CWE-172
Encoding Error
Produkt nie koduje lub dekoduje danych prawidłowo, co skutkuje nieoczekiwanymi wartościami. Błąd ten może prowadzić do nieprawidłowego przetwarzania informacji i potencjalnych luk bezpieczeństwa.
The product does not properly encode or decode the data, resulting in unexpected values.
W Pythonie odkryto regresję bezpieczeństwa CVE-2019-9636, która nadal umożliwia atakującemu manipulację częścią użytkownika i hasła w adresach URL w celu wyłudzenia danych uwierzytelniających lub ciasteczek. Podatność uzyskała ocenę CVSS 9.8 i dotyczy szerokiego zakresu wersji gałęzi 2.7, 3.5, 3.6, 3.7 oraz wczesnych wydań 3.8.
Biblioteka Restforce przed wersją 3.0.0 nieprawidłowo koduje identyfikatory URI, co umożliwia atakującemu wstrzyknięcie dowolnych parametrów do żądań API Salesforce. Podatność jest krytyczna, ponieważ nie wymaga uwierzytelnienia ani interakcji użytkownika.
Podatność w module gbk2utf sterownika Wi-Fi Qualcomm w systemie Android umożliwia zdalnemu atakującemu wywołanie awarii frameworka systemowego poprzez rozgłaszanie punktu dostępowego z nieprawidłowo sformowanym identyfikatorem SSID w kodowaniu GBK. Ze względu na wektor sieciowy i brak wymaganych uprawnień, podatność stanowi poważne zagrożenie dla urządzeń w zasięgu złośliwego punktu dostępowego.
Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. A bug that exists only in Libmodsecurity3 version 3.0.13 means that, in 3.0.13, Libmodsecurity3 can't decode encoded HTML entities if they contains leading zeroes. Version 3.0.14 contains a fix. No known workarounds are available.
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This can lead to an application using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service.
A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition that prevents the creation of new SSL/Transport Layer Security (TLS) connections to an affected device. The vulnerability is due to incorrect handling of Base64-encoded strings. An attacker could exploit this vulnerability by opening many SSL VPN sessions to an affected device. The attacker would need to have valid user credentials on the affected device to exploit this vulnerability. A successful exploit could allow the attacker to overwrite a special system memory location, which will eventually result in memory allocation errors for new SSL/TLS sessions to the device, preventing successful establishment of these sessions. A reload of the device is required to recover from this condition. Established SSL/TLS connections to the device and SSL/TLS connections through the device are not affected. Note: Although this vulnerability is in the SSL VPN feature, successful exploitation of this vulnerability would affect all new SSL/TLS sessions to the device, including management sessions.
Gdy NGINX Open Source jest skonfigurowany do proxy'owania ruchu HTTP/2 poprzez ustawienie proxy_http_version na 2 i jednocześnie używa proxy_set_body, atakujący może być w stanie wstrzyknąć nagłówki ramek i bajty payload'u do upstream'owego peera. Uwaga: wersje oprogramowania, które osiągnęły koniec wsparcia technicznego (EoTS), nie są oceniane.
A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.
codecs/hevcdec/SoftHEVC.cpp in libstagefright in mediaserver in Android 6.0.1 before 2016-08-01 mishandles decoder errors, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28816956.
decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-08-01 mishandles invalid PPS and SPS NAL units, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28835995.
The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 does not initialize certain structure members, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 29023649.
Symfony to framework PHP do aplikacji webowych i konsolowych oraz zestaw wielokrotnego użytku komponentów PHP. W wersjach przed 5.4.53, 6.4.41, 7.4.13 i 8.0.13 funkcja UrlGenerator::doGenerate() używała kodowania dot-segmentów za pomocą strtr(), które pomijało co drugi łańcuch segmentów ../ lub ./, umożliwiając atakującemu manipulowanie parametrami trasy w celu wygenerowania adresów URL, które podczas normalizacji RFC 3986 zawłaszczają się do innej ścieżki. Problem został naprawiony w wersjach 5.4.53, 6.4.41, 7.4.13 i 8.0.13.
A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM is a member.
SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40, 7.50) do not sufficiently encode user controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed.
W Armadito 0.12.7.2 odkryto podatność w pliku armadito-windows-driver/src/communication.c. Złośliwe oprogramowanie z nazwami plików zawierającymi czyste znaki UTF-16 może ominąć detekcję, ponieważ usługa user-mode nie otwiera pliku do skanowania po konwersji z Unicode na ANSI — znaki, których nie można przekonwertować, zastępowane są znakami '?'.
Błąd kodowania URL w obsłudze trybu development w com.vaadin:flow-server w wersjach 2.0.0 do 2.6.1 (Vaadin 14.0.0 do 14.6.1), 3.0.0 do 6.0.9 (Vaadin 15.0.0 do 19.0.8) pozwala użytkownikowi lokalnemu na wykonanie arbitralnego kodu JavaScript poprzez otwarcie spreparowanego adresu URL w przeglądarce.
SpiceDB to open source'owa baza danych do skalowanego przechowywania i wysyłania zapytań dotyczących szczegółowych danych autoryzacyjnych. Od wersji 1.35.0 do 1.37.1 klienci z włączoną funkcją `LookupResources2` i zastrzeżeniami w ścieżce oceny mogą zwrócić uprawnienie `CONDITIONAL` z kontekstem oznaczonym jako brakujący, nawet gdy kontekst został dostarczone. Luka została naprawiona w wersji 1.37.1. Obejściem jest wyłączenie LookupResources2 poprzez flagę `--enable-experimental-lookup-resources` ustawioną na `false`.