VARIoT IoT vulnerabilities database

VAR-200906-0064 | CVE-2009-0955 | Apple QuickTime Vulnerable to arbitrary code execution for handling image description atoms |
CVSS V2: 9.3 CVSS V3: - Severity: HIGH |
Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image description atoms in an Apple video file, related to a "sign extension issue.". Apple QuickTime is prone to a vulnerability that occurs because the bit width of a number is increased without changing its sign in certain image description atoms.
Successful exploits will allow the attacker to execute arbitrary code in the context of the user running the application. Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista, Windows XP SP3, and Mac OS X. Apple QuickTime is a very popular multimedia player. Versions of QuickTime prior to 7.6.2 have multiple security vulnerabilities that allow users to cause a denial of service or completely compromise a user's system through malformed media files. ----------------------------------------------------------------------
Are you missing:
SECUNIA ADVISORY ID:
Critical:
Impact:
Where:
within the advisory below?
This is now part of the Secunia commercial solutions.
Click here to learn more about our commercial solutions:
http://secunia.com/advisories/business_solutions/
Click here to trial our solutions:
http://secunia.com/advisories/try_vi/
----------------------------------------------------------------------
TITLE:
Apple QuickTime PICT Parsing Buffer Overflow Vulnerability
SECUNIA ADVISORY ID:
SA35091
VERIFY ADVISORY:
http://secunia.com/advisories/35091/
DESCRIPTION:
A vulnerability has been reported in Apple QuickTime, which can be
exploited by malicious people to compromise a user's system
The vulnerability is caused due to an error in the processing of
"0x77" tags within PICT images, which can be exploited to cause a
heap-based buffer overflow when the user opens a specially crafted
PICT image or visits a malicious web site.
This is related to vulnerability #30 in:
SA35074
SOLUTION:
Do not browse untrusted web sites. Do not open files from untrusted
sources.
PROVIDED AND/OR DISCOVERED BY:
Damian Put and Sebastian Apelt, reported via ZDI.
ORIGINAL ADVISORY:
http://www.zerodayinitiative.com/advisories/ZDI-09-021/
OTHER REFERENCES:
SA35074:
http://secunia.com/advisories/35074/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
VAR-200906-0063 | CVE-2009-0954 | Apple QuickTime In CRGN Buffer overflow vulnerability in atom type processing |
CVSS V2: 9.3 CVSS V3: - Severity: HIGH |
Heap-based buffer overflow in Apple QuickTime before 7.6.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a movie file containing crafted Clipping Region (CRGN) atom types. This vulnerability allows attackers to execute arbitrary code on vulnerable installations of QuickTime Player. The application trusts the contents of the atom to contain a terminator during a copy operation. The application will copy user-supplied data into a heap-buffer until it identifies this terminator. This will allow one to overwrite heap-control structures which can be leveraged to achieve code execution from the context of the application. Apple QuickTime is prone to a heap-based buffer-overflow vulnerability.
A remote attacker can exploit this issue by enticing an unsuspecting user to open a specially crafted file. Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista and Windows XP SP3. Versions of QuickTime prior to 7.6.2 have multiple security vulnerabilities that allow users to cause a denial of service or completely compromise a user's system through malformed media files. ZDI-09-028: Apple QuickTime CRGN Atom Parsing Heap Buffer Overflow
Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-09-028
June 2, 2009
-- CVE ID:
CVE-2009-0954
-- Affected Vendors:
Apple
-- Affected Products:
Apple Quicktime
-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 6698.
-- Vendor Response:
Apple has issued an update to correct this vulnerability. More
details can be found at:
http://support.apple.com/kb/HT3591
-- Disclosure Timeline:
2008-12-17 - Vulnerability reported to vendor
2009-06-02 - Coordinated public release of advisory
-- Credit:
This vulnerability was discovered by:
* Anonymous
* Damian Put
-- About the Zero Day Initiative (ZDI):
Established by TippingPoint, The Zero Day Initiative (ZDI) represents
a best-of-breed model for rewarding security researchers for responsibly
disclosing discovered vulnerabilities.
Researchers interested in getting paid for their security research
through the ZDI can find more information and sign-up at:
http://www.zerodayinitiative.com
The ZDI is unique in how the acquired vulnerability information is
used. TippingPoint does not re-sell the vulnerability details or any
exploit code. Instead, upon notifying the affected product vendor,
TippingPoint provides its customers with zero day protection through
its intrusion prevention technology. Explicit details regarding the
specifics of the vulnerability are not exposed to any parties until
an official vendor patch is publicly available. Furthermore, with the
altruistic aim of helping to secure a broader user base, TippingPoint
provides this vulnerability information confidentially to security
vendors (including competitors) who have a vulnerability protection or
mitigation product.
Our vulnerability disclosure policy is available online at:
http://www.zerodayinitiative.com/advisories/disclosure_policy/
. ----------------------------------------------------------------------
Are you missing:
SECUNIA ADVISORY ID:
Critical:
Impact:
Where:
within the advisory below?
This is now part of the Secunia commercial solutions.
Click here to learn more about our commercial solutions:
http://secunia.com/advisories/business_solutions/
Click here to trial our solutions:
http://secunia.com/advisories/try_vi/
----------------------------------------------------------------------
TITLE:
Apple QuickTime PICT Parsing Buffer Overflow Vulnerability
SECUNIA ADVISORY ID:
SA35091
VERIFY ADVISORY:
http://secunia.com/advisories/35091/
DESCRIPTION:
A vulnerability has been reported in Apple QuickTime, which can be
exploited by malicious people to compromise a user's system
The vulnerability is caused due to an error in the processing of
"0x77" tags within PICT images, which can be exploited to cause a
heap-based buffer overflow when the user opens a specially crafted
PICT image or visits a malicious web site.
This is related to vulnerability #30 in:
SA35074
SOLUTION:
Do not browse untrusted web sites. Do not open files from untrusted
sources.
PROVIDED AND/OR DISCOVERED BY:
Damian Put and Sebastian Apelt, reported via ZDI.
ORIGINAL ADVISORY:
http://www.zerodayinitiative.com/advisories/ZDI-09-021/
OTHER REFERENCES:
SA35074:
http://secunia.com/advisories/35074/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
VAR-200906-0061 | CVE-2009-0952 | Apple QuickTime In compression PSD Vulnerability to execute arbitrary code related to image processing |
CVSS V2: 9.3 CVSS V3: - Severity: HIGH |
Buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted compressed PSD image. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists when the application parses a malformed .PSD image. While decoding the columns, rows and channels in the image header, the application trusts a different length for copying than used for allocating it. This results in a heap overflow and can lead to code execution under the context of the current user. Apple QuickTime is prone to a buffer-overflow vulnerability.
A remote attacker can exploit this issue by enticing an unsuspecting user to open a specially crafted image. Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista, Windows XP SP3, and Mac OS X. Versions of QuickTime prior to 7.6.2 have multiple security vulnerabilities that allow users to cause a denial of service or completely compromise a user's system through malformed media files. ----------------------------------------------------------------------
Are you missing:
SECUNIA ADVISORY ID:
Critical:
Impact:
Where:
within the advisory below?
This is now part of the Secunia commercial solutions.
Click here to learn more about our commercial solutions:
http://secunia.com/advisories/business_solutions/
Click here to trial our solutions:
http://secunia.com/advisories/try_vi/
----------------------------------------------------------------------
TITLE:
Apple QuickTime PICT Parsing Buffer Overflow Vulnerability
SECUNIA ADVISORY ID:
SA35091
VERIFY ADVISORY:
http://secunia.com/advisories/35091/
DESCRIPTION:
A vulnerability has been reported in Apple QuickTime, which can be
exploited by malicious people to compromise a user's system
The vulnerability is caused due to an error in the processing of
"0x77" tags within PICT images, which can be exploited to cause a
heap-based buffer overflow when the user opens a specially crafted
PICT image or visits a malicious web site.
This is related to vulnerability #30 in:
SA35074
SOLUTION:
Do not browse untrusted web sites. Do not open files from untrusted
sources.
PROVIDED AND/OR DISCOVERED BY:
Damian Put and Sebastian Apelt, reported via ZDI.
ORIGINAL ADVISORY:
http://www.zerodayinitiative.com/advisories/ZDI-09-021/
OTHER REFERENCES:
SA35074:
http://secunia.com/advisories/35074/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
. ZDI-09-026: Apple QuickTime Packed-bit Decoding Heap Overflow Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-09-026
June 2, 2009
-- CVE ID:
CVE-2009-0952
-- Affected Vendors:
Apple
-- Affected Products:
Apple Quicktime
-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 8047.
