VARIoT IoT vulnerabilities database
| VAR-201904-0512 | CVE-2014-5436 | Honeywell Experion PKS 'confd.exe' Module directory traversal vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to possible information disclosure. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version. Honeywell Experion PKS Contains a path traversal vulnerability.Information may be obtained. Honeywell EPKS is used in the automation and control of industrial and production processes and is a distributed control system solution, including a web-based SCADA system. A remote attacker can use a specially crafted request ('../') with a directory traversal sequence to retrieve arbitrary files from the application for sensitive information. Information obtained could aid in further attacks.
The following versions are affected:
Honeywell Experion R40x versions prior to Experion PKS R400.6
Honeywell Experion R41x versions prior to Experion PKS R410.6
Honeywell Experion R43x versions prior to Experion PKS R430.2
| VAR-201903-0652 | CVE-2014-9189 | Honeywell Experion PKS Module buffer error vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules that could lead to possible remote code execution, dynamic memory corruption, or denial of service. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version. Honeywell Experion PKS The module contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Honeywell EPKS is used in the automation and control of industrial and production processes and is a distributed control system solution, including a web-based SCADA system. Honeywell Experion PKS has multiple stack buffer overflow vulnerabilities because the application failed to properly check the user-supplied data before copying it to a full-size buffer. A remote attacker could exploit these vulnerabilities to execute arbitrary code or cause dynamic memory corruption in the context of an affected application. Failed attempts will likely cause a denial-of-service condition.
The following versions are affected:
Honeywell Experion R40x versions prior to Experion PKS R400.6
Honeywell Experion R41x versions prior to Experion PKS R410.6
Honeywell Experion R43x versions prior to Experion PKS R430.2.
The vulnerability is due to insufficient boundary checks performed on the user-supplied input by the affected software. An attacker could exploit this vulnerability by sending a crafted request to the affected software.
Honeywell has confirmed this vulnerability and released updated software
| VAR-201412-0537 | CVE-2014-8272 | Multiple Dell iDRAC IPMI v1.5 implementations use insufficiently random session ID values |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack. Intelligent Platform Management Interface (IPMI) v1.5 Multiple implementations of the protocol Dell iDRAC The product contains a command injection vulnerability due to a session management issue. CWE-330: Use of Insufficiently Random Values http://cwe.mitre.org/data/definitions/330.html Sessions where random values should be used ID Is assigned regularly, so Dell iDRAC Next session used by the user logged in ID May be guessed. Also session ID Because the range of values used as is small, it is easy to guess by brute force attacks. Dell Computer Corporation, Inc. Information for VU#843044 (http://www.kb.cert.org/vuls/id/BLUU-9RDQHM) Then Dell Says: * The legacy nature of the IPMI 1.5 protocol exposes several weaknesses in * the overall design and implementation. These are: * Use of an insecure (unencrypted) channel for communication. * Poor password management including limited password length. * Limited session management capability. * These weaknesses are inherent in the overall design and implementation * of the protocol, therefore support for the IPMI 1.5 version of the protocol * has been permanently removed. This means that it will not be possible to * reactivate or enable it in an operational setting.By a remote third party, Dell iDRAC Could be hijacked to connect to and execute arbitrary commands. Multiple Dell iDRAC Products are prone to a vulnerability that lets attackers inject arbitrary commands.
Successful exploits will allow attackers to execute arbitrary commands in the context of the affected application. This may further aid in other attacks. Dell iDRAC6 modular, iDRAC6 monolithic and iDRAC7 are all system management solutions from Dell (Dell) including hardware and software. This solution provides functions such as remote management, crash recovery and power control for Dell PowerEdge systems. , which provides the ability to monitor, control, and automatically report on the health of a large number of servers. A security vulnerability exists in IPMI version 1.5 of several Dell products. The following products and versions are affected: Dell iDRAC6 modular 3.60 and earlier, iDRAC6 monolithic 1.97 and earlier, iDRAC7 1.56.55 and earlier
| VAR-201412-0515 | CVE-2014-3580 | Apache Subversion of mod_dav_svn Apache HTTPD server Service disruption in modules (DoS) Vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist. Supplementary information : CWE Vulnerability type by CWE-476: NULL Pointer Dereference (NULL Pointer dereference ) Has been identified. Apache subversion is prone to a remote denial-of-service vulnerability.
Exploiting this issue allows remote attackers to crash the affected process, causing denial of service conditions.
Subversion versions 1.7.0 through 1.7.18 and 1.8.0 through 1.8.10 are affected. Subversion is an open source version control system of the Apache Software Foundation in the United States. The main function of the system is to be compatible with the concurrent version management system (CVS). The verification
of md5 checksums and GPG signatures is performed automatically for you. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/support/security/advisories/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iD8DBQFUqoNCmqjQ0CJFipgRAqwFAKCUALR1yu7OcAY6tP4LrYCdhQMJDACg7FG5
zlOOLTc8tjEXNuj5PnqflP0=
=huIz
-----END PGP SIGNATURE-----
. ============================================================================
Ubuntu Security Notice USN-2721-1
August 20, 2015
subversion vulnerabilities
============================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in Subversion.
