VARIoT IoT vulnerabilities database
| VAR-202103-1735 | No CVE | Tenda AC9 has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Tenda AC9 is a wireless router product.
Tenda AC9 has a denial of service vulnerability. An attacker can use this vulnerability to cause a denial of service.
| VAR-202103-1736 | No CVE | Samsung WLAN AP has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Samsung (China) Investment Co., Ltd. is the headquarters of Samsung Group in China. As of the end of 2008, 20 of Samsung's more than 30 companies have invested in China, including Samsung Electronics, Samsung SDI, Samsung SDS, and Samsung Electro-Mechanics.
Samsung WLAN AP has a weak password vulnerability. Attackers can use this vulnerability to log in to the router backend to obtain sensitive information.
| VAR-202103-0241 | CVE-2020-29020 | Secomea SiteManager Authentication Vulnerability in Microsoft |
CVSS V2: 6.5 CVSS V3: 7.2 Severity: HIGH |
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.620527004 on Hardware. Secomea SiteManager Contains an improper authentication vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
| VAR-202103-0244 | CVE-2020-29030 | Secomea GateManager Cross Site Request Forgery Vulnerability |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. This issue affects: Secomea GateManager All versions prior to 9.4. Secomea GateManager Contains a cross-site request forgery vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Secomea GateManager is a remote access server product of Denmark Secomea Company
| VAR-202103-0243 | CVE-2020-29029 | Secomea GateManager Cross-site Scripting Vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4. Secomea GateManager Contains a cross-site scripting vulnerability.Information may be obtained and information may be tampered with. Secomea GateManager is a remote access server product of Denmark Secomea Company. The vulnerability stems from incorrect input validation
| VAR-202103-0242 | CVE-2020-29028 | Secomea GateManager Cross-site Scripting Vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
Cross-site Scripting (XSS) vulnerability in web GUI of Secomea GateManager allows an attacker to inject arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4. Secomea GateManager Contains a cross-site scripting vulnerability.Information may be obtained and information may be tampered with. Secomea GateManager is a remote access server product of Denmark Secomea Company
| VAR-202103-1030 | CVE-2021-28039 | Xen Used in Linux Kernel Resource Depletion Vulnerability |
CVSS V2: 2.1 CVSS V3: 6.5 Severity: MEDIUM |
An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical addresses when a configuration has CONFIG_XEN_UNPOPULATED_ALLOC but not CONFIG_XEN_BALLOON_MEMORY_HOTPLUG. Linux kernel 5.9.x through 5.11.3 contains a security vulnerability that could be exploited by an attacker to cause the driver to crash
| VAR-202103-1029 | CVE-2021-28038 | Xen PV Used in Linux Kernel Vulnerability in resource allocation without restrictions or throttling in |
CVSS V2: 4.9 CVSS V3: 6.5 Severity: MEDIUM |
An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of service may occur during misbehavior of a networking frontend driver. NOTE: this issue exists because of an incomplete fix for CVE-2021-26931. This update provides the corresponding
Linux kernel updates targeted specifically for Raspberry Pi devices
in those same Ubuntu Releases. ==========================================================================
Ubuntu Security Notice USN-4984-1
June 04, 2021
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.8, linux-kvm,
linux-oracle vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.10
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in the Linux kernel. An
attacker in a guest VM could possibly use this to cause a denial of service
(host domain crash). (CVE-2021-28038)
It was discovered that the Realtek RTL8188EU Wireless device driver in the
Linux kernel did not properly validate ssid lengths in some situations. An
attacker could use this to cause a denial of service (system crash). A local
attacker could use this to cause a denial of service (memory exhaustion).
(CVE-2021-28688)
It was discovered that the fuse user space file system implementation in
the Linux kernel did not properly handle bad inodes in some situations. A
local attacker could possibly use this to cause a denial of service.
(CVE-2021-28950)
John Stultz discovered that the audio driver for Qualcomm SDM845 systems in
the Linux kernel did not properly validate port ID numbers. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2021-28952)
Zygo Blaxell discovered that the btrfs file system implementation in the
Linux kernel contained a race condition during certain cloning operations.