-- Vendor Response:
Apple has issued an update to correct this vulnerability. More
details can be found at:
http://support.apple.com/kb/HT3591
-- Disclosure Timeline:
2009-04-15 - Vulnerability reported to vendor
2009-06-02 - Coordinated public release of advisory
-- Credit:
This vulnerability was discovered by:
* Damian Put
-- About the Zero Day Initiative (ZDI):
Established by TippingPoint, The Zero Day Initiative (ZDI) represents
a best-of-breed model for rewarding security researchers for responsibly
disclosing discovered vulnerabilities.
Researchers interested in getting paid for their security research
through the ZDI can find more information and sign-up at:
http://www.zerodayinitiative.com
The ZDI is unique in how the acquired vulnerability information is
used. TippingPoint does not re-sell the vulnerability details or any
exploit code. Instead, upon notifying the affected product vendor,
TippingPoint provides its customers with zero day protection through
its intrusion prevention technology. Explicit details regarding the
specifics of the vulnerability are not exposed to any parties until
an official vendor patch is publicly available. Furthermore, with the
altruistic aim of helping to secure a broader user base, TippingPoint
provides this vulnerability information confidentially to security
vendors (including competitors) who have a vulnerability protection or
mitigation product.
Our vulnerability disclosure policy is available online at:
http://www.zerodayinitiative.com/advisories/disclosure_policy/
VAR-200906-0062 | CVE-2009-0953 | Apple QuickTime In PICT Vulnerability to execute arbitrary code related to image processing |
CVSS V2: 9.3 CVSS V3: - Severity: HIGH |
Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists in the parsing of PICT files in QuickTime.qts. While processing data for opcode 0x8201 QuickTime trusts a value contained in the file and makes an allocation accordingly. The process then enters a loop whose terminating condition is controlled. The previously allocated heap buffer can be overflowed leading to arbitrary code execution under the context of the user running QuickTime. Apple QuickTime is prone to a heap-based buffer-overflow vulnerability.
A remote attacker can exploit this issue by enticing an unsuspecting user to open a specially crafted file. Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista, Windows XP SP3, and Mac OS X. Versions of QuickTime prior to 7.6.2 have multiple security vulnerabilities that allow users to cause a denial of service or completely compromise a user's system through malformed media files. ----------------------------------------------------------------------
Are you missing:
SECUNIA ADVISORY ID:
Critical:
Impact:
Where:
within the advisory below?
This is now part of the Secunia commercial solutions.
This is related to vulnerability #30 in:
SA35074
SOLUTION:
Do not browse untrusted web sites. Do not open files from untrusted
sources.
PROVIDED AND/OR DISCOVERED BY:
Damian Put and Sebastian Apelt, reported via ZDI.
ORIGINAL ADVISORY:
http://www.zerodayinitiative.com/advisories/ZDI-09-021/
OTHER REFERENCES:
SA35074:
http://secunia.com/advisories/35074/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
. ZDI-09-027: Apple Quicktime PICT Opcode 0x8201 Heap Overflow Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-09-027
June 2, 2009
-- CVE ID:
CVE-2009-0953
-- Affected Vendors:
Apple
-- Affected Products:
Apple Quicktime
-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 6664.
-- Vendor Response:
Apple has issued an update to correct this vulnerability. More
details can be found at:
http://support.apple.com/kb/HT3591
-- Disclosure Timeline:
2008-12-17 - Vulnerability reported to vendor
2009-06-02 - Coordinated public release of advisory
-- Credit:
This vulnerability was discovered by:
* Sebastian Apelt (sebastian.apelt@siberas.de)
-- About the Zero Day Initiative (ZDI):
Established by TippingPoint, The Zero Day Initiative (ZDI) represents
a best-of-breed model for rewarding security researchers for responsibly
disclosing discovered vulnerabilities.
Researchers interested in getting paid for their security research
through the ZDI can find more information and sign-up at:
http://www.zerodayinitiative.com
The ZDI is unique in how the acquired vulnerability information is
used. TippingPoint does not re-sell the vulnerability details or any
exploit code. Instead, upon notifying the affected product vendor,
TippingPoint provides its customers with zero day protection through
its intrusion prevention technology. Explicit details regarding the
specifics of the vulnerability are not exposed to any parties until
an official vendor patch is publicly available. Furthermore, with the
altruistic aim of helping to secure a broader user base, TippingPoint
provides this vulnerability information confidentially to security
vendors (including competitors) who have a vulnerability protection or
mitigation product.
Our vulnerability disclosure policy is available online at:
http://www.zerodayinitiative.com/advisories/disclosure_policy/
VAR-200906-0060 | CVE-2009-0951 | Apple QuickTime In FLC Vulnerability in arbitrary code execution related to processing of compressed files |
CVSS V2: 9.3 CVSS V3: - Severity: HIGH |
Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC compression file. This vulnerability allows attackers to execute arbitrary code on vulnerable installations of QuickTime Player. User interaction is required to exploit this vulnerability in that the target must either open a malicious file, or visit a malicious web page.The specific flaw exists during decompression of a delta-encoded chunk. The algorithm to decompress the frame trusts a line specifier when calculating where to write decompressed data. This results in a relative write using attacker supplied values which can lead to remove code execution under the context of the current user. Apple QuickTime is prone to a heap-based buffer-overflow vulnerability.
A remote attacker can exploit this issue by enticing an unsuspecting user to open a specially crafted file. Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista, Windows XP SP3, and Mac OS X. Versions of QuickTime prior to 7.6.2 have multiple security vulnerabilities that allow users to cause a denial of service or completely compromise a user's system through malformed media files. ----------------------------------------------------------------------
Are you missing:
SECUNIA ADVISORY ID:
Critical:
Impact:
Where:
within the advisory below?
This is now part of the Secunia commercial solutions.
Click here to learn more about our commercial solutions:
http://secunia.com/advisories/business_solutions/
Click here to trial our solutions:
http://secunia.com/advisories/try_vi/
----------------------------------------------------------------------
TITLE:
Apple QuickTime PICT Parsing Buffer Overflow Vulnerability
SECUNIA ADVISORY ID:
SA35091
VERIFY ADVISORY:
http://secunia.com/advisories/35091/
DESCRIPTION:
A vulnerability has been reported in Apple QuickTime, which can be
exploited by malicious people to compromise a user's system
The vulnerability is caused due to an error in the processing of
"0x77" tags within PICT images, which can be exploited to cause a
heap-based buffer overflow when the user opens a specially crafted
PICT image or visits a malicious web site.
This is related to vulnerability #30 in:
SA35074
SOLUTION:
Do not browse untrusted web sites. Do not open files from untrusted
sources.
PROVIDED AND/OR DISCOVERED BY:
Damian Put and Sebastian Apelt, reported via ZDI.
ORIGINAL ADVISORY:
http://www.zerodayinitiative.com/advisories/ZDI-09-021/
OTHER REFERENCES:
SA35074:
http://secunia.com/advisories/35074/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
. ZDI-09-025: Apple Quicktime Picture Viewer FLC Delta-Encoded Frame
Decompression Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-09-025
June 2, 2009
-- CVE ID:
CVE-2009-0951
-- Affected Vendors:
Apple
-- Affected Products:
Apple Quicktime
-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 6570.
The specific flaw exists during decompression of a delta-encoded chunk.
-- Vendor Response:
Apple has issued an update to correct this vulnerability. More
details can be found at:
http://support.apple.com/kb/HT3591
-- Disclosure Timeline:
2008-10-28 - Vulnerability reported to vendor
2009-06-02 - Coordinated public release of advisory
-- Credit:
This vulnerability was discovered by:
* Anonymous
-- About the Zero Day Initiative (ZDI):
Established by TippingPoint, The Zero Day Initiative (ZDI) represents
a best-of-breed model for rewarding security researchers for responsibly
disclosing discovered vulnerabilities.
Researchers interested in getting paid for their security research
through the ZDI can find more information and sign-up at:
http://www.zerodayinitiative.com
The ZDI is unique in how the acquired vulnerability information is
used. TippingPoint does not re-sell the vulnerability details or any
exploit code. Instead, upon notifying the affected product vendor,
TippingPoint provides its customers with zero day protection through
its intrusion prevention technology. Explicit details regarding the
specifics of the vulnerability are not exposed to any parties until
an official vendor patch is publicly available. Furthermore, with the
altruistic aim of helping to secure a broader user base, TippingPoint
provides this vulnerability information confidentially to security
vendors (including competitors) who have a vulnerability protection or
mitigation product.