Software Description:
- subversion: Advanced version control system
Details:
It was discovered that the Subversion mod_dav_svn module incorrectly
handled REPORT requests for a resource that does not exist. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. This issue only affected Ubuntu
14.04 LTS. This
issue only affected Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-0202)
Evgeny Kotkov discovered that the Subversion mod_dav_svn and svnserve
modules incorrectly certain crafted parameter combinations. (CVE-2015-0248)
Ivan Zhakov discovered that the Subversion mod_dav_svn module incorrectly
handled crafted v1 HTTP protocol request sequences. (CVE-2015-0251)
C. Michael Pilato discovered that the Subversion mod_dav_svn module
incorrectly restricted anonymous access. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-3184)
C. Michael Pilato discovered that Subversion incorrectly handled path-based
authorization. (CVE-2015-3187)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 15.04:
libapache2-svn 1.8.10-5ubuntu1.1
libsvn1 1.8.10-5ubuntu1.1
subversion 1.8.10-5ubuntu1.1
Ubuntu 14.04 LTS:
libapache2-svn 1.8.8-1ubuntu3.2
libsvn1 1.8.8-1ubuntu3.2
subversion 1.8.8-1ubuntu3.2
Ubuntu 12.04 LTS:
libapache2-svn 1.6.17dfsg-3ubuntu3.5
libsvn1 1.6.17dfsg-3ubuntu3.5
subversion 1.6.17dfsg-3ubuntu3.5
In general, a standard system update will make all the necessary changes. 6) - i386, noarch, x86_64
3. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
=====================================================================
Red Hat Security Advisory
Synopsis: Moderate: subversion security update
Advisory ID: RHSA-2015:0166-01
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0166.html
Issue date: 2015-02-10
CVE Names: CVE-2014-3528 CVE-2014-3580 CVE-2014-8108
=====================================================================
1. Summary:
Updated subversion packages that fix three security issues are now
available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having Moderate security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - ppc64, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
3. Description:
Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. A remote, unauthenticated attacker could use a
specially crafted REPORT request to crash mod_dav_svn. (CVE-2014-3580)
A NULL pointer dereference flaw was found in the way the mod_dav_svn module
handled certain requests for URIs that trigger a lookup of a virtual
transaction name. (CVE-2014-8108)
It was discovered that Subversion clients retrieved cached authentication
credentials using the MD5 hash of the server realm string without also
checking the server's URL. A malicious server able to provide a realm that
triggers an MD5 collision could possibly use this flaw to obtain the
credentials for a different realm. (CVE-2014-3528)
Red Hat would like to thank the Subversion project for reporting
CVE-2014-3580 and CVE-2014-8108. Upstream acknowledges Evgeny Kotkov of
VisualSVN as the original reporter.
All subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, for the update to take effect, you must restart the httpd
daemon, if you are using mod_dav_svn, and the svnserve daemon, if you are
serving Subversion repositories via the svn:// protocol.
4. Solution:
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to use the
Red Hat Network to apply this update are available at
https://access.redhat.com/articles/11258
5. Bugs fixed (https://bugzilla.redhat.com/):
1125799 - CVE-2014-3528 subversion: credentials leak via MD5 collision
1174054 - CVE-2014-3580 subversion: NULL pointer dereference flaw in mod_dav_svn when handling REPORT requests
1174057 - CVE-2014-8108 subversion: NULL pointer dereference flaw in mod_dav_svn when handling URIs for virtual transaction names
6. Package List:
Red Hat Enterprise Linux Client Optional (v. 7):
Source:
subversion-1.7.14-7.el7_0.src.rpm
x86_64:
mod_dav_svn-1.7.14-7.el7_0.x86_64.rpm
subversion-1.7.14-7.el7_0.i686.rpm
subversion-1.7.14-7.el7_0.x86_64.rpm
subversion-debuginfo-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.x86_64.rpm
subversion-devel-1.7.14-7.el7_0.i686.rpm
subversion-devel-1.7.14-7.el7_0.x86_64.rpm
subversion-gnome-1.7.14-7.el7_0.i686.rpm
subversion-gnome-1.7.14-7.el7_0.x86_64.rpm
subversion-javahl-1.7.14-7.el7_0.i686.rpm
subversion-javahl-1.7.14-7.el7_0.x86_64.rpm
subversion-kde-1.7.14-7.el7_0.i686.rpm
subversion-kde-1.7.14-7.el7_0.x86_64.rpm
subversion-libs-1.7.14-7.el7_0.i686.rpm
subversion-libs-1.7.14-7.el7_0.x86_64.rpm
subversion-perl-1.7.14-7.el7_0.i686.rpm
subversion-perl-1.7.14-7.el7_0.x86_64.rpm
subversion-python-1.7.14-7.el7_0.x86_64.rpm
subversion-ruby-1.7.14-7.el7_0.i686.rpm
subversion-ruby-1.7.14-7.el7_0.x86_64.rpm
subversion-tools-1.7.14-7.el7_0.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
Source:
subversion-1.7.14-7.el7_0.src.rpm
x86_64:
mod_dav_svn-1.7.14-7.el7_0.x86_64.rpm
subversion-1.7.14-7.el7_0.i686.rpm
subversion-1.7.14-7.el7_0.x86_64.rpm
subversion-debuginfo-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.x86_64.rpm
subversion-devel-1.7.14-7.el7_0.i686.rpm
subversion-devel-1.7.14-7.el7_0.x86_64.rpm
subversion-gnome-1.7.14-7.el7_0.i686.rpm
