VARIoT IoT vulnerabilities database
| VAR-202301-1403 | CVE-2023-0126 | SMA1000 Path traversal vulnerability in firmware |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory. SMA1000 A path traversal vulnerability exists in firmware.Information may be obtained
| VAR-202301-1432 | CVE-2022-34399 | Dell Alienware m17 R5 BIOS Buffer error vulnerability in |
CVSS V2: 1.4 CVSS V3: 2.3 Severity: LOW |
Dell Alienware m17 R5 BIOS version prior to 1.2.2 contain a buffer access vulnerability. A malicious user with admin privileges could potentially exploit this vulnerability by sending input larger than expected in order to leak certain sections of SMRAM. Dell Alienware is a line of gaming laptops from the American company Dell. An attacker exploits this vulnerability to send content larger than the specified input length to obtain sensitive information in SMRAM
| VAR-202301-1474 | CVE-2022-48191 | Trend Micro antivirus Multiple vulnerabilities in the cloud |
CVSS V2: - CVSS V3: 7.0 Severity: HIGH |
A vulnerability exists in Trend Micro Maximum Security 2022 (17.7) wherein a low-privileged user can write a known malicious executable to a specific location and in the process of removal and restoral an attacker could replace an original folder with a mount point to an arbitrary location, allowing a escalation of privileges on an affected system. Virus Buster from Trend Micro Inc. An update for the cloud has been released. This vulnerability information is provided by the developer for the purpose of dissemination to product users. JPCERT/CC Report to JPCERT/CC Coordinated with the developer.The potential impact will vary for each vulnerability, but you may be impacted by: Please refer to the respective advisory provided by the developer for details. Cloud version 17.7 It was * Arbitrary file deletion due to link interpretation problem when accessing file in data erasure tool - CVE-2022-30687 It was * Privilege escalation due to link interpretation problems when accessing files - CVE-2022-34893 It was * Information Disclosure via Out-of-Bounds Read Vulnerability - CVE-2022-35234 , CVE-2022-37347 , CVE-2022-37348 It was * Time-of-check Time-of-use (( TOCTOU ) Privilege escalation due to race condition vulnerability - CVE-2022-48191 virus buster Cloud version 17.0 It was * Information Disclosure via Out-of-Bounds Read Vulnerability - CVE-2022-35234 , CVE-2022-37347 , CVE-2022-37348. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.The specific flaw exists within the Damage Cleanup Engine. The issue results from the lack of proper locking when performing file operations. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM
| VAR-202301-1377 | CVE-2022-43648 | D-Link Systems, Inc. of DIR-3040 Heap-based buffer overflow vulnerability in firmware |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 1.20B03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MiniDLNA service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the MiniDLNA service. Was ZDI-CAN-19910. D-Link Systems, Inc. of DIR-3040 A heap-based buffer overflow vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-3040 is a router of D-Link company in China. Provides the ability to connect to the network
| VAR-202301-1435 | CVE-2022-34442 | Dell EMC SCG Policy Manager Vulnerability in using hard-coded credentials in |
CVSS V2: - CVSS V3: 8.0 Severity: HIGH |
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP user privileges. (DoS) It may be in a state
| VAR-202301-1547 | CVE-2022-34456 | Dell EMC Metro node Code injection vulnerability in |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application. (DoS) It may be in a state
| VAR-202301-1298 | CVE-2022-46732 | Proficy Historian Authentication Bypass Vulnerability Using Alternate Paths or Channels in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status. Proficy Historian contains an authentication bypass vulnerability using alternate paths or channels.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202301-1301 | CVE-2022-46331 | Proficy Historian access control vulnerabilities in |
CVSS V2: - CVSS V3: 8.1 Severity: HIGH |
An unauthorized user could possibly delete any file on the system. Proficy Historian contains an access control vulnerability.Information is tampered with and service operation is interrupted (DoS) It may be in a state
| VAR-202301-1299 | CVE-2022-43494 | Proficy Historian access control vulnerabilities in |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
An unauthorized user could be able to read any file on the system, potentially exposing sensitive information. Proficy Historian contains an access control vulnerability.Information may be obtained