A local attacker could possibly use this to cause a denial of service
(system crash). (CVE-2021-28964)
Vince Weaver discovered that the perf subsystem in the Linux kernel did not
properly handle certain PEBS records properly for some Intel Haswell
processors. A local attacker could use this to cause a denial of service
(system crash). (CVE-2021-28971)
It was discovered that the RPA PCI Hotplug driver implementation in the
Linux kernel did not properly handle device name writes via sysfs, leading
to a buffer overflow. A privileged attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2021-28972)
It was discovered that the Qualcomm IPC router implementation in the Linux
kernel did not properly initialize memory passed to user space. A local
attacker could use this to expose sensitive information (kernel memory). A local attacker
could use this to cause a denial of service (memory exhaustion).
(CVE-2021-30002)
Dan Carpenter discovered that the block device manager (dm) implementation
in the Linux kernel contained a buffer overflow in the ioctl for listing
devices. A privileged local attacker could use this to cause a denial of
service (system crash). (CVE-2021-31916)
It was discovered that the CIPSO implementation in the Linux kernel did not
properly perform reference counting in some situations, leading to use-
after-free vulnerabilities. An attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2021-33033)
马哲宇 discovered that the IEEE 1394 (Firewire) nosy packet sniffer driver in
the Linux kernel did not properly perform reference counting in some
situations, leading to a use-after-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2021-3483)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.10:
linux-image-5.8.0-1028-kvm 5.8.0-1028.30
linux-image-5.8.0-1031-oracle 5.8.0-1031.32
linux-image-5.8.0-1032-gcp 5.8.0-1032.34
linux-image-5.8.0-1033-azure 5.8.0-1033.35
linux-image-5.8.0-1035-aws 5.8.0-1035.37
linux-image-5.8.0-55-generic 5.8.0-55.62
linux-image-5.8.0-55-generic-64k 5.8.0-55.62
linux-image-5.8.0-55-generic-lpae 5.8.0-55.62
linux-image-5.8.0-55-lowlatency 5.8.0-55.62
linux-image-aws 5.8.0.1035.37
linux-image-azure 5.8.0.1033.33
linux-image-gcp 5.8.0.1032.32
linux-image-generic 5.8.0.55.60
linux-image-generic-64k 5.8.0.55.60
linux-image-generic-lpae 5.8.0.55.60
linux-image-gke 5.8.0.1032.32
linux-image-kvm 5.8.0.1028.30
linux-image-lowlatency 5.8.0.55.60
linux-image-oracle 5.8.0.1031.30
linux-image-virtual 5.8.0.55.60
Ubuntu 20.04 LTS:
linux-image-5.8.0-55-generic 5.8.0-55.62~20.04.1
linux-image-5.8.0-55-generic-64k 5.8.0-55.62~20.04.1
linux-image-5.8.0-55-generic-lpae 5.8.0-55.62~20.04.1
linux-image-5.8.0-55-lowlatency 5.8.0-55.62~20.04.1
linux-image-generic-64k-hwe-20.04 5.8.0.55.62~20.04.39
linux-image-generic-hwe-20.04 5.8.0.55.62~20.04.39
linux-image-generic-lpae-hwe-20.04 5.8.0.55.62~20.04.39
linux-image-lowlatency-hwe-20.04 5.8.0.55.62~20.04.39
linux-image-virtual-hwe-20.04 5.8.0.55.62~20.04.39
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-4984-1
CVE-2021-28038, CVE-2021-28660, CVE-2021-28688, CVE-2021-28950,
CVE-2021-28952, CVE-2021-28964, CVE-2021-28971, CVE-2021-28972,
CVE-2021-29647, CVE-2021-30002, CVE-2021-31916, CVE-2021-33033,
CVE-2021-3483
Package Information:
https://launchpad.net/ubuntu/+source/linux/5.8.0-55.62
https://launchpad.net/ubuntu/+source/linux-aws/5.8.0-1035.37
https://launchpad.net/ubuntu/+source/linux-azure/5.8.0-1033.35
https://launchpad.net/ubuntu/+source/linux-gcp/5.8.0-1032.34
https://launchpad.net/ubuntu/+source/linux-kvm/5.8.0-1028.30
https://launchpad.net/ubuntu/+source/linux-oracle/5.8.0-1031.32
https://launchpad.net/ubuntu/+source/linux-hwe-5.8/5.8.0-55.62~20.04.1
.