Our vulnerability disclosure policy is available online at:
http://www.zerodayinitiative.com/advisories/disclosure_policy/
VAR-200906-0053 | CVE-2009-0956 | Apple QuickTime Vulnerable to arbitrary code execution related to user data atom handling |
CVSS V2: 9.3 CVSS V3: - Severity: HIGH |
Apple QuickTime before 7.6.2 does not properly initialize memory before use in handling movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a movie containing a user data atom of size zero. Apple QuickTime is prone to a remote code-execution vulnerability.
A remote attacker can exploit this issue by enticing an unsuspecting user to open a specially crafted file.
Successful exploits will allow the attacker to execute arbitrary code in the context of the user running the application. Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista, Windows XP SP3, and Mac OS X. Versions of QuickTime prior to 7.6.2 have multiple security vulnerabilities that allow users to cause a denial of service or completely compromise a user's system through malformed media files. ----------------------------------------------------------------------
Are you missing:
SECUNIA ADVISORY ID:
Critical:
Impact:
Where:
within the advisory below?
This is now part of the Secunia commercial solutions.
Click here to learn more about our commercial solutions:
http://secunia.com/advisories/business_solutions/
Click here to trial our solutions:
http://secunia.com/advisories/try_vi/
----------------------------------------------------------------------
TITLE:
Apple QuickTime PICT Parsing Buffer Overflow Vulnerability
SECUNIA ADVISORY ID:
SA35091
VERIFY ADVISORY:
http://secunia.com/advisories/35091/
DESCRIPTION:
A vulnerability has been reported in Apple QuickTime, which can be
exploited by malicious people to compromise a user's system
The vulnerability is caused due to an error in the processing of
"0x77" tags within PICT images, which can be exploited to cause a
heap-based buffer overflow when the user opens a specially crafted
PICT image or visits a malicious web site.
This is related to vulnerability #30 in:
SA35074
SOLUTION:
Do not browse untrusted web sites. Do not open files from untrusted
sources.
PROVIDED AND/OR DISCOVERED BY:
Damian Put and Sebastian Apelt, reported via ZDI.
ORIGINAL ADVISORY:
http://www.zerodayinitiative.com/advisories/ZDI-09-021/
OTHER REFERENCES:
SA35074:
http://secunia.com/advisories/35074/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
VAR-200906-0034 | CVE-2009-0185 | Apple QuickTime In MS ADPCM Buffer overflow vulnerability in processing of encoded audio data |
CVSS V2: 9.3 CVSS V3: - Severity: HIGH |
Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted MS ADPCM encoded audio data in an AVI movie file. Apple QuickTime is prone to a heap-based buffer-overflow vulnerability.
A remote attacker can exploit this issue by enticing an unsuspecting user to open a specially AVI crafted file.
Successful exploits will allow the attacker to execute arbitrary code in the context of the user running the application. Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista, Windows XP SP3, and Mac OS X. Versions of QuickTime prior to 7.6.2 have multiple security vulnerabilities that allow users to cause a denial of service or completely compromise a user's system through malformed media files. ======================================================================
Secunia Research 02/06/2009
- Apple QuickTime MS ADPCM Encoding Buffer Overflow -
======================================================================
Table of Contents
Affected Software....................................................1
Severity.............................................................2
Vendor's Description of Software.....................................3
Description of Vulnerability.........................................4
Solution.............................................................5
Time Table...........................................................6
Credits..............................................................7
References...........................................................8
About Secunia........................................................9
Verification........................................................10
======================================================================
1) Affected Software
* Apple QuickTime version 7.6
NOTE: Other versions may also be affected.
======================================================================
2) Severity
Rating: Highly critical
Impact: System access
Where: Remote
======================================================================
3) Vendor's Description of Software
"Whether you are creating content for delivery on cell phones,
broadcast or the Internet, or a software developer looking to take
your application to the next level, QuickTime provides the most
comprehensive platform in the industry."
Product Link:
http://www.apple.com/quicktime/
======================================================================
4) Description of Vulnerability
Secunia Research has discovered a vulnerability in Apple QuickTime,
which can be exploited by malicious people to compromise a user's
system.
The vulnerability is caused by an error in the processing of MS ADPCM
encoded audio data.
======================================================================
5) Solution
Update to version 7.6.2.
======================================================================
6) Time Table
04/02/2009 - Vendor notified.
05/02/2009 - Vendor response.
25/05/2009 - Status update requested.
26/05/2009 - Vendor provides status update.
02/06/2009 - Public disclosure.
======================================================================
7) Credits
Discovered by Alin Rad Pop, Secunia Research.
======================================================================
8) References
The Common Vulnerabilities and Exposures (CVE) project has assigned
CVE-2009-0185 for the vulnerability.
Apple:
http://support.apple.com/kb/HT3591
======================================================================
9) About Secunia
Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:
http://secunia.com/advisories/business_solutions/
Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private
individuals, who are interested in or concerned about IT-security.
http://secunia.com/advisories/
Secunia believes that it is important to support the community and to
do active vulnerability research in order to aid improving the
security and reliability of software in general:
http://secunia.com/secunia_research/
Secunia regularly hires new skilled team members. Check the URL below
to see currently vacant positions:
http://secunia.com/corporate/jobs/
Secunia offers a FREE mailing list called Secunia Security Advisories:
http://secunia.com/advisories/mailing_lists/
======================================================================
10) Verification
Please verify this advisory by visiting the Secunia website:
http://secunia.com/secunia_research/2009-6/
Complete list of vulnerability reports published by Secunia Research:
http://secunia.com/secunia_research/
======================================================================
. ----------------------------------------------------------------------
Are you missing:
SECUNIA ADVISORY ID:
Critical:
Impact:
Where:
within the advisory below?
This is now part of the Secunia commercial solutions.
Click here to learn more about our commercial solutions:
http://secunia.com/advisories/business_solutions/
Click here to trial our solutions:
http://secunia.com/advisories/try_vi/
----------------------------------------------------------------------
TITLE:
Apple QuickTime PICT Parsing Buffer Overflow Vulnerability
SECUNIA ADVISORY ID:
SA35091
VERIFY ADVISORY:
http://secunia.com/advisories/35091/
DESCRIPTION:
A vulnerability has been reported in Apple QuickTime, which can be
exploited by malicious people to compromise a user's system
The vulnerability is caused due to an error in the processing of
"0x77" tags within PICT images, which can be exploited to cause a
heap-based buffer overflow when the user opens a specially crafted
PICT image or visits a malicious web site.
This is related to vulnerability #30 in:
SA35074
SOLUTION:
Do not browse untrusted web sites. Do not open files from untrusted
sources.
PROVIDED AND/OR DISCOVERED BY:
Damian Put and Sebastian Apelt, reported via ZDI.
ORIGINAL ADVISORY:
http://www.zerodayinitiative.com/advisories/ZDI-09-021/
OTHER REFERENCES:
SA35074:
http://secunia.com/advisories/35074/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
VAR-200906-0054 | CVE-2009-0957 | Apple QuickTime In JP2 Image Processing Buffer Overflow Vulnerability |
CVSS V2: 9.3 CVSS V3: - Severity: HIGH |
Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 image. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists during the parsing of malformed Jpen2000 image files. A field is read directly from the file and used to allocate memory for a structure. If the value read is smaller then the expected structure size then a memory corruption will occur which can be leveraged by an attacker to execute arbitrary code under the context of the current user. Apple QuickTime is prone to a heap-based buffer-overflow vulnerability.
A remote attacker can exploit this issue by enticing an unsuspecting user to open a specially crafted file. Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista, Windows XP SP3, and Mac OS X. Versions of QuickTime prior to 7.6.2 have multiple security vulnerabilities that allow users to cause a denial of service or completely compromise a user's system through malformed media files. ----------------------------------------------------------------------
Are you missing:
SECUNIA ADVISORY ID:
Critical:
Impact:
Where:
within the advisory below?
This is now part of the Secunia commercial solutions.
Click here to learn more about our commercial solutions:
http://secunia.com/advisories/business_solutions/
Click here to trial our solutions:
http://secunia.com/advisories/try_vi/
----------------------------------------------------------------------
TITLE:
Apple QuickTime PICT Parsing Buffer Overflow Vulnerability
SECUNIA ADVISORY ID:
SA35091
VERIFY ADVISORY:
http://secunia.com/advisories/35091/
DESCRIPTION:
A vulnerability has been reported in Apple QuickTime, which can be
exploited by malicious people to compromise a user's system
The vulnerability is caused due to an error in the processing of
"0x77" tags within PICT images, which can be exploited to cause a
heap-based buffer overflow when the user opens a specially crafted
PICT image or visits a malicious web site.