subversion-gnome-1.7.14-7.el7_0.x86_64.rpm
subversion-javahl-1.7.14-7.el7_0.i686.rpm
subversion-javahl-1.7.14-7.el7_0.x86_64.rpm
subversion-kde-1.7.14-7.el7_0.i686.rpm
subversion-kde-1.7.14-7.el7_0.x86_64.rpm
subversion-libs-1.7.14-7.el7_0.i686.rpm
subversion-libs-1.7.14-7.el7_0.x86_64.rpm
subversion-perl-1.7.14-7.el7_0.i686.rpm
subversion-perl-1.7.14-7.el7_0.x86_64.rpm
subversion-python-1.7.14-7.el7_0.x86_64.rpm
subversion-ruby-1.7.14-7.el7_0.i686.rpm
subversion-ruby-1.7.14-7.el7_0.x86_64.rpm
subversion-tools-1.7.14-7.el7_0.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
subversion-1.7.14-7.el7_0.src.rpm
ppc64:
mod_dav_svn-1.7.14-7.el7_0.ppc64.rpm
subversion-1.7.14-7.el7_0.ppc64.rpm
subversion-debuginfo-1.7.14-7.el7_0.ppc.rpm
subversion-debuginfo-1.7.14-7.el7_0.ppc64.rpm
subversion-libs-1.7.14-7.el7_0.ppc.rpm
subversion-libs-1.7.14-7.el7_0.ppc64.rpm
s390x:
mod_dav_svn-1.7.14-7.el7_0.s390x.rpm
subversion-1.7.14-7.el7_0.s390x.rpm
subversion-debuginfo-1.7.14-7.el7_0.s390.rpm
subversion-debuginfo-1.7.14-7.el7_0.s390x.rpm
subversion-libs-1.7.14-7.el7_0.s390.rpm
subversion-libs-1.7.14-7.el7_0.s390x.rpm
x86_64:
mod_dav_svn-1.7.14-7.el7_0.x86_64.rpm
subversion-1.7.14-7.el7_0.x86_64.rpm
subversion-debuginfo-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.x86_64.rpm
subversion-libs-1.7.14-7.el7_0.i686.rpm
subversion-libs-1.7.14-7.el7_0.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
ppc64:
subversion-1.7.14-7.el7_0.ppc.rpm
subversion-debuginfo-1.7.14-7.el7_0.ppc.rpm
subversion-debuginfo-1.7.14-7.el7_0.ppc64.rpm
subversion-devel-1.7.14-7.el7_0.ppc.rpm
subversion-devel-1.7.14-7.el7_0.ppc64.rpm
subversion-gnome-1.7.14-7.el7_0.ppc.rpm
subversion-gnome-1.7.14-7.el7_0.ppc64.rpm
subversion-javahl-1.7.14-7.el7_0.ppc.rpm
subversion-javahl-1.7.14-7.el7_0.ppc64.rpm
subversion-kde-1.7.14-7.el7_0.ppc.rpm
subversion-kde-1.7.14-7.el7_0.ppc64.rpm
subversion-perl-1.7.14-7.el7_0.ppc.rpm
subversion-perl-1.7.14-7.el7_0.ppc64.rpm
subversion-python-1.7.14-7.el7_0.ppc64.rpm
subversion-ruby-1.7.14-7.el7_0.ppc.rpm
subversion-ruby-1.7.14-7.el7_0.ppc64.rpm
subversion-tools-1.7.14-7.el7_0.ppc64.rpm
s390x:
subversion-1.7.14-7.el7_0.s390.rpm
subversion-debuginfo-1.7.14-7.el7_0.s390.rpm
subversion-debuginfo-1.7.14-7.el7_0.s390x.rpm
subversion-devel-1.7.14-7.el7_0.s390.rpm
subversion-devel-1.7.14-7.el7_0.s390x.rpm
subversion-gnome-1.7.14-7.el7_0.s390.rpm
subversion-gnome-1.7.14-7.el7_0.s390x.rpm
subversion-javahl-1.7.14-7.el7_0.s390.rpm
subversion-javahl-1.7.14-7.el7_0.s390x.rpm
subversion-kde-1.7.14-7.el7_0.s390.rpm
subversion-kde-1.7.14-7.el7_0.s390x.rpm
subversion-perl-1.7.14-7.el7_0.s390.rpm
subversion-perl-1.7.14-7.el7_0.s390x.rpm
subversion-python-1.7.14-7.el7_0.s390x.rpm
subversion-ruby-1.7.14-7.el7_0.s390.rpm
subversion-ruby-1.7.14-7.el7_0.s390x.rpm
subversion-tools-1.7.14-7.el7_0.s390x.rpm
x86_64:
subversion-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.x86_64.rpm
subversion-devel-1.7.14-7.el7_0.i686.rpm
subversion-devel-1.7.14-7.el7_0.x86_64.rpm
subversion-gnome-1.7.14-7.el7_0.i686.rpm
subversion-gnome-1.7.14-7.el7_0.x86_64.rpm
subversion-javahl-1.7.14-7.el7_0.i686.rpm
subversion-javahl-1.7.14-7.el7_0.x86_64.rpm
subversion-kde-1.7.14-7.el7_0.i686.rpm
subversion-kde-1.7.14-7.el7_0.x86_64.rpm
subversion-perl-1.7.14-7.el7_0.i686.rpm
subversion-perl-1.7.14-7.el7_0.x86_64.rpm
subversion-python-1.7.14-7.el7_0.x86_64.rpm
subversion-ruby-1.7.14-7.el7_0.i686.rpm
subversion-ruby-1.7.14-7.el7_0.x86_64.rpm
subversion-tools-1.7.14-7.el7_0.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source:
subversion-1.7.14-7.el7_0.src.rpm
x86_64:
mod_dav_svn-1.7.14-7.el7_0.x86_64.rpm
subversion-1.7.14-7.el7_0.x86_64.rpm
subversion-debuginfo-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.x86_64.rpm
subversion-libs-1.7.14-7.el7_0.i686.rpm
subversion-libs-1.7.14-7.el7_0.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
x86_64:
subversion-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.x86_64.rpm
subversion-devel-1.7.14-7.el7_0.i686.rpm
subversion-devel-1.7.14-7.el7_0.x86_64.rpm
subversion-gnome-1.7.14-7.el7_0.i686.rpm
subversion-gnome-1.7.14-7.el7_0.x86_64.rpm
subversion-javahl-1.7.14-7.el7_0.i686.rpm
subversion-javahl-1.7.14-7.el7_0.x86_64.rpm
subversion-kde-1.7.14-7.el7_0.i686.rpm
subversion-kde-1.7.14-7.el7_0.x86_64.rpm
subversion-perl-1.7.14-7.el7_0.i686.rpm
subversion-perl-1.7.14-7.el7_0.x86_64.rpm
subversion-python-1.7.14-7.el7_0.x86_64.rpm
subversion-ruby-1.7.14-7.el7_0.i686.rpm
subversion-ruby-1.7.14-7.el7_0.x86_64.rpm
subversion-tools-1.7.14-7.el7_0.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2014-3528
https://access.redhat.com/security/cve/CVE-2014-3580
https://access.redhat.com/security/cve/CVE-2014-8108
https://access.redhat.com/security/updates/classification/#moderate
https://subversion.apache.org/security/CVE-2014-3528-advisory.txt
https://subversion.apache.org/security/CVE-2014-3580-advisory.txt
https://subversion.apache.org/security/CVE-2014-8108-advisory.txt
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2015 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iD8DBQFU2pCEXlSAg2UNWIIRAmlpAJ4o2MhM6glIBctGbU52rfN8EZXCDgCdEIll
KM6EsnQkXd09uLTe1k+tQaU=
=CuZg
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
.
