New User, Welcome!     Login

Next Page >>

Memory leak

Cisco Security Advisory: Multiple Vulnerabilities in Cisco PIX and Cisco ASA

Security Appliances and Cisco PIX Security Appliances. This security
advisory outlines details of these vulnerabilities:

  * Windows NT Domain Authentication Bypass Vulnerability
  * IPv6 Denial of Service Vulnerability
  * Crypto Accelerator Memory Leak Vulnerability

Note: These vulnerabilities are independent of each other. A device may
be affected by one vulnerability and not affected by another.

Cisco has released free software updates that address these

Cisco Security Advisory: Cisco IOS Software IPS and Zone-Based Firewall Vulnerabilities

Cisco IOS Software contains two vulnerabilities related to Cisco IOS
Intrusion Prevention System (IPS) and Cisco IOS Zone-Based Firewall
features. These vulnerabilities are:

  * Memory leak in Cisco IOS Software
  * Cisco IOS Software Denial of Service when processing specially
    crafted HTTP packets

Cisco has released free software updates that address these
vulnerabilities.

Cisco Security Advisory: Remote Access VPN and SIP Vulnerabilities in Cisco PIX and Cisco ASA

This security advisory outlines details of the following
vulnerabilities:

  * Erroneous SIP Processing Vulnerabilities
  * IPSec Client Authentication Processing Vulnerability
  * SSL VPN Memory Leak Vulnerability
  * URI Processing Error Vulnerability in SSL VPNs
  * Potential Information Disclosure in Clientless VPNs

Note:  These vulnerabilities are independent of each other. A device
may be affected by one vulnerability and not affected by another.

Cisco Security Advisory: Cisco IOS Virtual Private Dial-up Network Denial of Service Vulnerability

(VPDN) solution when Point-to-Point Tunneling Protocol (PPTP) is used
in certain Cisco IOS releases prior to 12.3. PPTP is only one of the
supported tunneling protocols used to tunnel PPP frames within the
VPDN solution.

The first vulnerability is a memory leak that occurs as a result of
PPTP session termination. The second vulnerability may consume all
interface descriptor blocks on the affected device because those
devices will not reuse virtual access interfaces. If these
vulnerabilities are repeatedly exploited, the memory and/or interface
resources of the attacked device may be depleted.

Cisco Security Advisory: Cisco Unified Communications Manager Session Initiation Protocol Memory Leak Vulnerabilities

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Cisco Security Advisory: Cisco Unified Communications Manager Session
Initiation Protocol Memory Leak Vulnerability

Advisory ID: cisco-sa-20110928-cucm

Revision 1.0


[SECURITY] [DSA 1928-1] New Linux 2.6.24 packages fix several vulnerabilities

http://www.debian.org/security/                           Dann Frazier
November 5, 2009                    http://www.debian.org/security/faq
- ----------------------------------------------------------------------

Package        : linux-2.6.24
Vulnerability  : privilege escalation/denial of service/sensitive memory leak
Problem type   : local/remote
Debian-specific: no
CVE Id(s)      : CVE-2009-2846 CVE-2009-2847 CVE-2009-2848 CVE-2009-2849
                 CVE-2009-2903 CVE-2009-2908 CVE-2009-2909 CVE-2009-2910
                 CVE-2009-3001 CVE-2009-3002 CVE-2009-3228 CVE-2009-3238

Cisco Security Advisory: Cisco IOS Software Data-Link Switching Vulnerability

+---------------------------------------------------------------------

Summary
=======

Cisco IOS Software contains a memory leak vulnerability in the
Data-Link Switching (DLSw) feature that could result in a device
reload when processing crafted IP Protocol 91 packets.

Cisco has released free software updates that address this
vulnerability.

Cisco Security Advisory: Vulnerability in Cisco IOS with OSPF, MPLS VPN, and Supervisor 32, Supervisor 720, or Route Switch Processor 720

=======

Vulnerable Cisco devices, when configured for Multi Protocol Label
Switching (MPLS) Virtual Private Networking (VPN) and Open Shortest
Path First (OSPF) sham-link, can suffer from a blocked queue, 
memory leak and/or restart of the device

This vulnerability is documented in Cisco bug ID CSCsf12082, and has 
been assigned CVE ID CVE-2008-0057.

The following combination of hardware and software configuration must

Cisco Security Advisory: Cisco IOS Software WebVPN and SSLVPN Vulnerabilities

exploited without authentication to cause a denial of service
condition. Both vulnerabilities affect both Cisco IOS WebVPN and
Cisco IOS SSLVPN features:

 1. Crafted HTTPS packet will crash device.
 2. SSLVPN sessions cause a memory leak in the device.

Cisco has released free software updates that address these
vulnerabilities.

There are no workarounds that mitigate these vulnerabilities.

