CWE-417
Podatność w LibreOffice pod systemem Windows umożliwia obejście zabezpieczeń blokujących uruchamianie skryptu LibreLogo z poziomu obsługi zdarzeń dokumentu. Atakujący może skonstruować złośliwy dokument, który bez wiedzy użytkownika wykona dowolny kod Python.
October CMS w buildzie 412 zawiera podatność umożliwiającą modyfikację ścieżki pliku podczas operacji przenoszenia zasobów (asset move). Może to prowadzić do tworzenia złośliwych plików w dowolnych lokalizacjach na serwerze.
Wersje rkhunter przed 1.4.4 pobierają pliki podczas aktualizacji mirror po niezabezpieczonym kanale komunikacji. Umożliwia to atakującemu podstawienie złośliwego pliku i potencjalne zdalne wykonanie kodu (RCE) na systemie ofiary.
Mechanizm uwierzytelniania wiadomości HMAC w środowisku QSEE (Qualcomm Secure Execution Environment) jest podatny na atak side-channel oparty na analizie czasu wykonania. Pozwala to na potencjalne sfałszowanie wiadomości aplikacji, co stanowi poważne zagrożenie dla integralności komunikacji z bezpieczną enklawą.
Implementacja protokołu Multicast DNS (mDNS) w urządzeniu Bose Soundtouch 30 nieprawidłowo odpowiada na zapytania unicast IPv4 pochodzące spoza sieci lokalnej, co umożliwia zdalnym atakującym wywołanie ataku wzmocnienia ruchu (DoS) oraz potencjalne pozyskanie wrażliwych informacji. Podatność jest szczególnie groźna ze względu na brak wymogu uwierzytelnienia i możliwość zdalnego wykorzystania.
Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle attackers to decrypt messages via an inadequate implementation of SSL.
The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the original file can be altered by a malicious user by passing a special path to the callback parameter through the Mozilla Maintenance Service, allowing the manipulation of files in the installation directory and privilege escalation by manipulating the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.
On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs. Remote attackers can send print jobs directly to the printer via TCP port 9100.
Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.
An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a request, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. The unexpected presence of path parameters can cause a constraint to be bypassed. Users of Apache Tomcat (all current versions) are not affected by this vulnerability since Tomcat follows the guidance previously provided by the Servlet Expert group and strips path parameters from the value returned by getContextPath(), getServletPath(), and getPathInfo(). Users of other Servlet containers based on Apache Tomcat may or may not be affected depending on whether or not the handling of path parameters has been modified. Users of IBM WebSphere Application Server 8.5.x are known to be affected. Users of other containers that implement the Servlet specification may be affected.
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload.
Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because scalar multiplication in ecp.cpp (prime field curves, small leakage) and algebra.cpp (binary field curves, large leakage) is not constant time and leaks the bit length of the scalar among other information.
S3300 V100R006C05 have an Ethernet in the First Mile (EFM) flapping vulnerability due to the lack of type-length-value (TLV) consistency check. An attacker may craft malformed packets and send them to a device to cause EFM flapping.
W Tor w wersjach przed 0.2.5.16, 0.2.6–0.2.8 przed 0.2.8.17, 0.2.9 przed 0.2.9.14, 0.3.0 przed 0.3.0.13 i 0.3.1 przed 0.3.1.9, przekaźniki posiadające niekompletnie pobrane deskryptory mogą wybierać siebie w ścieżce obwodu, co prowadzi do pogorszenia anonimowości.
lxc-user-nic podczas usuwania interfejsu sieciowego bezwarunkowo otwiera ścieżkę podaną przez użytkownika. Ta ścieżka kodu może być wykorzystana przez nieprivilileowanego użytkownika do sprawdzenia istnienia ścieżki, do której normalnie nie miałby dostępu. Może również być użyta do wywołania efektów ubocznych poprzez otwarcie (w trybie tylko do odczytu) specjalnych plików jądra (ptmx, proc, sys). Dotyczy wydania LXC: wersje 2.0.9 i nowsze, oraz wersje 3.0.0 do 3.0.1.