| VAR-202301-1300 | CVE-2022-46660 | Proficy Historian Vulnerability in unlimited upload of dangerous types of files in |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
An unauthorized user could alter or write files with full control over the path and content of the file. Proficy Historian Contains a vulnerability related to unlimited uploads of dangerous types of files.Information may be tampered with
| VAR-202301-1297 | CVE-2022-38469 | Proficy Historian Cryptographic strength vulnerabilities in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords. Proficy Historian There is a security level vulnerability in.Information may be obtained
| VAR-202301-1540 | CVE-2022-34462 | Dell EMC SCG Policy Manager Vulnerability in using hard-coded credentials in |
CVSS V2: - CVSS V3: 8.4 Severity: HIGH |
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to gain admin privileges. (DoS) It may be in a state
| VAR-202301-1585 | CVE-2022-34457 | Dell command configuration Vulnerability in leaking resources to the wrong area in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users. Dell command configuration Exists in a vulnerability related to the leakage of resources to the wrong area.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202301-1433 | CVE-2022-32490 | plural Dell BIOS Product input verification vulnerabilities |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. Dell Edge Gateway 3000 firmware, Dell Edge Gateway 5000 firmware, Embedded Box PC 3000 There is an input validation vulnerability in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202301-1478 | CVE-2023-0214 | Skyhigh SWG Cross-site scripting vulnerability in |
CVSS V2: - CVSS V3: 6.1 Severity: MEDIUM |
A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to 12.0.1 allows a remote attacker to craft SWG-specific internal requests with URL paths to any third-party website, causing arbitrary content to be injected into the response when accessed through SWG. Skyhigh SWG Exists in a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
| VAR-202301-1362 | CVE-2022-46475 | D-Link DIR 645A1 Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
D-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main function. D-Link DIR 645A1 Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202301-1554 | CVE-2022-47853 | TOTOlink A7100RU Command injection vulnerability in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a stable root shell through a specially constructed payload. TOTOlink A7100RU Contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202301-1360 | CVE-2023-21888 | Oracle Construction and Engineering of Primavera Gateway In WebUI Vulnerability |
CVSS V2: - CVSS V3: 5.4 Severity: MEDIUM |
Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: WebUI). Supported versions that are affected are 18.8.0-18.8.15, 19.12.0-19.12.15, 20.12.0-20.12.10 and 21.12.0-21.12.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Gateway. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Gateway, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Gateway accessible data as well as unauthorized read access to a subset of Primavera Gateway accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
| VAR-202301-1527 | CVE-2006-20001 | Apache HTTP Server 2 memory read vulnerability in |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.
This issue affects Apache HTTP Server 2.4.54 and earlier. The server is fast, reliable and scalable via a simple API. ==========================================================================
Ubuntu Security Notice USN-5839-1
February 01, 2023
apache2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in Apache HTTP Server. A remote attacker could
possibly use this issue to perform an HTTP Request Smuggling attack.
(CVE-2022-36760)
Dimas Fariski Setyawan Putra discovered that the Apache HTTP Server
mod_proxy module incorrectly truncated certain response headers. This may
result in later headers not being interpreted by the client.
(CVE-2022-37436)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.10:
apache2 2.4.54-2ubuntu1.1
Ubuntu 22.04 LTS:
apache2 2.4.52-1ubuntu4.3
Ubuntu 20.04 LTS:
apache2 2.4.41-4ubuntu3.13
Ubuntu 18.04 LTS:
apache2 2.4.29-1ubuntu4.26
In general, a standard system update will make all the necessary changes. (BZ#2165975)
4. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: httpd:2.4 security and bug fix update
Advisory ID: RHSA-2023:0852-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2023:0852
Issue date: 2023-02-21
CVE Names: CVE-2006-20001 CVE-2022-36760 CVE-2022-37436
====================================================================
1. Summary:
An update for the httpd:2.4 module is now available for Red Hat Enterprise
Linux 8.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64
3.