(CVE-2017-16644)
It was discovered that the timer stats implementation in the Linux kernel
allowed the discovery of a real PID value while inside a PID namespace. (CVE-2021-20261)
Olivier Benjamin, Norbert Manthey, Martin Mazein, and Jan H
| VAR-202103-0920 | CVE-2021-27363 | Linux kernel Security hole |
CVSS V2: 3.6 CVSS V3: 4.4 Severity: MEDIUM |
An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system, at /sys/class/iscsi_transport/$TRANSPORT_NAME/handle. When read, the show_transport_handle function (in drivers/scsi/scsi_transport_iscsi.c) is called, which leaks the handle. This handle is actually the pointer to an iscsi_transport struct in the kernel module's global variables. =========================================================================
Ubuntu Security Notice USN-4887-1
March 23, 2021
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp,
linux-gcp-5.4, linux-gke-5.3, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4,
linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-kvm, linux-oem-5.10,
linux-oem-5.6, linux-oracle, linux-oracle-5.4, linux-raspi,
linux-raspi-5.4, linux-raspi2-5.3 vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory) or possibly execute arbitrary
code. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2021-27365)
Piotr Krysiuk discovered that the BPF subsystem in the Linux kernel did not
properly compute a speculative execution limit on pointer arithmetic in
some situations. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2020-27171)
Piotr Krysiuk discovered that the BPF subsystem in the Linux kernel did not
properly apply speculative execution limits on some pointer types. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2020-27170)
Adam Nichols discovered that the iSCSI subsystem in the Linux kernel did
not properly restrict access to iSCSI transport handles. A local attacker
could use this to cause a denial of service or expose sensitive information
(kernel pointer addresses). A local attacker could use this to cause a
denial of service (system crash) or expose sensitive information (kernel
memory). (CVE-2021-27364)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.10:
linux-image-5.8.0-1019-raspi 5.8.0-1019.22
linux-image-5.8.0-1019-raspi-nolpae 5.8.0-1019.22
linux-image-5.8.0-1022-kvm 5.8.0-1022.24
linux-image-5.8.0-1024-oracle 5.8.0-1024.25
linux-image-5.8.0-1026-azure 5.8.0-1026.28
linux-image-5.8.0-1026-gcp 5.8.0-1026.27
linux-image-5.8.0-1027-aws 5.8.0-1027.29
linux-image-5.8.0-48-generic 5.8.0-48.54
linux-image-5.8.0-48-generic-64k 5.8.0-48.54
linux-image-5.8.0-48-generic-lpae 5.8.0-48.54
linux-image-5.8.0-48-lowlatency 5.8.0-48.54
linux-image-aws 5.8.0.1027.29
linux-image-azure 5.8.0.1026.26
linux-image-gcp 5.8.0.1026.26
linux-image-generic 5.8.0.48.53
linux-image-generic-64k 5.8.0.48.53
linux-image-generic-lpae 5.8.0.48.53
linux-image-gke 5.8.0.1026.26
linux-image-kvm 5.8.0.1022.24
linux-image-lowlatency 5.8.0.48.53
linux-image-oem-20.04 5.8.0.48.53
linux-image-oracle 5.8.0.1024.23
linux-image-raspi 5.8.0.1019.22
linux-image-raspi-nolpae 5.8.0.1019.22
linux-image-virtual 5.8.0.48.53
Ubuntu 20.04 LTS:
linux-image-5.10.0-1019-oem 5.10.0-1019.20
linux-image-5.4.0-1012-gkeop 5.4.0-1012.13
