracked by Android Bug IDs A-109678453, A-111089815, A-112279482, A-112278875, A-109678259, A-111088838, A-111092944, A-112278972, A-112279521, A-112279426, A-112279483, A-112279144, A-112279544, and A-119050566. Qualcomm MDM9206 and others are products of Qualcomm (Qualcomm). The Qualcomm MDM9206 is a central processing unit (CPU). SDX24 is a modem. A security vulnerability exists in Content Protection in several Qualcomm Snapdragon products. Currently there is no information about this vulnerability, please keep an eye on CNNVD or vendor announcements
| VAR-201811-0555 | CVE-2018-5918 | plural Snapdragon Product buffer error vulnerability |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Possible buffer overflow in DRM Trusted application due to lack of check function return values in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDA845, SDX24, SXR1130. Snapdragon Automobile , Snapdragon Mobile , Snapdragon Wear Contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state
| VAR-201811-0178 | CVE-2018-15441 | Cisco Prime License Manager In SQL Injection vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted HTTP POST requests that contain malicious SQL statements to an affected application. A successful exploit could allow the attacker to modify and delete arbitrary data in the PLM database or gain shell access with the privileges of the postgres user.
This issue being tracked by Cisco Bug ID CSCvk30822. Cisco Prime License Manager (PLM) is a license manager of Cisco (Cisco)
| VAR-201811-0348 | CVE-2018-18982 | NUUO CMS SQL Injection Vulnerability |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution. NUUO CMS Is SQL An injection vulnerability exists.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. NUUO CMS is a central software management platform from NUUO. The platform is used to centrally manage NVR (DVR), IP cameras and other devices, and provides user management and alarm management. There is a SQL injection vulnerability in NUUO CMS 3.3 and earlier. A remote attacker can exploit this vulnerability to execute arbitrary code
| VAR-201811-0095 | CVE-2018-17936 | NUUO CMS Vulnerable to unlimited upload of dangerous types of files |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote code execution. NUUO CMS Contains a vulnerability related to unlimited uploads of dangerous types of files.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. NUUO CMS is a central software management platform of NUUO. The platform is used to centrally manage NVR (hard disk video recorders), IP cameras and other equipment, and provides functions such as user management and alarm management.
There are security vulnerabilities in NUUO CMS 3.3 and earlier versions