CWE-159
Improper Handling of Invalid Use of Special Elements
Produkt nie filtruje prawidłowo, nie usuwa, nie cytuje lub w inny sposób nie zarządza nieprawidłowym użyciem elementów specjalnych w danych kontrolowanych przez użytkownika. Może to spowodować niekorzystny wpływ na zachowanie i integralność systemu.
The product does not properly filter, remove, quote, or otherwise manage the invalid use of special elements in user-controlled input, which could cause adverse effect on its behavior and integrity.
Oprogramowanie PrinterLogic Print Management w wersjach do 18.3.1.96 włącznie nie sanityzuje znaków specjalnych, umożliwiając nieautoryzowaną zdalne modyfikację plików konfiguracyjnych. Niezauthentykowany atakujący może zdalnie wykonać dowolny kod z uprawnieniami SYSTEM.
On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific UPDATE for an EBGP peer can lead to a routing process daemon (RPD) crash and restart. This issue occurs only when the device is receiving and processing the BGP UPDATE for an EBGP peer. This issue does not occur when the device is receiving and processing the BGP UPDATE for an IBGP peer. However, the offending BGP UPDATE can originally come from an EBGP peer, propagates through the network via IBGP peers without causing crash, then it causes RPD crash when it is processed for a BGP UPDATE towards an EBGP peer. Repeated receipt and processing of the same specific BGP UPDATE can result in an extended Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 17.3R3-S6, 17.4R2-S7, and 18.1R3-S7. Juniper Networks Junos OS Evolved 19.2R2-EVO and later versions, prior to 19.3R1-EVO. Other Junos OS releases are not affected.
On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific BGP packet can lead to a routing process daemon (RPD) crash and restart. This issue can occur even before the BGP session with the peer is established. Repeated receipt of this specific BGP packet can result in an extended Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 18.2X75 versions starting from 18.2X75-D50.8, 18.2X75-D60 and later versions, prior to 18.2X75-D52.8, 18.2X75-D53, 18.2X75-D60.2, 18.2X75-D65.1, 18.2X75-D70; 19.4 versions 19.4R1 and 19.4R1-S1; 20.1 versions prior to 20.1R1-S2, 20.1R2. Juniper Networks Junos OS Evolved: 19.4-EVO versions prior to 19.4R2-S2-EVO; 20.1-EVO versions prior to 20.1R2-EVO. This issue does not affect: Juniper Networks Junos OS releases prior to 19.4R1. Juniper Networks Junos OS Evolved releases prior to 19.4R1-EVO.
On Juniper Networks Junos OS devices, a stream of TCP packets sent to the Routing Engine (RE) may cause mbuf leak which can lead to Flexible PIC Concentrator (FPC) crash or the system to crash and restart (vmcore). This issue can be trigged by IPv4 or IPv6 and it is caused only by TCP packets. This issue is not related to any specific configuration and it affects Junos OS releases starting from 17.4R1. However, this issue does not affect Junos OS releases prior to 18.2R1 when Nonstop active routing (NSR) is configured [edit routing-options nonstop-routing]. The number of mbufs is platform dependent. The following command provides the number of mbufs counter that are currently in use and maximum number of mbufs that can be allocated on a platform: user@host> show system buffers 2437/3143/5580 mbufs in use (current/cache/total) Once the device runs out of mbufs, the FPC crashes or the vmcore occurs and the device might become inaccessible requiring a manual restart. This issue affects Juniper Networks Junos OS 17.4 versions prior to 17.4R2-S11, 17.4R3-S2; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7, 18.2R3-S5; 18.2X75 versions prior to 18.2X75-D41, 18.2X75-D420.12, 18.2X75-D51, 18.2X75-D60, 18.2X75-D34; 18.3 versions prior to 18.3R2-S4, 18.3R3-S2; 18.4 versions prior to 18.4R1-S7, 18.4R2-S4, 18.4R3-S1; 19.1 versions prior to 19.1R1-S5, 19.1R2-S1, 19.1R3; 19.2 versions prior to 19.2R1-S5, 19.2R2; 19.3 versions prior to 19.3R2-S3, 19.3R3; 19.4 versions prior to 19.4R1-S2, 19.4R2. Versions of Junos OS prior to 17.4R1 are unaffected by this vulnerability.
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
SuiteCRM to aplikacja open-source Customer Relationship Management (CRM) klasy enterprise. Przed wersjami 7.15.1 i 8.9.3 wartość parametru żądania return_id była kopiowana do atrybutu tagu HTML będącego obsługą zdarzenia i ujęta w cudzysłowy. Wersje 7.15.1 i 8.9.3 usuwają podatność. Użytkownicy powinni również zastosować nagłówek Content Security Policy (CSP), aby całkowicie złagodzić XSS.
Podatność wynika ze słabości CWE-159: "Improper Handling of Invalid Use of Special Elements", która prowadzi do nieodwracalnej niespójności w sterowniku CLFS.sys. Ten stan wymusza wywołanie funkcji KeBugCheckEx, umożliwiając niepriorytetowanemu użytkownikowi wyzwolenie crash systemu. Microsoft cicho naprawił tę podatność we wrześniowej aktualizacji zbiorczej dla Windows 11 2024 LTSC i Windows Server 2025. Windows 25H2 (wydany we wrześniu) został wydany z łatką. Windows 1123h2 i wcześniejsze wersje pozostają podatne.
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast address (0xFFFFFFFF) which could result in unexpected behavior and potential for DDoS attacks on the network. A malicious actor could craft a packet to be from that address which would result in an amplification of this one message into every node on the network sending multiple messages. Such an attack could result in degraded network performance for all users as the available bandwidth is consumed. This issue has been addressed in release version 2.5.6. All users are advised to upgrade. There are no known workarounds for this vulnerability.
In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.
Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3
ssh w OpenSSH przed wersją 10.1 pozwala na znaki kontrolne w nazwach użytkowników pochodzących z określonych potencjalnie niezaufanych źródeł, co może prowadzić do code execution przy użyciu ProxyCommand. Niezaufanymi źródłami są linia poleceń i rozszerzenie sekwencji % w pliku konfiguracyjnym. (Plik konfiguracyjny zawierający pełną literalną nazwę użytkownika nie jest kategoryzowany jako niezaufane źródło.)
RISC Zero to platforma do uniwersalnego obliczeń z zero-knowledge proof, zintegrowana z Ethereum. Repozytorium risc0-ethereum zawiera kontrakty Solidity weryfikatora, bibliotekę Steel EVM view call i kod wspierający. W wersjach wcześniejszych niż 2.1.1 i 2.2.0 funkcja biblioteki Solidity `Steel.validateCommitment` zwraca `true` dla spreparowanego commitment'u o digest'ie równym zero, co narusza semantykę `validateCommitment` — taki commitment nie odpowiada żadnemu blokowi w obecnym łańcuchu. Luka została naprawiona w risc0-ethereum 2.1.1 i 2.2.0; użytkownicy biblioteki Steel w wersjach 2.1.0 i wcześniejszych powinni upewnić się, że używają `Steel.validateCommitment` razem z weryfikacją zkVM proof'u programu Steel zgodnie z dokumentacją i przykładami — jest to prawidłowe użycie, i użytkownicy postępujący zgodnie z tym wzorcem nie są narażeni na ryzyko.