linux-image-5.4.0-1032-raspi 5.4.0-1032.35
linux-image-5.4.0-1036-kvm 5.4.0-1036.37
linux-image-5.4.0-1040-gcp 5.4.0-1040.43
linux-image-5.4.0-1041-aws 5.4.0-1041.43
linux-image-5.4.0-1041-oracle 5.4.0-1041.44
linux-image-5.4.0-1043-azure 5.4.0-1043.45
linux-image-5.4.0-70-generic 5.4.0-70.78
linux-image-5.4.0-70-generic-lpae 5.4.0-70.78
linux-image-5.4.0-70-lowlatency 5.4.0-70.78
linux-image-5.6.0-1052-oem 5.6.0-1052.56
linux-image-5.8.0-48-generic 5.8.0-48.54~20.04.1
linux-image-5.8.0-48-generic-64k 5.8.0-48.54~20.04.1
linux-image-5.8.0-48-generic-lpae 5.8.0-48.54~20.04.1
linux-image-5.8.0-48-lowlatency 5.8.0-48.54~20.04.1
linux-image-aws 5.4.0.1041.42
linux-image-azure 5.4.0.1043.41
linux-image-gcp 5.4.0.1040.49
linux-image-generic 5.4.0.70.73
linux-image-generic-64k-hwe-20.04 5.8.0.48.54~20.04.32
linux-image-generic-hwe-20.04 5.8.0.48.54~20.04.32
linux-image-generic-lpae 5.4.0.70.73
linux-image-generic-lpae-hwe-20.04 5.8.0.48.54~20.04.32
linux-image-gkeop 5.4.0.1012.15
linux-image-gkeop-5.4 5.4.0.1012.15
linux-image-kvm 5.4.0.1036.34
linux-image-lowlatency 5.4.0.70.73
linux-image-lowlatency-hwe-20.04 5.8.0.48.54~20.04.32
linux-image-oem 5.4.0.70.73
linux-image-oem-20.04 5.6.0.1052.48
linux-image-oem-20.04b 5.10.0.1019.20
linux-image-oem-osp1 5.4.0.70.73
linux-image-oracle 5.4.0.1041.38
linux-image-raspi 5.4.0.1032.67
linux-image-raspi2 5.4.0.1032.67
linux-image-virtual 5.4.0.70.73
linux-image-virtual-hwe-20.04 5.8.0.48.54~20.04.32
Ubuntu 18.04 LTS:
linux-image-5.3.0-1038-raspi2 5.3.0-1038.40
linux-image-5.3.0-1041-gke 5.3.0-1041.44
linux-image-5.3.0-72-generic 5.3.0-72.68
linux-image-5.3.0-72-lowlatency 5.3.0-72.68
linux-image-5.4.0-1012-gkeop 5.4.0-1012.13~18.04.1
linux-image-5.4.0-1032-raspi 5.4.0-1032.35~18.04.1
linux-image-5.4.0-1039-gke 5.4.0-1039.41~18.04.1
linux-image-5.4.0-1040-gcp 5.4.0-1040.43~18.04.1
linux-image-5.4.0-1041-aws 5.4.0-1041.43~18.04.1
linux-image-5.4.0-1041-oracle 5.4.0-1041.44~18.04.1
linux-image-5.4.0-1043-azure 5.4.0-1043.45~18.04.1
linux-image-5.4.0-70-generic 5.4.0-70.78~18.04.1
linux-image-5.4.0-70-generic-lpae 5.4.0-70.78~18.04.1
linux-image-5.4.0-70-lowlatency 5.4.0-70.78~18.04.1
linux-image-aws 5.4.0.1041.24
linux-image-azure 5.4.0.1043.23
linux-image-gcp 5.4.0.1040.27
linux-image-generic-hwe-18.04 5.4.0.70.78~18.04.63
linux-image-generic-lpae-hwe-18.04 5.4.0.70.78~18.04.63
linux-image-gke-5.3 5.3.0.1041.24
linux-image-gke-5.4 5.4.0.1039.41~18.04.6
linux-image-gkeop-5.3 5.3.0.72.129
linux-image-gkeop-5.4 5.4.0.1012.13~18.04.13
linux-image-lowlatency-hwe-18.04 5.4.0.70.78~18.04.63
linux-image-oem 5.4.0.70.78~18.04.63
linux-image-oem-osp1 5.4.0.70.78~18.04.63
linux-image-oracle 5.4.0.1041.44~18.04.23
linux-image-raspi-hwe-18.04 5.4.0.1032.34
linux-image-raspi2-hwe-18.04 5.3.0.1038.27
linux-image-snapdragon-hwe-18.04 5.4.0.70.78~18.04.63
linux-image-virtual-hwe-18.04 5.4.0.70.78~18.04.63
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
Bug fix:
* RHACM 2.0.10 images (BZ #1940452)
3. Bugs fixed (https://bugzilla.redhat.com/):
1940452 - RHACM 2.0.10 images
1944286 - CVE-2021-23358 nodejs-underscore: Arbitrary code execution via the template function
5. 8.1) - aarch64, noarch, ppc64le, s390x, x86_64
3.