Security Fix(es):
* httpd: mod_dav: out-of-bounds read/write of zero byte (CVE-2006-20001)
* httpd: mod_proxy_ajp: Possible request smuggling (CVE-2022-36760)
* httpd: mod_proxy: HTTP response splitting (CVE-2022-37436)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Bug Fix(es):
* httpd-init fails to create localhost.crt, localhost.key due to "sscg"
default now creates a /dhparams.pem and is not idempotent if the file
/dhparams.pem already exists. (BZ#2165967)
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the updated packages, the httpd daemon will be restarted
automatically.
5. Bugs fixed (https://bugzilla.redhat.com/):
2161773 - CVE-2022-37436 httpd: mod_proxy: HTTP response splitting
2161774 - CVE-2006-20001 httpd: mod_dav: out-of-bounds read/write of zero byte
2161777 - CVE-2022-36760 httpd: mod_proxy_ajp: Possible request smuggling
2165967 - httpd-init fails to create localhost.crt, localhost.key due to "sscg" default now creates a /dhparams.pem and is not idempotent if the file /dhparams.pem already exists. [rhel-8.7.0.z]
6. Package List:
Red Hat Enterprise Linux AppStream (v. 8):
Source:
httpd-2.4.37-51.module+el8.7.0+18026+7b169787.1.src.rpm
mod_http2-1.15.7-5.module+el8.6.0+13996+01710940.src.rpm
mod_md-2.0.8-8.module+el8.3.0+6814+67d1e611.src.rpm
aarch64:
httpd-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
httpd-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
httpd-debugsource-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
httpd-devel-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
httpd-tools-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
httpd-tools-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
mod_http2-1.15.7-5.module+el8.6.0+13996+01710940.aarch64.rpm
mod_http2-debuginfo-1.15.7-5.module+el8.6.0+13996+01710940.aarch64.rpm
mod_http2-debugsource-1.15.7-5.module+el8.6.0+13996+01710940.aarch64.rpm
mod_ldap-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
mod_ldap-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
mod_md-2.0.8-8.module+el8.3.0+6814+67d1e611.aarch64.rpm
mod_md-debuginfo-2.0.8-8.module+el8.3.0+6814+67d1e611.aarch64.rpm
mod_md-debugsource-2.0.8-8.module+el8.3.0+6814+67d1e611.aarch64.rpm
mod_proxy_html-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
mod_proxy_html-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
mod_session-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
mod_session-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
mod_ssl-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
mod_ssl-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.aarch64.rpm
noarch:
httpd-filesystem-2.4.37-51.module+el8.7.0+18026+7b169787.1.noarch.rpm
httpd-manual-2.4.37-51.module+el8.7.0+18026+7b169787.1.noarch.rpm
ppc64le:
httpd-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
httpd-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
httpd-debugsource-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
httpd-devel-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
httpd-tools-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
httpd-tools-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
mod_http2-1.15.7-5.module+el8.6.0+13996+01710940.ppc64le.rpm
mod_http2-debuginfo-1.15.7-5.module+el8.6.0+13996+01710940.ppc64le.rpm
mod_http2-debugsource-1.15.7-5.module+el8.6.0+13996+01710940.ppc64le.rpm
mod_ldap-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
mod_ldap-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
mod_md-2.0.8-8.module+el8.3.0+6814+67d1e611.ppc64le.rpm
mod_md-debuginfo-2.0.8-8.module+el8.3.0+6814+67d1e611.ppc64le.rpm
mod_md-debugsource-2.0.8-8.module+el8.3.0+6814+67d1e611.ppc64le.rpm
mod_proxy_html-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
mod_proxy_html-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
mod_session-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
mod_session-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
mod_ssl-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
mod_ssl-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.ppc64le.rpm
s390x:
httpd-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
httpd-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
httpd-debugsource-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
httpd-devel-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
httpd-tools-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
httpd-tools-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