These issues were addressed by updating Apache Subversion to version
1.7.19.
CVE-ID
CVE-2014-3522
CVE-2014-3528
CVE-2014-3580
CVE-2014-8108
Git
Available for: OS X Mavericks v10.9.4 or later
Impact: Synching with a malicious git repository may allow
unexpected files to be added to the .git folder
Description: The checks involved in disallowed paths did not account
for case insensitivity or unicode characters. This issue was
addressed by adding additional checks.
CVE-ID
CVE-2014-9390 : Matt Mackall of Mercurial and Augie Fackler of
Mercurial
Xcode 6.2 may be obtained from:
https://developer.apple.com/xcode/downloads/
To check that the Xcode has been updated:
* Select Xcode in the menu bar
* Select About Xcode
* The version after applying this update will be "6.2".
For the stable distribution (wheezy), this problem has been fixed in
version 1.6.17dfsg-4+deb7u7.
For the unstable distribution (sid), this problem has been fixed in
version 1.8.10-5
| VAR-201412-0309 | CVE-2014-8108 | Apache Subversion of mod_dav_svn Apache HTTPD server Service disruption in modules (DoS) Vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a URI that triggers a lookup for a virtual transaction name that does not exist. Supplementary information : CWE Vulnerability type by CWE-476: NULL Pointer Dereference (NULL Pointer dereference ) Has been identified. Apache subversion is prone to a remote denial-of-service vulnerability.
Exploiting this issue allows remote attackers to crash the affected process, causing denial of service conditions.
Subversion versions 1.7.0 through 1.7.18 and 1.8.0 through 1.8.10 are affected. Subversion is an open source version control system of the Apache Software Foundation in the United States. The main function of the system is to be compatible with the concurrent version management system (CVS). The verification
of md5 checksums and GPG signatures is performed automatically for you. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/support/security/advisories/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iD8DBQFUqoNCmqjQ0CJFipgRAqwFAKCUALR1yu7OcAY6tP4LrYCdhQMJDACg7FG5
zlOOLTc8tjEXNuj5PnqflP0=
=huIz
-----END PGP SIGNATURE-----
. ============================================================================
Ubuntu Security Notice USN-2721-1
August 20, 2015
subversion vulnerabilities
============================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in Subversion.
Software Description:
- subversion: Advanced version control system
Details:
It was discovered that the Subversion mod_dav_svn module incorrectly
handled REPORT requests for a resource that does not exist. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. This issue only affected Ubuntu
14.04 LTS. This
issue only affected Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-0202)
Evgeny Kotkov discovered that the Subversion mod_dav_svn and svnserve
modules incorrectly certain crafted parameter combinations. (CVE-2015-0248)
Ivan Zhakov discovered that the Subversion mod_dav_svn module incorrectly
handled crafted v1 HTTP protocol request sequences. (CVE-2015-0251)
C. Michael Pilato discovered that the Subversion mod_dav_svn module
incorrectly restricted anonymous access. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-3184)
C. Michael Pilato discovered that Subversion incorrectly handled path-based
authorization. (CVE-2015-3187)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 15.04:
libapache2-svn 1.8.10-5ubuntu1.1
libsvn1 1.8.10-5ubuntu1.1
subversion 1.8.10-5ubuntu1.1
Ubuntu 14.04 LTS:
libapache2-svn 1.8.8-1ubuntu3.2
libsvn1 1.8.8-1ubuntu3.2
subversion 1.8.8-1ubuntu3.2
Ubuntu 12.04 LTS:
libapache2-svn 1.6.17dfsg-3ubuntu3.5
libsvn1 1.6.17dfsg-3ubuntu3.5
subversion 1.6.17dfsg-3ubuntu3.5
In general, a standard system update will make all the necessary changes. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
=====================================================================
Red Hat Security Advisory
Synopsis: Moderate: subversion security update
Advisory ID: RHSA-2015:0166-01
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0166.html
Issue date: 2015-02-10
CVE Names: CVE-2014-3528 CVE-2014-3580 CVE-2014-8108
=====================================================================
1. Summary:
Updated subversion packages that fix three security issues are now
available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having Moderate security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - ppc64, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
3. Description:
Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access
to Subversion repositories via HTTP. A remote, unauthenticated attacker could use a
specially crafted REPORT request to crash mod_dav_svn. (CVE-2014-8108)
It was discovered that Subversion clients retrieved cached authentication
credentials using the MD5 hash of the server realm string without also
checking the server's URL. A malicious server able to provide a realm that
triggers an MD5 collision could possibly use this flaw to obtain the
credentials for a different realm. (CVE-2014-3528)
Red Hat would like to thank the Subversion project for reporting
CVE-2014-3580 and CVE-2014-8108. Upstream acknowledges Evgeny Kotkov of
VisualSVN as the original reporter.
All subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, for the update to take effect, you must restart the httpd
daemon, if you are using mod_dav_svn, and the svnserve daemon, if you are
serving Subversion repositories via the svn:// protocol.