Bug Fix(es):
* Upstream Patch for Gracefully handle DMAR units with no supported address
widthsx86/vt-d (BZ#1932201)
* RHEL8.1 Alpha - ISST-LTE:PNV:Witherspoon-DD2.3:woo: KDUMP hang during
shutdown, lpfc loses connection to disks (rootdisk:nvme) (BZ#1934306)
4. Description:
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments. See the following advisory for the container images for
this release:
https://access.redhat.com/errata/RHBA-2021:1427
All OpenShift Container Platform 4.6 users are advised to upgrade to these
updated packages and images when they are available in the appropriate
release channel. To check for available updates, use the OpenShift Console
or the CLI oc command. Instructions for upgrading a cluster are available
at
https://docs.openshift.com/container-platform/4.6/updating/updating-cluster
- -between-minor.html#understanding-upgrade-channels_updating-cluster-between
- -minor
3. Solution:
For OpenShift Container Platform 4.6 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.openshift.com/container-platform/4.6/release_notes/ocp-4-6-rel
ease-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.6/updating/updating-cluster
- -cli.html
4. Bugs fixed (https://bugzilla.redhat.com/):
1887664 - CVE-2020-25649 jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)
1941768 - Reports that has specified a retention should not be requeued in the sync handler
1954163 - Placeholder bug for OCP 4.6.0 extras release
5. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Important: kernel-rt security and bug fix update
Advisory ID: RHSA-2021:1070-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2021:1070
Issue date: 2021-04-06
CVE Names: CVE-2021-27363 CVE-2021-27364 CVE-2021-27365
====================================================================
1. Summary:
An update for kernel-rt is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux for Real Time (v. 7) - noarch, x86_64
Red Hat Enterprise Linux for Real Time for NFV (v. 7) - noarch, x86_64
3. Description:
The kernel-rt packages provide the Real Time Linux Kernel, which enables
fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
* kernel: out-of-bounds read in libiscsi module (CVE-2021-27364)
* kernel: heap buffer overflow in the iSCSI subsystem (CVE-2021-27365)
* kernel: iscsi: unrestricted access to sessions and handles
(CVE-2021-27363)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Bug Fix(es):
* RHEL7.9 Realtime crashes due to a blocked task detection. The blocked
task is stuck in unregister_shrinker() where multiple tasks have taken the
shrinker_rwsem and are fighting on a dentry's d_lockref lock rt_mutex.