mod_http2-1.15.7-5.module+el8.6.0+13996+01710940.s390x.rpm
mod_http2-debuginfo-1.15.7-5.module+el8.6.0+13996+01710940.s390x.rpm
mod_http2-debugsource-1.15.7-5.module+el8.6.0+13996+01710940.s390x.rpm
mod_ldap-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
mod_ldap-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
mod_md-2.0.8-8.module+el8.3.0+6814+67d1e611.s390x.rpm
mod_md-debuginfo-2.0.8-8.module+el8.3.0+6814+67d1e611.s390x.rpm
mod_md-debugsource-2.0.8-8.module+el8.3.0+6814+67d1e611.s390x.rpm
mod_proxy_html-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
mod_proxy_html-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
mod_session-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
mod_session-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
mod_ssl-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
mod_ssl-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.s390x.rpm
x86_64:
httpd-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
httpd-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
httpd-debugsource-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
httpd-devel-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
httpd-tools-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
httpd-tools-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
mod_http2-1.15.7-5.module+el8.6.0+13996+01710940.x86_64.rpm
mod_http2-debuginfo-1.15.7-5.module+el8.6.0+13996+01710940.x86_64.rpm
mod_http2-debugsource-1.15.7-5.module+el8.6.0+13996+01710940.x86_64.rpm
mod_ldap-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
mod_ldap-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
mod_md-2.0.8-8.module+el8.3.0+6814+67d1e611.x86_64.rpm
mod_md-debuginfo-2.0.8-8.module+el8.3.0+6814+67d1e611.x86_64.rpm
mod_md-debugsource-2.0.8-8.module+el8.3.0+6814+67d1e611.x86_64.rpm
mod_proxy_html-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
mod_proxy_html-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
mod_session-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
mod_session-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
mod_ssl-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
mod_ssl-debuginfo-2.4.37-51.module+el8.7.0+18026+7b169787.1.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2006-20001
https://access.redhat.com/security/cve/CVE-2022-36760
https://access.redhat.com/security/cve/CVE-2022-37436
https://access.redhat.com/security/updates/classification/#moderate
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBY/S5HdzjgjWX9erEAQh4bRAAkF3EgQgukNt/nGFBeSNly7ekQ6MZzwx6
/g701Jznu0z/XZM4+lhWIB6Au8sDwHyzp9tL3Mmwb1vSDkJfYMEBNpx22Ku4yr78
AqvAtMbtr3ZRtzlCow12ARhcsoV3mxCNvEs8Gw9ZK7VlJy0bq771jpau14tgZHvU
cy3IOQgBUbACHoaJ+C4fpSFtd4ewKuYV9VDQrW08ZhYejF32U/0jFeWKPPAv2VFU
gr9EazXKwQp4QF2d/dMOpmuERQNqRWRYKT7SdWykvCIpOjB1NeJ/iTKBK4hZnm3A
malqCf3hnWl/6v+ZFRlb62G1UPzVH3xGfNrkBgN96ktGhJ/i7GYKn04zWioP/0mv
pp5TsME6BT4J7ykw1SCZRDecFBHXyFKA8E08nXG+/aS9CDiHyUfP2mWyo7wx228Y
xUvZYJQA165zaxSC7PG0W52CGeVYhUnBaa1xZKbG00YE+U+eN7KsHnbv+J7VjSnT
F2Qm/z4OW1dFZU462VK2XVydYFPBoMormkeHFfOo3N92DdKduOU9rXcL9n++Y8dn
3tpuinfUc82EXeFm79HkVPaKz2R7/sm+dsylaC5QUkJqcbTahAYF2JgrkyfSWA9/
iY86qqDT17rd84adrQfXojb5hc4AKqVMJZuRJv5OGsj7SH/qiCGbYAtUDLf4C31G
sw6Iqa1wZ18=EViL
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202309-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Low
Title: Apache HTTPD: Multiple Vulnerabilities
Date: September 08, 2023
Bugs: #891211, #900416
ID: 202309-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities have been discovered in Apache HTTPD, the worst
of which could result in denial of service. Please
review the CVE identifiers referenced below for details.
Impact
======
Please review the referenced CVE identifiers for details.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All Apache HTTPD users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-servers/apache-2.4.56"
References
==========
[ 1 ] CVE-2006-20001
https://nvd.nist.gov/vuln/detail/CVE-2006-20001
[ 2 ] CVE-2022-36760
https://nvd.nist.gov/vuln/detail/CVE-2022-36760
[ 3 ] CVE-2022-37436
https://nvd.nist.gov/vuln/detail/CVE-2022-37436
[ 4 ] CVE-2023-25690
https://nvd.nist.gov/vuln/detail/CVE-2023-25690
[ 5 ] CVE-2023-27522
https://nvd.nist.gov/vuln/detail/CVE-2023-27522
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202309-01
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2023 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
.