This is related to vulnerability #30 in:
SA35074
SOLUTION:
Do not browse untrusted web sites. Do not open files from untrusted
sources.
PROVIDED AND/OR DISCOVERED BY:
Damian Put and Sebastian Apelt, reported via ZDI.
ORIGINAL ADVISORY:
http://www.zerodayinitiative.com/advisories/ZDI-09-021/
OTHER REFERENCES:
SA35074:
http://secunia.com/advisories/35074/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
. ZDI-09-029: Apple QuickTime Jpeg2000 Marker Size Heap Overflow Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-09-029
June 2, 2009
-- CVE ID:
CVE-2009-0957
-- Affected Vendors:
Apple
-- Affected Products:
Apple Quicktime
-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 8153.
-- Vendor Response:
Apple has issued an update to correct this vulnerability. More
details can be found at:
http://support.apple.com/kb/HT3591
-- Disclosure Timeline:
2009-04-28 - Vulnerability reported to vendor
2009-06-02 - Coordinated public release of advisory
-- Credit:
This vulnerability was discovered by:
* Damian Put
-- About the Zero Day Initiative (ZDI):
Established by TippingPoint, The Zero Day Initiative (ZDI) represents
a best-of-breed model for rewarding security researchers for responsibly
disclosing discovered vulnerabilities.
Researchers interested in getting paid for their security research
through the ZDI can find more information and sign-up at:
http://www.zerodayinitiative.com
The ZDI is unique in how the acquired vulnerability information is
used. TippingPoint does not re-sell the vulnerability details or any
exploit code. Instead, upon notifying the affected product vendor,
TippingPoint provides its customers with zero day protection through
its intrusion prevention technology. Explicit details regarding the
specifics of the vulnerability are not exposed to any parties until
an official vendor patch is publicly available. Furthermore, with the
altruistic aim of helping to secure a broader user base, TippingPoint
provides this vulnerability information confidentially to security
vendors (including competitors) who have a vulnerability protection or
mitigation product.
Our vulnerability disclosure policy is available online at:
http://www.zerodayinitiative.com/advisories/disclosure_policy/
VAR-200906-0033 | CVE-2009-0188 | Apple iTunes In Sorenson 3 Vulnerability in executing arbitrary code related to processing of video files |
CVSS V2: 9.3 CVSS V3: - Severity: HIGH |
Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie composed of a Sorenson 3 video file. Apple QuickTime is prone to a memory-corruption vulnerability.
A remote attacker can exploit this issue by enticing an unsuspecting user to open a specially crafted file.
Successful exploits will allow the attacker to execute arbitrary code in the context of the user running the application. Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista, Windows XP SP3, and Mac OS X. ----------------------------------------------------------------------
Are you missing:
SECUNIA ADVISORY ID:
Critical:
Impact:
Where:
within the advisory below?
This is now part of the Secunia commercial solutions.
Click here to learn more about our commercial solutions:
http://secunia.com/advisories/business_solutions/
Click here to trial our solutions:
http://secunia.com/advisories/try_vi/
----------------------------------------------------------------------
TITLE:
Apple QuickTime PICT Parsing Buffer Overflow Vulnerability
SECUNIA ADVISORY ID:
SA35091
VERIFY ADVISORY:
http://secunia.com/advisories/35091/
DESCRIPTION:
A vulnerability has been reported in Apple QuickTime, which can be
exploited by malicious people to compromise a user's system
The vulnerability is caused due to an error in the processing of
"0x77" tags within PICT images, which can be exploited to cause a
heap-based buffer overflow when the user opens a specially crafted
PICT image or visits a malicious web site.
This is related to vulnerability #30 in:
SA35074
SOLUTION:
Do not browse untrusted web sites. Do not open files from untrusted
sources.
PROVIDED AND/OR DISCOVERED BY:
Damian Put and Sebastian Apelt, reported via ZDI.
ORIGINAL ADVISORY:
http://www.zerodayinitiative.com/advisories/ZDI-09-021/
OTHER REFERENCES:
SA35074:
http://secunia.com/advisories/35074/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
. ======================================================================
Secunia Research 02/06/2009
- QuickTime Sorenson Video 3 Content Parsing Vulnerability -
======================================================================
Table of Contents
Affected Software....................................................1
Severity.............................................................2
Vendor's Description of Software.....................................3
Description of Vulnerability.........................................4
Solution.............................................................5
Time Table...........................................................6
Credits..............................................................7
References...........................................................8
About Secunia........................................................9
Verification........................................................10
======================================================================
1) Affected Software
* Apple QuickTime 7.60
NOTE: Other versions may also be affected.
======================================================================
2) Severity
Rating: Highly critical
Impact: System compromise
Where: Remote
======================================================================
3) Vendor's Description of Software
"When you hop aboard QuickTime 7 Player, you\x92re assured of a truly
rich multimedia experience.".
Product Link:
http://www.apple.com/quicktime/player/
======================================================================
4) Description of Vulnerability
Secunia Research has discovered a vulnerability in QuickTime, which
can be exploited by malicious people to compromise a user's system.
The vulnerability is caused by an error in the parsing of Sorenson
Video 3 content.
======================================================================
5) Solution
Update to version 7.6.2.
======================================================================
6) Time Table
26/02/2009 - Vendor notified.
02/03/200X - Vendor response.
25/05/2009 - Status update requested.
26/05/2009 - Vendor provides status update.
02/06/2009 - Public disclosure.
======================================================================
7) Credits
Discovered by Carsten Eiram, Secunia Research.
======================================================================
8) References
The Common Vulnerabilities and Exposures (CVE) project has assigned
CVE-2009-0188 for the vulnerability.
Apple:
http://support.apple.com/kb/HT3591
======================================================================
9) About Secunia
Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:
http://secunia.com/advisories/business_solutions/
Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private
individuals, who are interested in or concerned about IT-security.
http://secunia.com/advisories/
Secunia believes that it is important to support the community and to
do active vulnerability research in order to aid improving the
security and reliability of software in general:
http://secunia.com/secunia_research/
Secunia regularly hires new skilled team members. Check the URL below
to see currently vacant positions:
http://secunia.com/corporate/jobs/
Secunia offers a FREE mailing list called Secunia Security Advisories:
http://secunia.com/advisories/mailing_lists/
======================================================================
10) Verification
Please verify this advisory by visiting the Secunia website:
http://secunia.com/secunia_research/2009-10/
Complete list of vulnerability reports published by Secunia Research:
http://secunia.com/secunia_research/
======================================================================
VAR-200907-0452 | No CVE | Cosminexus Processing Kit for XML and Hitachi Developer's Kit for Java Possible Unauthorized Access through Vulnerability in Encoding Process |
CVSS V2: 10.0 CVSS V3: - Severity: High |
Cosminexus Processing Kit for XML and Hitachi Developer's Kit for Java have a vulnerability where UTF-8 output is not properly judged due to deficiency in encoding processing, which may lead to unauthorized access.Unauthorized access may be done exploiting a deficiency in encoding processing. Multiple products from Hitachi are prone to multiple code-execution vulnerabilities.
Successfully exploiting these issues would allow the attacker to execute arbitrary code in the context of the currently logged-in user or cause denial-of-service conditions.
An attacker can exploit this issue to gain read access to arbitrary memory locations. Information obtained may aid in other attacks.
NOTE: This BID is being retired because it is a duplicate of the issue discussed in BID 35589. ----------------------------------------------------------------------
Do you have VARM strategy implemented?
(Vulnerability Assessment Remediation Management)
If not, then implement it through the most reliable vulnerability
intelligence source on the market.
Implement it through Secunia.
For more information visit:
http://secunia.com/advisories/business_solutions/
Alternatively request a call from a Secunia representative today to
discuss how we can help you with our capabilities contact us at:
sales@secunia.com
----------------------------------------------------------------------
TITLE:
Hitachi Products ZIP and UTF-8 Processing Vulnerabilities
SECUNIA ADVISORY ID:
SA35413
VERIFY ADVISORY:
http://secunia.com/advisories/35413/
DESCRIPTION:
Some vulnerabilities have been reported in multiple Hitachi products,
which can be exploited by malicious people to potentially compromise a
vulnerable system.
1) An unspecified error in the processing of ZIP files can be
exploited to potentially execute arbitrary code.
2) An unspecified error in the processing of UTF-8 data can be
exploited to potentially execute arbitrary code.
Please see the vendor's advisory for a full list of affected
products.