[kernel-rt] (BZ#1935557)
* kernel-rt: update to the latest RHEL7.9.z5 source tree (BZ#1939220)
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
5. Bugs fixed (https://bugzilla.redhat.com/):
1930078 - CVE-2021-27365 kernel: heap buffer overflow in the iSCSI subsystem
1930079 - CVE-2021-27363 kernel: iscsi: unrestricted access to sessions and handles
1930080 - CVE-2021-27364 kernel: out-of-bounds read in libiscsi module
6. Package List:
Red Hat Enterprise Linux for Real Time for NFV (v. 7):
Source:
kernel-rt-3.10.0-1160.24.1.rt56.1161.el7.src.rpm
noarch:
kernel-rt-doc-3.10.0-1160.24.1.rt56.1161.el7.noarch.rpm
x86_64:
kernel-rt-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-debug-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-debug-debuginfo-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-debug-devel-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-debug-kvm-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-debug-kvm-debuginfo-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-debuginfo-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-debuginfo-common-x86_64-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-devel-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-kvm-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-kvm-debuginfo-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-trace-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-trace-debuginfo-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-trace-devel-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-trace-kvm-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-trace-kvm-debuginfo-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
Red Hat Enterprise Linux for Real Time (v. 7):
Source:
kernel-rt-3.10.0-1160.24.1.rt56.1161.el7.src.rpm
noarch:
kernel-rt-doc-3.10.0-1160.24.1.rt56.1161.el7.noarch.rpm
x86_64:
kernel-rt-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-debug-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-debug-debuginfo-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-debug-devel-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-debuginfo-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-debuginfo-common-x86_64-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-devel-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-trace-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-trace-debuginfo-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
kernel-rt-trace-devel-3.10.0-1160.24.1.rt56.1161.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2021-27363
https://access.redhat.com/security/cve/CVE-2021-27364
https://access.redhat.com/security/cve/CVE-2021-27365
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYGwUItzjgjWX9erEAQjxsA//SlDSD/SJHCxceZvPrzgBTa7x6icArqhH
08++iBcxQ924tX3O9AizfbKGi4SfixaLnkTK/ZmucTD1nctMxvbQU/bSwnqT6NEv
SIEMMhxnwCG09utCX1hlKMjOjtwT53oapInBu8svGowlXzOg4WSzBLv5q7A7QmuQ
uFkSrymbQvoGVsDW3cee2xksPtHDuXg7rsNrnr5sfpyY0qrONgiy9WnhR4C/fCw3
uG/kedTHM4tTT0+8JgC4hfiAOZSSf6cowobPkE/kmOGxmUdLC8G4aRNQzOP/PPyp
MXQfo77P5Oq8FDt28DqlTTxu589YKUiY0/QtiCy4+nKMQ3eCFu6MK8es20VEamrk
CSr8Ms5OzUbAgEwlQnqcKjaXqEa6Z10SrqgL6tVYQmnqmO5y8XcnAJTNN8aAjvWj
6FoTLwpcGkNuL6ctaUjf8+tv/ybZG5OTLgvBto8pmS4pQBldxsn5MJUERye3POes
lh6QZtE3x59NsuDV0nczleVHO7pHbgpe5EiNXufRIVp9VvH6VU3JArSFq5GOwqNC
TRei+AumL9AL9cUWUE50DR3aBiPvXUbYabz8v0e5fPeXl/EkQAiypT4l82bxwoqI
l7CV1v62LoyfaPfHq34dPZA8I4BAdqorDYSDbtcgkOO1W1T4NeNOIBRJn6J/n8QW
r8zE0R3Ih9M=OvRU
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
. 7.2) - x86_64
3.
Bug Fix(es):
* Enable CI and changelog for GitLab workflow (BZ#1930934)
4. Description:
Red Hat Advanced Cluster Management for Kubernetes 2.1.6 images
Red Hat Advanced Cluster Management for Kubernetes provides the
capabilities to address common challenges that administrators and site
reliability engineers face as they work across a range of public and
private cloud environments. Clusters and applications are all visible and
managed from a single console—with security policy built in.
Bug fixes:
* RHACM 2.1.6 images (BZ#1940581)
* When generating the import cluster string, it can include unescaped
characters (BZ#1934184)
3. Solution:
Before applying this update, make sure all previously released errata
relevant to your system have been applied. Bugs fixed (https://bugzilla.redhat.com/):
1853652 - CVE-2020-14040 golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash
1929338 - CVE-2020-35149 mquery: Code injection via merge or clone operation
1934184 - When generating the import cluster string, it can include unescaped characters
1940581 - RHACM 2.1.6 images
5
| VAR-202103-0523 | CVE-2020-5148 | SonicWall SSO-agent Authentication vulnerabilities in |
CVSS V2: 6.4 CVSS V3: 8.2 Severity: HIGH |
SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker to bypass firewall access controls. SonicWall SSO-agent Contains an authentication vulnerability.Information may be obtained and information may be tampered with. SonicWall SSO-agent is an application software of the US (SonicWall) company. Provides a single login to provide access to multiple network resources based on administrator-configured group membership and policy matching. A security vulnerability exists in the SonicWall SSO-agent that could allow an attacker to bypass firewall access controls
| VAR-202103-1786 | No CVE | ZTE Corporation ZXHN F460 has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
ZXHN F460 is the optical modem of ZTE's EPON mode.