4. Solution:
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to use the
Red Hat Network to apply this update are available at
https://access.redhat.com/articles/11258
5. Bugs fixed (https://bugzilla.redhat.com/):
1125799 - CVE-2014-3528 subversion: credentials leak via MD5 collision
1174054 - CVE-2014-3580 subversion: NULL pointer dereference flaw in mod_dav_svn when handling REPORT requests
1174057 - CVE-2014-8108 subversion: NULL pointer dereference flaw in mod_dav_svn when handling URIs for virtual transaction names
6. Package List:
Red Hat Enterprise Linux Client Optional (v. 7):
Source:
subversion-1.7.14-7.el7_0.src.rpm
x86_64:
mod_dav_svn-1.7.14-7.el7_0.x86_64.rpm
subversion-1.7.14-7.el7_0.i686.rpm
subversion-1.7.14-7.el7_0.x86_64.rpm
subversion-debuginfo-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.x86_64.rpm
subversion-devel-1.7.14-7.el7_0.i686.rpm
subversion-devel-1.7.14-7.el7_0.x86_64.rpm
subversion-gnome-1.7.14-7.el7_0.i686.rpm
subversion-gnome-1.7.14-7.el7_0.x86_64.rpm
subversion-javahl-1.7.14-7.el7_0.i686.rpm
subversion-javahl-1.7.14-7.el7_0.x86_64.rpm
subversion-kde-1.7.14-7.el7_0.i686.rpm
subversion-kde-1.7.14-7.el7_0.x86_64.rpm
subversion-libs-1.7.14-7.el7_0.i686.rpm
subversion-libs-1.7.14-7.el7_0.x86_64.rpm
subversion-perl-1.7.14-7.el7_0.i686.rpm
subversion-perl-1.7.14-7.el7_0.x86_64.rpm
subversion-python-1.7.14-7.el7_0.x86_64.rpm
subversion-ruby-1.7.14-7.el7_0.i686.rpm
subversion-ruby-1.7.14-7.el7_0.x86_64.rpm
subversion-tools-1.7.14-7.el7_0.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
Source:
subversion-1.7.14-7.el7_0.src.rpm
x86_64:
mod_dav_svn-1.7.14-7.el7_0.x86_64.rpm
subversion-1.7.14-7.el7_0.i686.rpm
subversion-1.7.14-7.el7_0.x86_64.rpm
subversion-debuginfo-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.x86_64.rpm
subversion-devel-1.7.14-7.el7_0.i686.rpm
subversion-devel-1.7.14-7.el7_0.x86_64.rpm
subversion-gnome-1.7.14-7.el7_0.i686.rpm
subversion-gnome-1.7.14-7.el7_0.x86_64.rpm
subversion-javahl-1.7.14-7.el7_0.i686.rpm
subversion-javahl-1.7.14-7.el7_0.x86_64.rpm
subversion-kde-1.7.14-7.el7_0.i686.rpm
subversion-kde-1.7.14-7.el7_0.x86_64.rpm
subversion-libs-1.7.14-7.el7_0.i686.rpm
subversion-libs-1.7.14-7.el7_0.x86_64.rpm
subversion-perl-1.7.14-7.el7_0.i686.rpm
subversion-perl-1.7.14-7.el7_0.x86_64.rpm
subversion-python-1.7.14-7.el7_0.x86_64.rpm
subversion-ruby-1.7.14-7.el7_0.i686.rpm
subversion-ruby-1.7.14-7.el7_0.x86_64.rpm
subversion-tools-1.7.14-7.el7_0.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
subversion-1.7.14-7.el7_0.src.rpm
ppc64:
mod_dav_svn-1.7.14-7.el7_0.ppc64.rpm
subversion-1.7.14-7.el7_0.ppc64.rpm
subversion-debuginfo-1.7.14-7.el7_0.ppc.rpm
subversion-debuginfo-1.7.14-7.el7_0.ppc64.rpm
subversion-libs-1.7.14-7.el7_0.ppc.rpm
subversion-libs-1.7.14-7.el7_0.ppc64.rpm
s390x:
mod_dav_svn-1.7.14-7.el7_0.s390x.rpm
subversion-1.7.14-7.el7_0.s390x.rpm
subversion-debuginfo-1.7.14-7.el7_0.s390.rpm
subversion-debuginfo-1.7.14-7.el7_0.s390x.rpm
subversion-libs-1.7.14-7.el7_0.s390.rpm
subversion-libs-1.7.14-7.el7_0.s390x.rpm
x86_64:
mod_dav_svn-1.7.14-7.el7_0.x86_64.rpm
subversion-1.7.14-7.el7_0.x86_64.rpm
subversion-debuginfo-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.x86_64.rpm
subversion-libs-1.7.14-7.el7_0.i686.rpm
subversion-libs-1.7.14-7.el7_0.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
ppc64:
subversion-1.7.14-7.el7_0.ppc.rpm
subversion-debuginfo-1.7.14-7.el7_0.ppc.rpm
subversion-debuginfo-1.7.14-7.el7_0.ppc64.rpm
subversion-devel-1.7.14-7.el7_0.ppc.rpm
subversion-devel-1.7.14-7.el7_0.ppc64.rpm
subversion-gnome-1.7.14-7.el7_0.ppc.rpm
subversion-gnome-1.7.14-7.el7_0.ppc64.rpm
subversion-javahl-1.7.14-7.el7_0.ppc.rpm
subversion-javahl-1.7.14-7.el7_0.ppc64.rpm
subversion-kde-1.7.14-7.el7_0.ppc.rpm
subversion-kde-1.7.14-7.el7_0.ppc64.rpm
subversion-perl-1.7.14-7.el7_0.ppc.rpm
subversion-perl-1.7.14-7.el7_0.ppc64.rpm
subversion-python-1.7.14-7.el7_0.ppc64.rpm
subversion-ruby-1.7.14-7.el7_0.ppc.rpm
subversion-ruby-1.7.14-7.el7_0.ppc64.rpm
subversion-tools-1.7.14-7.el7_0.ppc64.rpm
s390x:
subversion-1.7.14-7.el7_0.s390.rpm
subversion-debuginfo-1.7.14-7.el7_0.s390.rpm
subversion-debuginfo-1.7.14-7.el7_0.s390x.rpm
subversion-devel-1.7.14-7.el7_0.s390.rpm
subversion-devel-1.7.14-7.el7_0.s390x.rpm
subversion-gnome-1.7.14-7.el7_0.s390.rpm
subversion-gnome-1.7.14-7.el7_0.s390x.rpm
subversion-javahl-1.7.14-7.el7_0.s390.rpm
subversion-javahl-1.7.14-7.el7_0.s390x.rpm
subversion-kde-1.7.14-7.el7_0.s390.rpm
subversion-kde-1.7.14-7.el7_0.s390x.rpm
subversion-perl-1.7.14-7.el7_0.s390.rpm
subversion-perl-1.7.14-7.el7_0.s390x.rpm
subversion-python-1.7.14-7.el7_0.s390x.rpm
subversion-ruby-1.7.14-7.el7_0.s390.rpm
subversion-ruby-1.7.14-7.el7_0.s390x.rpm