SOLUTION:
Update to a fixed version. See vendor advisory for details.
PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.
ORIGINAL ADVISORY:
Hitachi:
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS09-007/index.html
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS09-008/index.html
JVN:
http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-001544.html
http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-001545.html
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
VAR-200905-0318 | CVE-2009-1745 | Armorlogic Profense Web Application Firewall Vulnerabilities that gain access |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, has a default root password hash, and permits password-based root logins over SSH, which makes it easier for remote attackers to obtain access. Profense Web Application Firewall is prone to a remote security vulnerability
VAR-200905-0167 | CVE-2009-1593 | Armorlogic Profense Web Application Firewall Cross-site scripting attacks (XSS) Vulnerability to be executed |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "negative model," which allows remote attackers to conduct cross-site scripting (XSS) attacks via a modified end tag of a SCRIPT element. Profense Web Application Firewall is prone to multiple security-bypass vulnerabilities.
An attacker can exploit these issues to bypass certain security restrictions and perform various web-application attacks.
Versions *prior to* the following are vulnerable:
Profense 2.4.4
Profense 2.2.22. 0A (encoded newline) bypasses XSS protection mechanisms and executes arbitrary code within the user's browser session
VAR-200905-0168 | CVE-2009-1594 | Armorlogic Profense Web Application Firewall Vulnerabilities that bypass specific protection mechanisms |
CVSS V2: 7.5 CVSS V3: - Severity: HIGH |
Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "positive model," which allows remote attackers to bypass certain protection mechanisms via a %0A (encoded newline), as demonstrated by a %0A in a cross-site scripting (XSS) attack URL. Profense Web Application Firewall is prone to multiple security-bypass vulnerabilities.
An attacker can exploit these issues to bypass certain security restrictions and perform various web-application attacks.
Versions *prior to* the following are vulnerable:
Profense 2.4.4
Profense 2.2.22. Remote attackers can include modified SCRIPT element end tags or % in URL requests
VAR-200905-0302 | CVE-2009-1729 |
Sun Java System Communications Express Vulnerable to cross-site scripting
Related entries in the VARIoT exploits database: VAR-E-200905-0101, VAR-E-200905-0102 |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the abperson_displayName parameter to uwc/abs/search.xml in the Add Contact implementation in the Personal Address Book component or (2) the temporaryCalendars parameter to uwc/base/UWCMain.
This issue is tracked by Sun Alert ID 258068.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Core Security Technologies - CoreLabs Advisory
http://www.coresecurity.com/corelabs/
Multiple XSS in Sun Communications Express
1. *Advisory Information*
Title: Multiple XSS in Sun Communications Express
Advisory ID: CORE-2009-0109
Advisory URL: http://www.coresecurity.com/content/sun-communications-express
Date published: 2009-05-20
Date of last update: 2009-05-20
Vendors contacted: Sun Microsystems
Release mode: Coordinated release
2. *Vulnerability Information*
Class: Cross site scripting (XSS)
Remotely Exploitable: Yes
Locally Exploitable: No
Bugtraq ID: 34154, 34155
CVE Name: CVE-2009-1729
3. 'https://<server>/uwc/abs/search.xml?'
2. For example, an attacker could
exploit a XSS vulnerability to steal user cookies (and then impersonate
the legitimate user) or fake a page requesting information to the user
(i.e. credentials). This vulnerability occurs when user-supplied data is
displayed without encoding.
4. *Vulnerable packages*
4.1. *SPARC Platform*
.
4.2. *x86 Platform*
.
4.3. *Linux*
.
5. *Non-vulnerable packages*
.
6.
7. *Credits*
These vulnerabilities were discovered by the SCS team from Core Security
Technologies.
8. *Technical Description / Proof of Concept Code*
Cross-Site Scripting (commonly referred to as XSS) attacks are the
result of improper encoding or filtering of input obtained from
untrusted sources. The injected code then
takes advantage of the trust given by the user to the vulnerable site.
These attacks are usually targeted at all users of a web application
rather than at the application itself (although one could say that the
users are affected because of a vulnerability of the web application).
The term 'cross-site scripting' is also sometimes used in a
broader-sense referring to different types of attacks involving script
injection into the client. For additional information, please look at
the references [2], [3], [4], [5] and [6].
8.1.
Although the affected URL is originally accessed through a POST request,
this vulnerability can be exploited both with a GET and with a POST
request. Using the following variables:
/-----------
abperson_displayName
- -----------/
The contents of the variables previously mentioned are not being
encoded at the time of using them in HTML output, therefore allowing an
attacker who controls their content to insert javascript code.
The following code is a proof of concept of this flaw:
/-----------
https://<server>/uwc/abs/search.xml?bookid=e11e46531a8a0&j_encoding=UTF-8&uiaction=quickaddcontact&entryid=&valueseparator=%3B&prefix=abperson_&stopalreadyselected=1&isselchanged=0&idstoadd=&selectedbookid=&type=abperson%2Cgroup&wcfg_groupview=&wcfg_searchmode=&stopsearch=1&expandgroup=&expandselectedgroup=&expandonmissing=&nextview=&bookid=e11e46531a8a0&actionbookid=e11e46531a8a0&searchid=7&filter=entry%2Fdisplayname%3D*&firstentry=0&sortby=%2Bentry%2Fdisplayname&curbookid=e11e46531a8a0&searchelem=0&searchby=contains&searchstring=Search+for&searchbookid=e11e46531a8a0&abperson_givenName=aa&abperson_sn=aa&abperson_piEmail1=a%40a.com&abperson_piEmail1Type=work&abperson_piPhone1=11&abperson_piPhone1Type=work&quickaddprefix=abperson_&abperson_displayName=%3Cscript%3Ealert%28%27xss2%27%29%3C%2Fscript%3E%2C+%3Cscript%3Ealert%28%27xss1%27%29%3C%2Fscript%3E&abperson_entrytype=abperson&abperson_memberOfPIBook=e11e46531a8a0
- -----------/
8.2. *Vulnerability #2 - XSS (BID 34155, CVE-2009-1729)*
Cross-site scripting vulnerabilities were found in the following file/url:
/-----------
http://<server>/uwc/base/UWCMain
- -----------/
The contents of the url are not being encoded at the time of using them
in HTML output, therefore allowing an attacker who controls their
content to insert javascript code.
This vulnerability can be exploited through a GET request, and the user
does not need to be logged into the web application. This makes this
cross-site scripting vulnerability perfect to be used by attackers on
email-based attacks. An attacker can send via email a link to a
'calendar' and 'exploit' the victim.
The following code is a proof of concept of this flaw:
/-----------
http://<server>/uwc/base/UWCMain?anon=true&calid=test@test.com&caltype=temporaryCalids&date=20081223T143836Z&category=All&viewctx=day&temporaryCalendars=test@test.com%27;alert(%27hello%27);a=%27
- -----------/
9. *Report Timeline*
. 2009-01-09:
Core Security Technologies notifies Sun Security Coordination Team of
the vulnerability, setting the estimated publication date of the
advisory to Feb 2nd. Technical details are sent to Communications
Express team. 2009-01-09:
The vendor acknowledges reception of the report and asks Core to
postpone publication of the security advisory in order to have enough
time to investigate and fix the bugs. Vendor requests GPG key of Core's
security Advisories team. 2009-01-12:
Core agrees to postpone the advisory publication but asks the vendor for
a feedback of their engineering team as soon as possible in order to
coordinate the release date of fixes and security advisories. 2009-01-21:
Core asks the vendor an estimated date for the release of patches and
fixes. 2009-01-21:
Sun Security Coordination Team notifies Core that the vendor's
engineering team is hoping to have patches released sometime near the
end of February or the beginning of March. The time-frame is tentative
due to the vendor's QA testing process that includes testing of all
patches which may include fixes to bugs unrelated to those reported by
Core. 2009-02-06:
Core re-schedules the advisory publication date to Feb 25th. Updated
timeline sent to the vendor requesting confirmation that patches will be
released by then. 2009-02-16:
The vendor asks Core to delay the advisory publication until the end of
March, in order to finish a rigorous process of internal testing. 2009-02-16:
Core re-schedules the advisory publication date to March 30th. Core
indicates that it would appreciate further technical details about the
flaws from the vendors engineering team. 2009-02-17:
Vendor acknowledges previous email. 2009-03-17:
Core reminds the vendor that the publication of the advisory is
scheduled for March 30th. Core also requests updated information about
the development and release of fixed versions. 2009-03-23:
Vendor confirms that it is on track to have the fix ready for
publication at the end of this month, March 30th, and provides a list of
affected products and versions. 2009-03-24:
Vendor states that there was a confusion on his end, and that patches
are scheduled to complete testing and to be published on 22nd April
2009. Vendor requests Core to delay publication of its advisory. 2009-03-25:
Core confirms that the advisory publication is rescheduled to April 22nd. 2009-04-08:
Sun engineering team informs that they have a fix for other flaw
reported by Core [7]. This fix is currently undergoing Sun standard
testing, and vendor expect to be ready to publish the patch on Monday
20th April 2009. 2009-04-16:
Sun engineering team confirms they are still planning to release the fix
for [7] on 20th April 2009. Core requires an estimated date
for the release of patches and fixes. 2009-04-20:
Sun engineering team informs that the issue which affects Communications
Express is planned for publication later in the week. The vendor will
get back to Core with a more final date once they have confirmed the
details. 2009-04-22:
Sun engineering team informs that the fix related to Communications
Express is currently undergoing internal testing and they expect to be
ready to publish the fixes and the sun alert on 6th May 2009. 2009-04-29:
Core re-schedules the advisory publication date to 6th May 2009, asks
Sun for an URL of the corresponding Sun alert and a list of
non-vulnerable packages. 2009-05-05:
Sun engineering team informs that they are experiencing some
difficulties related to the final release stages of the fix for this
bug. The vendor will not be ready to go public with this fix tomorrow. 2009-05-05:
Core responds that it is possible to postpone the publication of the
advisory, but asks Sun engineering team for an estimated date to reach
the final release of the fix as soon as possible. 2009-05-08:
Sun engineering team informs they are still experiencing some delays
with the final stages of this release process and asks to delay the
publication of the advisory. 2009-05-18:
Sun engineering team confirms that they have resolved the outstanding
issues related to this vulnerability and they expect to be ready to
publish the fixes on Wednesday 20th May. 2009-05-18:
Core re-schedules the advisory publication date to 20th May. 2009-05-20: The advisory CORE-2009-0109 is published.