For the stable distribution (bullseye), these problems have been fixed in
version 2.4.56-1~deb11u1.
We recommend that you upgrade your apache2 packages.
For the detailed security status of apache2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/apache2
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmQYqdQACgkQEMKTtsN8
TjYWeQ//dwKUtLc9oKmjEmiY1QsRsSYdlzMTWA8ow63vdtGD1QU3Xb/CxPSZ22Oh
8zypNP5qtk3m11JA7npd7RNPpF3Gb1V5ebIlKP7GavGBIrGOmvH31hV3IUP4HoXO
/mC36BA3twAgyF12HMtdPvj+qaNguYnxXhc02Kt7kl6sq+ybtdCnRnBfJJ2KYXKq
tjRedc+HJZa0gSuq9fsFbaQF1OPk1jHEO/ixHhISKhEr1mHO+eLN3soQ9gqaEG/a
/0jLUm1ThiBNeK5jkmCXuIuqwwrGHG16Cl9fIKGps1Yb+ef2aJca7onA4IfyUj1d
1S7VmCgFFQe+5eAgdcR77mWS8RyEP/lyItY+ifzGG6xR0EUnDgD7ApcqhZBIJCgU
583Dle+sjvwgb9iSSeNwynqx58Pf4648AJSx6nNlsop4ekE4To5GvKyr/eI3HNqa
t9BfVtwqRu4GnnurvJFzh5n2wpRl1JbQMFMx/kxb1He5ioayRtru9guViNA3ylgn
d7lbk8FEsvvzS9MM0RVivlWdzD6+FVFHaWoCcwzv+0dFD6iiG5MJMGUr0pElw+ju
As6bnKCCoEHU4HK0rKHlVeB6E3Ch7yF+b6PvzZqCqcOE6RB5/I2Nu9S3L78cZWRU
nKXf/WHf3Lw+DCB8QKWUBuo0WjkFjmEe/oUCWHGt/UbtXGbSM+E=Bi/w
-----END PGP SIGNATURE-----
. This software, such as Apache HTTP Server, is
common to multiple JBoss middleware products, and is packaged under Red Hat
JBoss Core Services to allow for faster distribution of updates, and for a
more consistent update experience.
This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.51
Service Pack 2 serves as a replacement for Red Hat JBoss Core Services
Apache HTTP Server 2.4.51 Service Pack 1, and includes bug fixes and
enhancements, which are documented in the Release Notes document linked to
in the References. Bugs fixed (https://bugzilla.redhat.com/):
2152639 - CVE-2022-43551 curl: HSTS bypass via IDN
2152652 - CVE-2022-43552 curl: Use-after-free triggered by an HTTP proxy deny response
2161774 - CVE-2006-20001 httpd: mod_dav: out-of-bounds read/write of zero byte
2164440 - CVE-2023-0286 openssl: X.400 address type confusion in X.509 GeneralName
2164487 - CVE-2022-4304 openssl: timing attack in RSA Decryption implementation
2164492 - CVE-2023-0215 openssl: use-after-free following BIO_new_NDEF
2164494 - CVE-2022-4450 openssl: double free after calling PEM_read_bio_ex
2167797 - CVE-2023-23914 curl: HSTS ignored on multiple requests
2167813 - CVE-2023-23915 curl: HSTS amnesia with --parallel
2167815 - CVE-2023-23916 curl: HTTP multi-header compression denial of service
2169652 - CVE-2022-25147 apr-util: out-of-bounds writes in the apr_base64
2176209 - CVE-2023-25690 httpd: HTTP request splitting with mod_rewrite and mod_proxy
6. Solution:
Before applying this update, make sure all previously released errata
relevant to your system have been applied
| VAR-202301-1278 | CVE-2022-4431 | WOOCS WordPress Cross-site scripting vulnerability in plugins |
CVSS V2: - CVSS V3: 5.4 Severity: MEDIUM |
The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. WOOCS WordPress A cross-site scripting vulnerability exists in the plugin.Information may be obtained and information may be tampered with