subversion-tools-1.7.14-7.el7_0.s390x.rpm
x86_64:
subversion-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.x86_64.rpm
subversion-devel-1.7.14-7.el7_0.i686.rpm
subversion-devel-1.7.14-7.el7_0.x86_64.rpm
subversion-gnome-1.7.14-7.el7_0.i686.rpm
subversion-gnome-1.7.14-7.el7_0.x86_64.rpm
subversion-javahl-1.7.14-7.el7_0.i686.rpm
subversion-javahl-1.7.14-7.el7_0.x86_64.rpm
subversion-kde-1.7.14-7.el7_0.i686.rpm
subversion-kde-1.7.14-7.el7_0.x86_64.rpm
subversion-perl-1.7.14-7.el7_0.i686.rpm
subversion-perl-1.7.14-7.el7_0.x86_64.rpm
subversion-python-1.7.14-7.el7_0.x86_64.rpm
subversion-ruby-1.7.14-7.el7_0.i686.rpm
subversion-ruby-1.7.14-7.el7_0.x86_64.rpm
subversion-tools-1.7.14-7.el7_0.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source:
subversion-1.7.14-7.el7_0.src.rpm
x86_64:
mod_dav_svn-1.7.14-7.el7_0.x86_64.rpm
subversion-1.7.14-7.el7_0.x86_64.rpm
subversion-debuginfo-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.x86_64.rpm
subversion-libs-1.7.14-7.el7_0.i686.rpm
subversion-libs-1.7.14-7.el7_0.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
x86_64:
subversion-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.i686.rpm
subversion-debuginfo-1.7.14-7.el7_0.x86_64.rpm
subversion-devel-1.7.14-7.el7_0.i686.rpm
subversion-devel-1.7.14-7.el7_0.x86_64.rpm
subversion-gnome-1.7.14-7.el7_0.i686.rpm
subversion-gnome-1.7.14-7.el7_0.x86_64.rpm
subversion-javahl-1.7.14-7.el7_0.i686.rpm
subversion-javahl-1.7.14-7.el7_0.x86_64.rpm
subversion-kde-1.7.14-7.el7_0.i686.rpm
subversion-kde-1.7.14-7.el7_0.x86_64.rpm
subversion-perl-1.7.14-7.el7_0.i686.rpm
subversion-perl-1.7.14-7.el7_0.x86_64.rpm
subversion-python-1.7.14-7.el7_0.x86_64.rpm
subversion-ruby-1.7.14-7.el7_0.i686.rpm
subversion-ruby-1.7.14-7.el7_0.x86_64.rpm
subversion-tools-1.7.14-7.el7_0.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2014-3528
https://access.redhat.com/security/cve/CVE-2014-3580
https://access.redhat.com/security/cve/CVE-2014-8108
https://access.redhat.com/security/updates/classification/#moderate
https://subversion.apache.org/security/CVE-2014-3528-advisory.txt
https://subversion.apache.org/security/CVE-2014-3580-advisory.txt
https://subversion.apache.org/security/CVE-2014-8108-advisory.txt
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2015 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iD8DBQFU2pCEXlSAg2UNWIIRAmlpAJ4o2MhM6glIBctGbU52rfN8EZXCDgCdEIll
KM6EsnQkXd09uLTe1k+tQaU=
=CuZg
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
.
These issues were addressed by updating Apache Subversion to version
1.7.19.
CVE-ID
CVE-2014-3522
CVE-2014-3528
CVE-2014-3580
CVE-2014-8108
Git
Available for: OS X Mavericks v10.9.4 or later
Impact: Synching with a malicious git repository may allow
unexpected files to be added to the .git folder
Description: The checks involved in disallowed paths did not account
for case insensitivity or unicode characters. This issue was
addressed by adding additional checks.
CVE-ID
CVE-2014-9390 : Matt Mackall of Mercurial and Augie Fackler of
Mercurial
Xcode 6.2 may be obtained from:
https://developer.apple.com/xcode/downloads/
To check that the Xcode has been updated:
* Select Xcode in the menu bar
* Select About Xcode
* The version after applying this update will be "6.2"
| VAR-201412-0295 | CVE-2014-8012 | Cisco Adaptive Security Appliance Software WebVPN Portal login page cross-site scripting vulnerability |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
This issue is being tracked by Cisco Bug ID CSCuh24695
| VAR-201412-0300 | CVE-2014-8014 | Cisco IOS XR Service disruption in (DoS) Vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCub63710. Vendors have confirmed this vulnerability Bug ID CSCub63710 It is released as. Supplementary information : CWE Vulnerability type by CWE-19: Data Handling ( Data processing ) Has been identified. http://cwe.mitre.org/data/definitions/19.htmlService disruption by a third party (RSVP Reload process ) There is a possibility of being put into a state. Cisco IOS is the interconnected network operating system used on most Cisco system routers and network switches
| VAR-201501-0654 | CVE-2014-9517 | D-link IP camera DCS-2103 Firmware cross-site scripting vulnerability |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
Cross-site scripting (XSS) vulnerability in D-link IP camera DCS-2103 with firmware before 1.20 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to vb.htm. D-link IP camera The DCS-2103 is a camera for IP surveillance solutions. Dcs-2103 Hd Cube Network Camera is prone to a cross-site scripting vulnerability. If previous Path Traversal and Full path disclosure
vulnerabilities were post-auth, then these BF and XSS vulnerabilities are
pre-auth.