ZTE Corporation ZXHN F460 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service attack.
| VAR-202103-1787 | No CVE | ZTE Corporation ZXHN F460S has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
ZTE Corporation is the world's leading provider of integrated communications solutions.
ZTE Corporation ZXHN F460S has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service attack.
| VAR-202103-1800 | No CVE | Delta Electronics Enterprise Management (Shanghai) Co., Ltd. has an arbitrary file reading vulnerability in DIAView (CNVD-2021-08514) |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
DIAView is an automated management system with real-time system monitoring, data acquisition and analysis functions.
The DIAView configuration software of Delta Electronics Enterprise Management (Shanghai) Co., Ltd. has an arbitrary file reading vulnerability. Attackers can use this vulnerability to obtain sensitive information.
| VAR-202103-1649 | No CVE | WiseGrid Huimin application delivery gateway has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The business scope of Beijing Xinnuoride Software System Co., Ltd. includes: software development; computer system services; technology promotion services; technical development of network equipment, communication products, computer hardware and software, etc.
The WiseGrid Huimin application delivery gateway has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202103-1650 | No CVE | ZTE Corporation ZXHN F4600U has a denial of service vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
ZTE Corporation is the world's leading provider of integrated communications solutions.
ZTE Corporation ZXHN F4600U has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service attack.
| VAR-202103-0560 | CVE-2021-22128 | FortiProxy Authentication Vulnerability in Microsoft |
CVSS V2: 4.0 CVSS V3: 4.3 Severity: MEDIUM |
An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connection functionality. FortiProxy Contains an improper authentication vulnerability.Information may be obtained. Fortinet FortiProxy SSL VPN is an application software of the United States (Fortinet) company. An intrusion detection function is provided. There is a security vulnerability in FortiProxy SSL VPN, which allows attackers to exploit the vulnerability to obtain credentials of SSL VPN users
| VAR-202103-0173 | CVE-2020-15938 | FortiGate Vulnerability in |
CVSS V2: 4.3 CVSS V3: 7.5 Severity: HIGH |
When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6.2.5 and below 6.4.2 on port 80/443, it is not redirected to the transparent proxy policy for processing, as it doesn't have a valid HTTP header. FortiGate Contains an unspecified vulnerability.Information may be tampered with. Opera Software Opera is a web browser produced by Opera Software in Norway. It supports multi-window browsing, custom user interface and other functions. HTTPS (Hypertext Transfer Protocol Secure) is a network security transmission protocol, which communicates via Hypertext Transfer Protocol (HTTP) on a computer network, and uses SSL/TLS to encrypt data packets. The main purpose of HTTPS development is to provide identity authentication to web servers and protect the privacy and integrity of exchanged data. Vulnerabilities exist in Opera Software Opera and HTTPS. The following products and versions are affected:
| VAR-202103-1785 | No CVE | XINJE XL5E-16T ModbusTCP protocol has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
XINJE XL5E-16T is a series of Ethernet controller products.
XINJE XL5E-16T ModbusTCP protocol has a denial of service vulnerability. Attackers can use this vulnerability to cause the device to crash and fail to work normally.
| VAR-202103-1790 | No CVE | MOXA AWK-1131A Ethernet 802LLC protocol has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Moxa is a leading manufacturer of industrial automation, providing complete industrial equipment networking, industrial computers and industrial network solutions, and is committed to the joint promotion and practice of industrial Internet.
The MOXA AWK-1131A Ethernet 802LLC protocol has a denial of service vulnerability, which can be exploited by an attacker to cause the device to fail to work normally.
| VAR-202103-1791 | No CVE | XINJE XDME-30T4-E ModbusTCP protocol has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
XINJE XDME-30T4-E is a controller product of the Ethernet series.
XINJE XDME-30T4-E ModbusTCP protocol has a denial of service vulnerability. Attackers can use this vulnerability to cause the device to crash and fail to work normally.