10. *References*
[1]
http://www.sun.com/software/products/calendar_srvr/comms_express/index.xml
[2] HTML Code Injection and Cross-Site Scripting
http://www.technicalinfo.net/papers/CSS.html.
[3] The Cross-Site Scripting FAQ (XSS)
http://www.cgisecurity.com/articles/xss-faq.shtml
[4] How to prevent Cross-Site Scripting Security Issues
http://support.microsoft.com/default.aspx?scid=KB;en-us;q252985
[5] How to review ASP Code for CSSI Vulnerability
http://support.microsoft.com/default.aspx?scid=kb;EN-US;253119
[6] How to review Visual InterDev Generated Code for CSSI Vulnerability
http://support.microsoft.com/default.aspx?scid=kb;EN-US;253120
[7] HTTP Response Splitting vulnerability in Sun Delegated Administrator
- - http://www.coresecurity.com/content/sun-delegated-administrator
11. *About CoreLabs*
CoreLabs, the research center of Core Security Technologies, is charged
with anticipating the future needs and requirements for information
security technologies. We conduct our research in several important
areas of computer security including system vulnerabilities, cyber
attack planning and simulation, source code auditing, and cryptography.
Our results include problem formalization, identification of
vulnerabilities, novel solutions and prototypes for new technologies.
CoreLabs regularly publishes security advisories, technical papers,
project information and shared software tools for public use at:
http://www.coresecurity.com/corelabs.
12. *About Core Security Technologies*
Core Security Technologies develops strategic solutions that help
security-conscious organizations worldwide develop and maintain a
proactive process for securing their networks. The company's flagship
product, CORE IMPACT, is the most comprehensive product for performing
enterprise security assurance testing. CORE IMPACT evaluates network,
endpoint and end-user vulnerabilities and identifies what resources are
exposed. It enables organizations to determine if current security
investments are detecting and preventing attacks. Core Security
Technologies augments its leading technology solution with world-class
security consulting services, including penetration testing and software
security auditing. Based in Boston, MA and Buenos Aires, Argentina, Core
Security Technologies can be reached at 617-399-6980 or on the Web at
http://www.coresecurity.com.
13. *Disclaimer*
The contents of this advisory are copyright (c) 2009 Core Security
Technologies and (c) 2009 CoreLabs, and may be distributed freely
provided that no fee is charged for this distribution and proper credit
is given.
14. *PGP/GPG Keys*
This advisory has been signed with the GPG key of Core Security
Technologies advisories team, which is available for download at
http://www.coresecurity.com/files/attachments/core_security_advisories.asc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFKFEWVyNibggitWa0RAqSuAKCRr0zxGIvhYRVD92VLI7W1pJezQwCfVvSO
SNbJmS6GjYkZPyIfI3+JIpw=
=wOZe
-----END PGP SIGNATURE-----
. ----------------------------------------------------------------------
Are you missing:
SECUNIA ADVISORY ID:
Critical:
Impact:
Where:
within the advisory below?
This is now part of the Secunia commercial solutions.
Various input is not properly sanitised before being returned to
users.
SOLUTION:
Apply patches.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
VAR-200905-0075 | CVE-2009-1161 | CiscoWorks Common Services TFTP Server Directory Traversal Vulnerability |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows remote attackers to access arbitrary files via unspecified vectors. Multiple products provided by Cisco Systems contain a directory traversal vulnerablility. Multiple Cisco Systems products are vulnerable to directory traversal due to an issue in CiscoWorks Common Services. Jun Okada of NTT DATA SECURITY CORPORATION reported this vulnerability to IPA. JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.A remote attacker could view or alter files on the target server. CiscoWorks Common Services TFTP Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to upload and download arbitrary files outside of the TFTP server root directory. This may result in a denial-of-service condition or lead to a complete compromise of the affected computer.
This issue is tracked by Cisco Bug ID CSCsx07107.
Cisco has released free software updates that address this
vulnerability. A workaround that mitigates this vulnerability is
available.
This advisory is posted at
http://www.cisco.com/warp/public/707/cisco-sa-20090520-cw.shtml.
The TFTP service is enabled by default. To verify that the TFTP service
is running connect to the CiscoWorks interface and choose "Start >
Settings > Control Panel > Administrative Tools > Services" to access
the "Services" window. The name of the service is "CWCS tftp service". No other Cisco products are currently
known to be affected by this vulnerability. CiscoWorks is a
family of products based on Internet standards for managing networks and
devices.
Vulnerability Scoring Details
+----------------------------
Cisco has provided scores for the vulnerability in this advisory based
on the Common Vulnerability Scoring System (CVSS). The CVSS scoring in
this Security Advisory is done in accordance with CVSS version 2.0.
CVSS is a standards-based scoring method that conveys vulnerability
severity and helps determine urgency and priority of response.
Cisco has provided a base and temporal score. Customers can then
compute environmental scores to assist in determining the impact of the
vulnerability in individual networks.
Cisco has provided an FAQ to answer additional questions regarding CVSS
at:
http://www.cisco.com/web/about/security/intelligence/cvss-qandas.html
Cisco has also provided a CVSS calculator to help compute the
environmental impact for individual networks at:
http://intellishield.cisco.com/security/alertmanager/cvss
* CSM: TFTP service allows directory traversal (CSCsx07107)
CVSS Base Score - 10.0
Access Vector - Network
Access Complexity - Low
Authentication - None
Confidentiality Impact - Complete
Integrity Impact - Complete
Availability Impact - Complete
CVSS Temporal Score - 8.7
Exploitability - High
Remediation Level - Official-Fix
Report Confidence - Confirmed
Impact
======
A successful exploitation of this vulnerability may allow an attacker
unauthorized access to view or modify application and host operating
system files.
Software Versions and Fixes
===========================
Cisco has released free software updates that address this
vulnerability. Prior to deploying software, customers should consult
their maintenance provider or check the software for feature set
compatibility and known issues specific to their environment.
This vulnerability has been corrected in the following CiscoWorks Common
Services software patch:
cwcs3.x-win-CSCsx07107-0.zip
The CiscoWorks Common Services patch can be downloaded from the
following link:
http://www.cisco.com/pcgi-bin/tablebuild.pl/cw2000-cd-one
When considering software upgrades, also consult
http://www.cisco.com/go/psirt and any subsequent advisories to determine
exposure and a complete upgrade solution.
In all cases, customers should exercise caution to be certain the
devices to be upgraded contain sufficient memory and that current
hardware and software configurations will continue to be supported
properly by the new release. If the information is not clear, contact
the Cisco Technical Assistance Center (TAC) or your contracted
maintenance provider for assistance.