-------------------------
Affected products:
-------------------------
Vulnerable is the next model: D-Link DCS-2103, Firmware 1.0.0. For BF
vulnerability version 1.20 and previous versions are vulnerable.
Developers refused to fix BF vulnerability (they think that it's problem of
a user to have strong password) and XSS vulnerability was fixed in firmware
version 1.20.
----------
Details:
----------
Brute Force (WASC-11):
http://site
No protection from BF attacks.
Cross-Site Scripting (WASC-08):
http://site/vb.htm?%3Cscript%3Ealert%28document.cookie%29%3C/script%3E
------------
Timeline:
------------
2014.05.22-2014.11.26 - conversation with D-Link about vulnerabilities in
DAP-1360.
2014.08.01 - announced at my site about vulnerabilities in DCS-2103.
2014.11.14-2014.12.13 - conversation with D-Link about vulnerabilities in
DCS-2103.
2014.12.16 - disclosed at my site (http://websecurity.com.ua/7288/).
I found this and other web cameras during summer to watch terrorists
activities in Donetsk and Lugansks regions of Ukraine
(http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2014-November/009062.html)
and also I took under control web cameras in Russia
(http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2014-December/009065.html).
Best wishes & regards,
Eugene Dokukin aka MustLive
Administrator of Websecurity web site
http://websecurity.com.ua
| VAR-201412-0596 | CVE-2014-7285 | Symantec Web Gateway Any management console running on the appliance OS Command execution vulnerability |
CVSS V2: 6.5 CVSS V3: - Severity: MEDIUM |
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts. Supplementary information : CWE Vulnerability type by CWE-77: Improper Neutralization of Special Elements used in a Command ( Command injection ) Has been identified. Symantec Web Gateway is prone to a command-injection vulnerability.
Successfully exploiting this issue may allow an attacker to execute arbitrary OS commands in the context of the affected appliance.
Versions prior to Symantec Web Gateway 5.2.2 are vulnerable. Symantec Web Gateway (SWG) is a set of network content filtering software developed by Symantec Corporation of the United States. The software provides web content filtering, data loss prevention, and more
| VAR-201412-0291 | CVE-2014-8006 | Cisco ISB8320-E High-Definition IP-Only DVR of Disaster Recovery Vulnerabilities that bypass authentication in functions |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
The Disaster Recovery (DRA) feature on the Cisco ISB8320-E High-Definition IP-Only DVR allows remote attackers to bypass authentication by establishing a TELNET session during a recovery boot, aka Bug ID CSCup85422. The Cisco ISB8320-E High-Definition IP-Only DVR is a Cisco HD DVR. Cisco ISB8320-E High-Definition IP-Only DVR has a security vulnerability that could allow an attacker to exploit this vulnerability to bypass certain security restrictions or to perform unauthorized access on an affected device.
This issue is tracked by Cisco Bug ID CSCup85422
| VAR-201412-0687 | No CVE | Multiple Vulnerabilities in JP1/Cm2/Network Node Manager i |
CVSS V2: 9.3 CVSS V3: - Severity: High |
JP1/Cm2/Network Node Manager i contains cross-site scripting and execution of arbitrary code vulnerabilities.An attacker could inject arbitrary web script and execute arbitrary code.
| VAR-201412-0686 | No CVE | Multiple buffer overflows in Hitachi JP1/Cm2/Network Node Manager i |
CVSS V2: 9.3 CVSS V3: - Severity: High |
Multiple buffer overflow vulnerabilities exist in JP1/Cm2/Network Node Manager i.An attacker can exploit these vulnerabilities to execute arbitary code.
| VAR-201412-0564 | CVE-2014-2716 | plural Ekahau Vulnerability in obtaining plaintext messages in products |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 reuses the RC4 cipher stream, which makes it easier for remote attackers to obtain plaintext messages via an XOR operation on two ciphertexts. Ekahau Real-Time Location System is prone to multiple security weaknesses.
Successful exploits may allow an attacker to bypass certain security restrictions and perform unauthorized actions. Ekahau Real-Time Location System (RTLS) is a real-time positioning system based on Wi-Fi (wireless) of Ekahau Company in the United States. Activator is one of the label setter components. A security vulnerability exists in several Ekahau products due to program reuse of RC4 cipher streams. A remote attacker can use the XOR operation to exploit this vulnerability to obtain plaintext information. The following products and versions are affected: Ekahau B4 staff badge tag version 5.7 using firmware version 1.4.52, RTLS Controller version 6.0.5-FINAL, Activator 3 version
| VAR-201412-0103 | CVE-2014-9408 | plural Ekahau Vulnerability that guesses the setup key in the product |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 uses part of the MAC address as part of the RC4 setup key, which makes it easier for remote attackers to guess the key via a brute-force attack. Ekahau Real-Time Location System is prone to multiple security weaknesses.