Cisco Security Advisory: Multiple Cisco IOS Session Initiation Protocol Denial of Service Vulnerabilities

Summary
=======

Multiple vulnerabilities exist in the Session Initiation Protocol
(SIP) implementation in Cisco IOS that can be exploited remotely to
trigger a memory leak or to cause a reload of the IOS device.

Cisco has released free software updates that address these
vulnerabilities. Fixed Cisco IOS software listed in the Software
Versions and Fixes section contains fixes for all vulnerabilities
addressed in this advisory.

[SECURITY] [DSA 1915-1] New Linux 2.6.26 packages fix several vulnerabilities

http://www.debian.org/security/                           dann frazier
October 22, 2009                    http://www.debian.org/security/faq
- ----------------------------------------------------------------------

Package        : linux-2.6
Vulnerability  : privilege escalation/denial of service/sensitive memory leak
Problem type   : local/remote
Debian-specific: no
CVE Id(s)      : CVE-2009-2695 CVE-2009-2903 CVE-2009-2908 CVE-2009-2909
                 CVE-2009-2910 CVE-2009-3001 CVE-2009-3002 CVE-2009-3286
                 CVE-2009-3290 CVE-2009-3613

Cisco Security Advisory: Cisco IOS Software Network Address Translation Vulnerabilities

assigned CVE ID CVE-2011-3279.

NAT of crafted SIP over UDP packets DoS vulnerabilities: There are two
DoS vulnerabilities related to similar crafted packets on UDP port 5060
that require SIP translation: the first is a vulnerability that will
cause the device to reload and the second will cause a memory leak
that could lead to a DoS condition, including reload of the vulnerable
device. The NAT of SIP vulnerabilities are documented in Cisco bug ID
CSCti48483 and Cisco bug ID CSCtj04672. They have been assigned CVE IDs
CVE-2011-3278 and CVE-2011-3280.


Cisco Security Advisory: Cisco Physical Access Gateway Denial of Service Vulnerability

=======

The Cisco Physical Access Gateway is the primary means for the Cisco
Physical Access Control solution to connect door hardware, such as
locks and readers, to an IP network. Certain crafted TCP port 443
packets may cause a memory leak that could lead to a denial of
service (DoS) condition in the Cisco Physical Access Gateway. A TCP
three-way handshake is needed to exploit this vulnerability.

This vulnerability is documented in Cisco Bug ID CSCsu95864 and has
been assigned Common Vulnerabilities and Exposures (CVE) ID CVE-2009-1163.

Cisco Security Advisory: Cisco Content Switching Module Memory Leak Vulnerability

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Cisco Content Switching Module Memory Leak
Vulnerability

Advisory ID: cisco-sa-20080514-csm

http://www.cisco.com/warp/public/707/cisco-sa-20080514-csm.shtml


Cisco Security Advisory: Cisco Content Switching Module Memory Leak Vulnerability

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cisco Security Advisory: Cisco Content Switching Module Memory Leak
Vulnerability

Advisory ID: cisco-sa-20080514-csm

http://www.cisco.com/warp/public/707/cisco-sa-20080514-csm.shtml


IRM025: TIBCO Rendezvous RVD Daemon Remote Memory Leak DoS

--------------------------------------------------------
IRM Security Advisory 025

TIBCO Rendezvous RVD Daemon Remote Memory Leak DoS 

Vulnerability Type / Importance: Remote DoS / High

Problem Discovered: 16 April 2007
Vendor Contacted: 16 April 2007
Advisory Published: 29 November 2007

[oCERT-2009-003] LittleCMS integer errors

Description:

LittleCMS, an open source color management engine, suffers from several
integer errors, resulting in stack based buffer overflows and various heap
errors as well as dangerous memory leaks. Decoding a specially crafted
image file will result in unexpected process termination, Denial Of
Service conditions or arbitrary code execution due to stack overflow.

LittleCMS is used by several Open Source projects including OpenJDK,
Firefox and GIMP.

[SECURITY] [DSA 1505-1] New alsa-driver packages fix kernel memory leak

http://www.debian.org/security/                           dann frazier
February 22, 2008                   http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package        : alsa-driver
Vulnerability  : kernel memory leak
Problem type   : local
Debian-specific: no
CVE Id(s)      : CVE-2007-4571

Takashi Iwai supplied a fix for a memory leak in the snd_page_alloc module.

[SECURITY] [DSA 1929-1] New Linux 2.6.18 packages fix several vulnerabilities

http://www.debian.org/security/                           Dann Frazier
November 5, 2009                    http://www.debian.org/security/faq
- ----------------------------------------------------------------------

Package        : linux-2.6
Vulnerability  : privilege escalation/denial of service/sensitive memory leak
Problem type   : local
Debian-specific: no
CVE Id(s)      : CVE-2009-1883 CVE-2009-2909 CVE-2009-3001 CVE-2009-3002
                 CVE-2009-3228 CVE-2009-3238 CVE-2009-3286 CVE-2009-3547
                 CVE-2009-3612 CVE-2009-3621

[ MDVSA-2010:133 ] libpng

 Problem Description:

 Multiple vulnerabilities has been found and corrected in libpng:
 
 Memory leak in the png_handle_tEXt function in pngrutil.c in libpng
 before 1.2.33 rc02 and 1.4.0 beta36 allows context-dependent attackers
 to cause a denial of service (memory exhaustion) via a crafted PNG file
 (CVE-2008-6218.
 
 Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances

affected by this vulnerability.

Crafted TCP Packet DoS Vulnerability
+-----------------------------------

Cisco ASA and Cisco PIX security appliances may experience a memory leak
that can be triggered by a series of crafted TCP packets. Cisco ASA and
Cisco PIX security appliances running versions 7.0, 7.1, 7.2, 8.0, and
8.1 are affected when configured for any of the following features:

  * SSL VPNs

[SECURITY] [DSA 1749-1] New Linux 2.6.26 packages fix several vulnerabilities

http://www.debian.org/security/                           dann frazier
March 20, 2009                      http://www.debian.org/security/faq
- ----------------------------------------------------------------------

Package        : linux-2.6
Vulnerability  : denial of service/privilege escalation/sensitive memory leak
Problem type   : local/remote
Debian-specific: no
CVE Id(s)      : CVE-2009-0029 CVE-2009-0031 CVE-2009-0065 CVE-2009-0269
                 CVE-2009-0322 CVE-2009-0676 CVE-2009-0675 CVE-2009-0745
                 CVE-2009-0746 CVE-2009-0747 CVE-2009-0748

Cisco Security Advisory: Cisco IOS SSL VPN Vulnerability

Summary
=======

Cisco IOS  Software contains a vulnerability when the Cisco IOS SSL
VPN feature is configured with an HTTP redirect. Exploitation could
allow a remote, unauthenticated user to cause a memory leak on the
affected devices, that could result in a memory exhaustion condition
that may cause device reloads, the inability to service new TCP
connections, and other denial of service (DoS) conditions.

Cisco has released free software updates that address this

[ MDVSA-2009:124 ] apache

 Problem Description:

 Multiple vulnerabilities has been found and corrected in apache:
 
 Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c
 in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to
 cause a denial of service (memory consumption) via multiple calls, as
 demonstrated by initial SSL client handshakes to the Apache HTTP Server
 mod_ssl that specify a compression algorithm (CVE-2008-1678). Note
 that this security issue does not really apply as zlib compression

[ MDVSA-2008:072 ] - Updated kernel packages fix vulnerability

 The Linux kernel prior to 2.6.22.17, when using certain drivers
 that register a fault handler that does not perform range checks,
 allowed local users to access kernel memory via an out-of-range offset
 (CVE-2008-0007).
 
 Additionally, this kernel fixes a JBD checkpoint memory leak bug.
 
 To update your kernel, please follow the directions located at:
 
   http://www.mandriva.com/en/security/kernelupdate
 _______________________________________________________________________

[SECURITY] [DSA 1745-2] New lcms packages fix regression

the following problems:


CVE-2009-0581

Chris Evans discovered that lcms is affected by a memory leak, which
could result in a denial of service via specially crafted image files.

CVE-2009-0723

Chris Evans discovered that lcms is prone to several integer overflows

[SECURITY] [DSA 1794-1] New Linux 2.6.18 packages fix several vulnerabilities

    users to cause a denial of service or potentially gain elevated
    privileges.

CVE-2009-0031

    Vegard Nossum discovered a memory leak in the keyctl subsystem
    that allows local users to cause a denial of service by consuming
    all available kernel memory.

CVE-2009-0065


Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers

    This vulnerability is documented in Cisco Bug ID CSCsx03715 and
    has been assigned Common Vulnerabilities and Exposures (CVE) ID
    CVE-2009-1164.

  * SSH connections denial of service vulnerability
    Affected devices may be susceptible to a memory leak when they
    handle SSH management connections. An attacker could use this
    behavior to cause an affected device to crash and reload.
   
    Note:  A three-way handshake is not required to exploit this
    vulnerability.

[TZO-27-2009] Firefox Denial of Service (Keygen)

for free. 

II. Description
~~~~~~~~~~~~~~~
This bug is a simple design bug that results in an endless loop (and interesting
memory leaks).

Once upon a time Netscape thought it would be a great idea to add the keygen tag
(<keygen>) as a feature to their Browser. The keygen tag offers a simple way
of automatically generating key material using various algorithms. For instance
it is possible to generate RSA, DSA and EC key material.

[SECURITY] [DSA 1504-1] New Linux kernel 2.6.8 packages fix several issues

    A similar issue exists in the IPV4 protocol handler and will be fixed
    in a subsequent update.

CVE-2007-2525

    Florian Zumbiehl discovered a memory leak in the PPPOE subsystem caused
    by releasing a socket before PPPIOCGCHAN is called upon it. This could
    be used by a local user to DoS a system by consuming all available memory.

CVE-2007-3105


Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!