Workarounds
===========
To mitigate this vulnerability, administrators can disable TFTP services
by completing the following steps:
Step 1. Choose "Start > Settings > Control Panel > Administrative Tools
> Services" to access the Services window.
Step 2. Right-click "CWCS tftp service" and select "Properties".
Step 3. Set the "Startup Type" to "Disabled".
Step 4. Click the "Stop" button to stop the TFTP service.
Note: Disabling TFTP services may impact the functionality of some of
the CiscoWorks components.
Additional mitigations that can be deployed on Cisco devices within the
network are available in the Cisco Applied Mitigation Bulletin companion
document for this advisory, which is available at the following link:
http://www.cisco.com/warp/public/707/cisco-amb-20090520-cw.shtml.
Obtaining Fixed Software
========================
Cisco has released free software updates that address this
vulnerability. Prior to deploying software, customers should consult
their maintenance provider or check the software for feature set
compatibility and known issues specific to their environment.
Customers may only install and expect support for the feature
sets they have purchased. By installing, downloading, accessing
or otherwise using such software upgrades, customers agree to be
bound by the terms of Cisco's software license terms found at
http://www.cisco.com/en/US/docs/general/warranty/English/EU1KEN_.html,
or as otherwise set forth at Cisco.com Downloads at
http://www.cisco.com/public/sw-center/sw-usingswc.shtml.
Do not contact psirt@cisco.com or security-alert@cisco.com for software
upgrades.
Customers with Service Contracts
+-------------------------------
Customers with contracts should obtain upgraded software through their
regular update channels. For most customers, this means that upgrades
should be obtained through the Software Center on Cisco's worldwide
website at http://www.cisco.com.
Customers using Third Party Support Organizations
+------------------------------------------------
Customers whose Cisco products are provided or maintained through prior
or existing agreements with third-party support organizations, such
as Cisco Partners, authorized resellers, or service providers should
contact that support organization for guidance and assistance with the
appropriate course of action in regards to this advisory.
The effectiveness of any workaround or fix is dependent on specific
customer situations, such as product mix, network topology, traffic
behavior, and organizational mission. Due to the variety of affected
products and releases, customers should consult with their service
provider or support organization to ensure any applied workaround or fix
is the most appropriate for use in the intended network before it is
deployed.
Customers without Service Contracts
+----------------------------------
Customers who purchase direct from Cisco but do not hold a Cisco service
contract, and customers who purchase through third-party vendors but are
unsuccessful in obtaining fixed software through their point of sale
should acquire upgrades by contacting the Cisco Technical Assistance
Center (TAC). TAC contacts are as follows.
* +1 800 553 2447 (toll free from within North America)
* +1 408 526 7209 (toll call from anywhere in the world)
* e-mail: tac@cisco.com
Customers should have their product serial number available and be
prepared to give the URL of this notice as evidence of entitlement to a
free upgrade. Free upgrades for non-contract customers must be requested
through the TAC.
Refer to http://www.cisco.com/en/US/support/tsd_cisco_worldwide_contacts.html
for additional TAC contact information, including localized telephone
numbers, and instructions and e-mail addresses for use in various
languages.
Exploitation and Public Announcements
=====================================
The Cisco PSIRT is not aware of any public announcements or malicious
use of the vulnerability described in this advisory.
This vulnerability was found during the resolution of customer service
requests.
Status of this Notice: FINAL
============================
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY
ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF
MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE
INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS
AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS
DOCUMENT AT ANY TIME.
A stand-alone copy or Paraphrase of the text of this document that omits
the distribution URL in the following section is an uncontrolled copy,
and may lack important information or contain factual errors.
Distribution
============
This advisory is posted on Cisco's worldwide website at:
http://www.cisco.com/warp/public/707/cisco-sa-20090520-cw.shtml
In addition to worldwide web posting, a text version of this notice is
clear-signed with the Cisco PSIRT PGP key and is posted to the following
e-mail and Usenet news recipients.
* cust-security-announce@cisco.com
* first-bulletins@lists.first.org
* bugtraq@securityfocus.com
* vulnwatch@vulnwatch.org
* cisco@spot.colorado.edu
* cisco-nsp@puck.nether.net
* full-disclosure@lists.grok.org.uk
* comp.dcom.sys.cisco@newsgate.cisco.com
Future updates of this advisory, if any, will be placed on Cisco's
worldwide website, but may or may not be actively announced on mailing
lists or newsgroups. Users concerned about this problem are encouraged
to check the above URL for any updates.
Revision History
================
+------------------------------------------------------------+
| Revision 1.0 | 2009-May-20 | Initial public release |
+------------------------------------------------------------+
Cisco Security Procedures
=========================
Complete information on reporting security vulnerabilities in
Cisco products, obtaining assistance with security incidents, and
registering to receive security information from Cisco, is available
on Cisco's worldwide website at
http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html.
This includes instructions for press inquiries regarding Cisco security
notices. All Cisco security advisories are available at
http://www.cisco.com/go/psirt.
+--------------------------------------------------------------------
Copyright 2008-2009 Cisco Systems, Inc. All rights reserved.
+--------------------------------------------------------------------
Updated: May 20, 2009 Document ID: 110143
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAkoUF9wACgkQ86n/Gc8U/uD6vwCfR19hcS8fBuvDrshKYSc9zbsM
Yp8AoJj60tLS7dMKkYcRcgJLreh3dl8A
=yjnP
-----END PGP SIGNATURE-----
. ----------------------------------------------------------------------
Are you missing:
SECUNIA ADVISORY ID:
Critical:
Impact:
Where:
within the advisory below?
This is now part of the Secunia commercial solutions.
Click here to learn more about our commercial solutions:
http://secunia.com/advisories/business_solutions/
Click here to trial our solutions:
http://secunia.com/advisories/try_vi/
----------------------------------------------------------------------
TITLE:
CiscoWorks TFTP Directory Traversal Vulnerability
SECUNIA ADVISORY ID:
SA35179
VERIFY ADVISORY:
http://secunia.com/advisories/35179/
DESCRIPTION:
A vulnerability has been reported in various Cisco products, which
can be exploited by malicious people to disclose sensitive
information or compromise a vulnerable system.
http://www.cisco.com/pcgi-bin/tablebuild.pl/cw2000-cd-one
PROVIDED AND/OR DISCOVERED BY:
Reported to the vendor by a customer.
ORIGINAL ADVISORY:
http://www.cisco.com/warp/public/707/cisco-sa-20090520-cw.shtml
http://www.cisco.com/warp/public/707/cisco-amb-20090520-cw.shtml
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor
VAR-201005-0205 | CVE-2010-2032 | Caucho Technology Resin Professional of resin-admin/digest.php Vulnerable to cross-site scripting |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) digest_realm or (2) digest_username parameters. NOTE: some of these details are obtained from third party information. Resin is a web server developed by Caucho Technology. The input to the \"digest_username\" and \"digest_realm\" parameters passed to the resin-admin/digest.php script lacks sufficient filtering before returning to the user, and the attacker can execute arbitrary HTML and script code on the target user's browser. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Resin Professional 3.1.5 is affected; other versions may also be affected. ----------------------------------------------------------------------
Stay Compliant
Alerts, Technical Descriptions, PoC, Links to patches, CVSS, CVE, Changelogs, Alternative Remediation Strategies, and much more provided in the Secunia Vulnerability Intelligence solutions
Free Trial
http://secunia.com/products/corporate/evm/trial/
----------------------------------------------------------------------
TITLE:
Caucho Resin Two Cross-Site Scripting Vulnerabilities
SECUNIA ADVISORY ID:
SA39839
VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/39839/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=39839
RELEASE DATE:
2010-05-21
DISCUSS ADVISORY:
http://secunia.com/advisories/39839/#comments
AVAILABLE ON SITE AND IN CUSTOMER AREA:
* Last Update
* Popularity
* Comments
* Criticality Level
* Impact
* Where
* Solution Status
* Operating System / Software
* CVE Reference(s)
http://secunia.com/advisories/39839/
ONLY AVAILABLE IN CUSTOMER AREA:
* Authentication Level
* Report Reliability
* Secunia PoC
* Secunia Analysis
* Systems Affected
* Approve Distribution
* Remediation Status
* Secunia CVSS Score
* CVSS
https://ca.secunia.com/?page=viewadvisory&vuln_id=39839
ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI:
* AUTOMATED SCANNING
http://secunia.com/vulnerability_scanning/personal/
http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/
DESCRIPTION:
Two vulnerabilities have been discovered in Caucho Resin, which can
be exploited by malicious people to conduct cross-site scripting
attacks.