Successful exploits may allow an attacker to bypass certain security restrictions and perform unauthorized actions. Ekahau Real-Time Location System (RTLS) is a real-time positioning system based on Wi-Fi (wireless) of Ekahau Company in the United States. Activator is one of the label setter components. There are security vulnerabilities in several Ekahau products. The vulnerability stems from the fact that the program uses part of the MAC address as part of the RC4 installation key
| VAR-201412-0521 | CVE-2014-5437 | ARRIS Touchstone TG862G/CT Telephony Gateway Vulnerabilities in which access rights can be obtained in firmware |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote management via a request to remote_management.php, (2) add a port forwarding rule via a request to port_forwarding_add.php, (3) change the wireless network to open via a request to wireless_network_configuration_edit.php, or (4) conduct cross-site scripting (XSS) attacks via the keyword parameter to managed_sites_add_keyword.php. ARRIS Touchstone TG862G/CT Telephony Gateway Because the firmware of the default password of the administrator account password, there is a vulnerability to gain access.By a third party home_loggedout.php Access may be obtained through a request for. The ARRIS TG862G Route is a router. A cross-site request forgery vulnerability exists in the ARRIS TG862G Route due to a program failing to properly validate HTTP requests. Allow remote attackers to perform certain unauthorized operations. Other attacks are also possible.
Arris TG862G running firmware version 7.6.59S.CT is vulnerable. Arris Touchstone TG862G/CT Telephony Gateway is a Modem (modem) router all-in-one machine produced by Arris Group Corporation of the United States
| VAR-201412-0522 | CVE-2014-5438 | ARRIS Touchstone TG862G/CT Telephony Gateway Firmware cross-site scripting vulnerability |
CVSS V2: 3.5 CVSS V3: - Severity: LOW |
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name parameter to connected_devices_computers_edit.php. The ARRIS TG862G Route is a router. Arris TG862G is prone to an HTML-injection vulnerability and a cross-site scripting vulnerability. Other attacks are also possible. Arris Touchstone TG862G/CT Telephony Gateway is a Modem (modem) router all-in-one machine produced by Arris Group Corporation of the United States. The vulnerability is caused by the connected_devices_computers_edit.php script not adequately filtering the 'computer_name' parameter
| VAR-201412-0128 | CVE-2014-9339 | WordPress for SPNbabble Cross-site request forgery vulnerability in plugin |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Multiple cross-site request forgery (CSRF) vulnerabilities in the SPNbabble plugin 1.4.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) username or (2) password parameter in the spnbabble.php page to wp-admin/options-general.php. WordPress is a blogging platform developed using the PHP language. Users can set up their own blogs on servers that support PHP and MySQL databases. # Title: CSRF/XSS Vulnerability in SPNbabble WP Plugin
# Author: Manideep K
# CVE-ID: \xa0CVE-2014-9339
# Plugin Homepage: https://wordpress.org/plugins/spnbabble/
# Version Affected: 1.4.1 (probably lower versions)
# Severity: High
# About Plugin:
SPNbabble (http://spnbabble.sitepronews.com) allows users to create an account and post 140 character blogs with urls to send out messages to your followers. Through the professional setup of SPNbabble you can also auto connect to Twitter, Friendfeed, Plurk, Tumblr, Facebook, Zannel, Youare, Meemi & Utterli. This plugin once installed allows you to enter your SPNbabble user and password and you can choose which blog posts will be converted into mini blogs. Your blog turned into several mini blogs on the most popular social media platforms is a great way to keep your message strong.
# Description:
# Vulnerable Parameter: username, password etc
# About Vulnerability: This plugin is vulnerable to a combination of CSRF/XSS attack meaning that if an admin user can be tricked to visit a crafted URL created by attacker (via spear phishing/social engineering), the attacker can insert arbitrary script into admin page. Once exploited, admin\x92s browser can be made to do almost anything the admin user could typically do by hijacking admin's cookies etc.
# Vulnerability Class:
https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29
Cross Site Scripting (https://www.owasp.org/index.php/Top_10_2013-A3-Cross-Site_Scripting_(XSS))
# Steps to Reproduce: (POC):
After installing the plugin
You can use the following exploit code to exploit the vulnerability. For testing - you can just save it as .html and then get it clicked with an logged in administrator (by social engineering/spear phishing techniques) and see exploit in action
Almost majority of the fields are vulnerable to CSRF + XSS attack
<html>
<body>
<form action="http://localhost/wordpress/wp-admin/options-general.php?page=spnbabble.php" method="POST">
<input type="hidden" name="username" value="csrf testing" />
<input type="hidden" name="password" value="" />
<input type="hidden" name="blogname" value="" />
<input type="hidden" name="postprefix" value="New Blog Post:" />
<input type="hidden" name="spn_enable" value="Yes" />
<input type="hidden" name="spn_update" value="Yes" />
<input type="hidden" name="info_update" value="Update Options" />
<input type="submit" value="Submit request" />
</form>
</body>
</html>
# Recommendations:
a) Use proper input filtering techniques
b) Use unique tokens such as nonces
# Mitigation:
Plugin Closed
# Credits:
Manideep K
Information Security Researcher
https://in.linkedin.com/in/manideepk
| VAR-201412-0694 | No CVE | Multiple Hitachi Products Multiple Unspecified Buffer Overflow Vulnerabilities |
CVSS V2: - CVSS V3: - Severity: - |
Multiple Hitachi Products are prone to multiple unspecified buffer-overflow vulnerabilities because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Attackers can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely cause denial-of-service conditions.
| VAR-201412-0695 | No CVE | Multiple Hitachi Products Cross Site Scripting and Arbitrary Code Execution Vulnerabilities |
CVSS V2: - CVSS V3: - Severity: - |
Multiple Hitachi Products are prone to a cross-site scripting vulnerability and an arbitrary-code execution vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and steal cookie-based authentication credentials or execute arbitrary code within the context of the vulnerable application.
| VAR-201412-0274 | CVE-2014-3364 | Cisco Prime Security Manager of Web Cross-site scripting vulnerability in the framework |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Prime Security Manager (aka PRSM) 9.2.1-2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) Access Policies or (2) Device Summary Dashboard parameter, aka Bug ID CSCuq80661.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
This issue is being tracked by Cisco Bug ID CSCuq80661. The platform can add multiple ASA CX devices to PRSM's device inventory and apply security policies to their devices