Input passed to the "digest_username" and "digest_realm" parameters
in resin-admin/digest.php is not properly sanitised before being
returned to the user.
The vulnerabilities are confirmed in version 3.1.10 and 4.0.6.
SOLUTION:
Edit the source code to ensure that input is properly sanitised.
PROVIDED AND/OR DISCOVERED BY:
flyh4t
ORIGINAL ADVISORY:
http://packetstormsecurity.org/1005-exploits/cauchoresin312-xss.txt
OTHER REFERENCES:
Further details available in Customer Area:
http://secunia.com/products/corporate/EVM/
DEEP LINKS:
Further details available in Customer Area:
http://secunia.com/products/corporate/EVM/
EXTENDED DESCRIPTION:
Further details available in Customer Area:
http://secunia.com/products/corporate/EVM/
EXTENDED SOLUTION:
Further details available in Customer Area:
http://secunia.com/products/corporate/EVM/
EXPLOIT:
Further details available in Customer Area:
http://secunia.com/products/corporate/EVM/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
VAR-200905-0313 | CVE-2009-1740 | csviewer.ocx Heap-based buffer overflow vulnerability |
CVSS V2: 9.3 CVSS V3: - Severity: HIGH |
Multiple heap-based buffer overflows in the D-Link MPEG4 Viewer ActiveX Control (csviewer.ocx) 2.11.918.2006 allow remote attackers to execute arbitrary code via a long argument to the (1) SetFilePath and (2) SetClientCookie methods. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Failed exploit attempts likely result in denial-of-service conditions.
MPEG4 Viewer 2.11.918.2006 is vulnerable; other versions may also be affected. D-Link MPEG4 Viewer is an ActiveX control installed on the D-Link webcam client. The D-Link MPEG4 Viewer ActiveX control did not properly validate input passed to the SetFilePath() and SetClientCookie() methods. If a user is tricked into visiting a malicious webpage and sends a super-long input parameter to the above method, a heap overflow can be triggered, resulting in the execution of arbitrary instructions. ----------------------------------------------------------------------
Are you missing:
SECUNIA ADVISORY ID:
Critical:
Impact:
Where:
within the advisory below?
This is now part of the Secunia commercial solutions.
The vulnerabilities are confirmed in version 2.11.918.2006.
SOLUTION:
Set the kill-bit for the affected ActiveX control.
PROVIDED AND/OR DISCOVERED BY:
0x29A
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
VAR-201906-0002 | CVE-2009-5157 | Linksys WAG54G2 Command injection vulnerability in devices |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable. Linksys WAG54G2 The device contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. The Linksys WAG54G2 is an ADSL all-in-one with integrated modem and router. The Linksys WAG54G2 router provides a management console that is accessible only to LAN users by default. Since the special characters such as \";\", \"&\", \"|\", \"``\", \"%a0\" in the user request are not correctly filtered, the user can inject and execute the malicious request after logging in to the console. Any shell command. If the user does not change the default management password, the external network user can also exploit the vulnerability remotely by using the cross-site request forgery attack. Linksys WAG54G2 router is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary shell commands with superuser privileges. This may facilitate a complete compromise of the affected device.
Linksys WAG54G2 with firmware V1.00.10 is affected; other versions may also be vulnerable.
UPDATE (May 29, 2009): The reporter indicates that this issue may not be remotely exploitable if the administrator credentials have been changed from the default values
VAR-200905-0370 | No CVE | D-Link MPEG4 Viewer ActiveX Control Multiple Heap Overflow Vulnerabilities |
CVSS V2: - CVSS V3: - Severity: - |
D-Link MPEG4 Viewer is an ActiveX control installed on the D-Link webcam client.
The D-Link MPEG4 Viewer ActiveX control does not correctly validate the input passed to the SetFilePath () and SetClientCookie () methods. If a user is tricked into visiting a malicious webpage and transmitting long input parameters to the above method, a heap overflow can be triggered, causing arbitrary instructions to be executed.
VAR-200906-0272 | CVE-2009-1535 | Microsoft IIS WebDAV Remote Authentication Bypass |
CVSS V2: 7.5 CVSS V3: - Severity: HIGH |
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder, aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122. Microsoft Internet Information Service (IIS) is prone to multiple authentication-bypass vulnerabilities because the application fails to properly enforce access restrictions on certain requests to password-protected WebDAV folders.
An attacker can exploit these issues to gain unauthorized access to protected WebDAV resources, which may lead to other attacks.
This issue affects IIS 5.0, 5.1, and 6.0.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
National Cyber Alert System
Technical Cyber Security Alert TA09-160A
Microsoft Updates for Multiple Vulnerabilities
Original release date: June 09, 2009
Last revised: --
Source: US-CERT
Systems Affected
* Microsoft Windows
* Microsoft Office
* Microsoft Internet Explorer
Overview
Microsoft has released updates that address vulnerabilities in
Microsoft Windows, Office, and Internet Explorer.
I. Description
As part of the Microsoft Security Bulletin Summary for June 2009,
Microsoft released updates to address vulnerabilities that affect
Microsoft Windows, Office, and Internet Explorer.
II. Impact
A remote, unauthenticated attacker could execute arbitrary code,
gain elevated privileges, or cause a vulnerable application to
crash.
III. Solution
Microsoft has provided updates for these vulnerabilities in the
Microsoft Security Bulletin Summary for June 2009. The security
bulletin describes any known issues related to the updates.
Administrators are encouraged to note these issues and test for any
potentially adverse effects. Administrators should consider using
an automated update distribution system such as Windows Server
Update Services (WSUS).
IV. References
* Microsoft Security Bulletin Summary for June 2009 -
<http://www.microsoft.com/technet/security/bulletin/ms09-jun.mspx>
* Microsoft Windows Server Update Services -
<http://technet.microsoft.com/en-us/wsus/default.aspx>
* US-CERT Vulnerability Notes for Microsoft June 2009 updates -
<http://www.kb.cert.org/vuls/byid?searchview&query=ms09-jun>
____________________________________________________________________
The most recent version of this document can be found at:
<http://www.us-cert.gov/cas/techalerts/TA09-160A.html>
____________________________________________________________________
Feedback can be directed to US-CERT Technical Staff. Please send
email to <cert@cert.org> with "TA09-160A Feedback VU#983731" in
the subject.
____________________________________________________________________
For instructions on subscribing to or unsubscribing from this
mailing list, visit <http://www.us-cert.gov/cas/signup.html>.
____________________________________________________________________
Produced 2009 by US-CERT, a government organization.
Terms of use:
<http://www.us-cert.gov/legal.html>
____________________________________________________________________
Revision History
June 09, 2009: Initial release
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
iQEVAwUBSi7EY3IHljM+H4irAQKpUwgAqcYG1SVf4dPt7wevUx9UIKyw/RWG/wCI
+ns9UEmk4Pbdu8Tj+snDsNxxOnvdUGnWzfbuBFrzexr+u3zY0BgvBQ50eaYnYyVn
Iv9yxxxKfdvQEQIiPi/5gWl05k4axYdSjEYLZqNkQIj1VvqJOhCWaHKPsJZykdZq
ZZLd8aFxxM7fj0RrKeorXGiApw45kP9a133EN7NRf8CvYsNKnUTMYVPC2bTaq0Jb
HCjjEOwBWaP6YjqQ1laVslCHzOVpFzQnkl+IKBsoDAu1397KjwobIR340YyW6K4g
ckdod5TwdG77KOcNZHAp+uQMffGOaCfqj/MFk7qEYxN7/0gJXuB8mQ==
=9e4w
-----END PGP SIGNATURE-----
. ----------------------------------------------------------------------
Are you missing:
SECUNIA ADVISORY ID:
Critical:
Impact:
Where:
within the advisory below?
This is now part of the Secunia commercial solutions.
The vulnerability is caused due to an error when handling WebDAV
requests for directories requiring authentication. This can be
exploited to bypass access restrictions and e.g. download files from
protected folders by issuing an HTTP GET request containing Unicode
characters and a "Translate: f" HTTP header.
Successful exploitation may allow uploading arbitrary files to
protected WebDAV folders.
The vulnerability is confirmed in Microsoft IIS 5.1 on a fully
patched Windows XP SP3 and reported in version 6.0. Other versions
may also be affected.
SOLUTION:
Do not store sensitive files inside the webroot. Disable WebDAV
support.
PROVIDED AND/OR DISCOVERED BY:
Nikolaos Rangos (Kingcope)
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------