New User, Welcome!     Login

Next Page >>

crash

[USN-1093-1] Linux Kernel vulnerabilities (Marvell Dove)

Details follow:

Joel Becker discovered that OCFS2 did not correctly validate on-disk
symlink structures. If an attacker were able to trick a user or automated
system into mounting a specially crafted filesystem, it could crash the
system or exposde kernel memory, leading to a loss of privacy.

Ben Hutchings discovered that the ethtool interface did not correctly
check certain sizes. A local attacker could perform malicious ioctl calls
that could crash the system, leading to a denial of service. (Only Ubuntu

[USN-1083-1] Linux kernel vulnerabilities

perform this as well.

Details follow:

Al Viro discovered a race condition in the TTY driver. A local attacker
could exploit this to crash the system, leading to a denial of service.
(CVE-2009-4895)

Gleb Napatov discovered that KVM did not correctly check certain privileged
operations. A local attacker with access to a guest kernel could exploit
this to crash the host system, leading to a denial of service.

[USN-1074-1] Linux kernel vulnerabilities

all the necessary changes.

Details follow:

Al Viro discovered a race condition in the TTY driver. A local attacker
could exploit this to crash the system, leading to a denial of service.
(CVE-2009-4895)

Dan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly
check file permissions. A local attacker could overwrite append-only files,
leading to potential data loss. (CVE-2010-2066)

[USN-1074-2] Linux kernel vulnerabilities

update provides the corresponding updates for Ubuntu 10.04.

Original advisory details:

 Al Viro discovered a race condition in the TTY driver. A local attacker
 could exploit this to crash the system, leading to a denial of service.
 (CVE-2009-4895)
 
 Dan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly
 check file permissions. A local attacker could overwrite append-only files,
 leading to potential data loss. (CVE-2010-2066)

[USN-1017-1] MySQL vulnerabilities

Details follow:

It was discovered that MySQL incorrectly handled certain requests with the
UPGRADE DATA DIRECTORY NAME command. An authenticated user could exploit
this to make MySQL crash, causing a denial of service. This issue only
affected Ubuntu 9.10 and 10.04 LTS. (CVE-2010-2008)

It was discovered that MySQL incorrectly handled joins involving a table
with a unique SET column. An authenticated user could exploit this to make
MySQL crash, causing a denial of service. This issue only affected Ubuntu

CORE-2012-0123 - SAP Netweaver Dispatcher Multiple Vulnerabilities

could allow a remote unauthenticated attacker to execute arbitrary code
with the privileges of the user running the "Dispatcher" service. The
following python code can be used to trigger the vulnerability:

/-----
crash = "X"*114 + "\xff\xff" # --> Unicode Address to call !
crash+= "Y"*32
crash = "\x10\x06\x20" + struct.pack("!H", len(crash)) + crash
send_message(connection, crash)
-----/


Cisco Security Advisory: Multiple vulnerabilities in Cisco PGW Softswitch

independent from other. The vulnerabilities are related to processing
Session Initiation Protocol (SIP) or Media Gateway Control Protocol
(MGCP) messages.

Successful exploitation of all but one of these vulnerabilities can
crash the affected device. Exploitation of the remaining
vulnerability will not crash the affected device, but it can lead to
a denial-of-service (DoS) condition in which no new TCP-based
connections will be accepted or created.

Cisco has released free software updates that address these

[Suspected Spam][USN-947-2] Linux kernel regression

 exploit this to cause a denial of service. (Only affected Ubuntu 6.06
 LTS.) (CVE-2009-4271)
 
 It was discovered that the r8169 network driver did not correctly check
 the size of Ethernet frames.  A remote attacker could send specially
 crafted traffic to crash the system, leading to a denial of service.
 (CVE-2009-4537)
 
 Wei Yongjun discovered that SCTP did not correctly validate certain
 chunks.  A remote attacker could send specially crafted traffic to
 monopolize CPU resources, leading to a denial of service. (Only affected

[ MDVSA-2009:321 ] pidgin

 certificates, which makes it easier for remote attackers to trick
 a user into accepting an invalid server certificate for a spoofed
 service. (CVE-2008-3532)
 
 Pidgin 2.4.1 allows remote attackers to cause a denial of service
 (crash) via a long filename that contains certain characters, as
 demonstrated using an MSN message that triggers the crash in the
 msn_slplink_process_msg function. (CVE-2008-2955)
 
 The UPnP functionality in Pidgin 2.0.0, and possibly other versions,
 allows remote attackers to trigger the download of arbitrary files

CORE-2008-0126: Multiple vulnerabilities in iCal

 Three vulnerabilities discovered in the iCal application may allow
un-authenticated attackers to execute arbitrary code on vulnerable
systems with (and potentially without) the assistance from the end user
of the application or to repeatean resource liberationdly execute a
denial of service attack to crash the iCal application.

 The most serious of the three vulnerabilities is due to potential
memory corruption resulting from a resource liberation bug that can be
triggered with a malformed '.ics' calendar file specially crafted by a
would-be attacker.

CORE-2008-0126: Multiple vulnerabilities in iCal

 Three vulnerabilities discovered in the iCal application may allow
un-authenticated attackers to execute arbitrary code on vulnerable
systems with (and potentially without) the assistance from the end user
of the application or to repeatean resource liberationdly execute a
denial of service attack to crash the iCal application.

 The most serious of the three vulnerabilities is due to potential
memory corruption resulting from a resource liberation bug that can be
triggered with a malformed '.ics' calendar file specially crafted by a
would-be attacker.

[ MDVSA-2010:222 ] mysql

 Problem Description:

 Multiple vulnerabilities were discovered and corrected in mysql:
 
 * Joins involving a table with with a unique SET column could cause
 a server crash (CVE-2010-3677).
 
 * Use of TEMPORARY InnoDB tables with nullable columns could cause
 a server crash (CVE-2010-3680).
 
 * The server could crash if there were alternate reads from two

[SECURITY] [DSA-2143-1] New mysql-dfsg-5.0 packages fix several vulnerabilities

CVE-2010-3677

  It was discovered that MySQL allows remote authenticated users to cause
  a denial of service (mysqld daemon crash) via a join query that uses a
  table with a unique SET column.


CVE-2010-3680


[USN-1119-1] Linux kernel (OMAP4) vulnerabilities

memory ranges on 64bit kernels when allocating memory on behalf of 32bit
system calls. On a 64bit system, a local attacker could perform malicious
multicast getsockopt calls to gain root privileges. (CVE-2010-3081)

Tavis Ormandy discovered that the IRDA subsystem did not correctly shut
down. A local attacker could exploit this to cause the system to crash or
possibly gain root privileges. (CVE-2010-2954)

Brad Spengler discovered that the wireless extensions did not correctly
validate certain request sizes. A local attacker could exploit this to read
portions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)

[USN-710-1] xine-lib vulnerabilities

Details follow:

It was discovered that xine-lib did not correctly handle certain malformed
Ogg and Windows Media files. If a user or automated system were tricked into
opening a specially crafted Ogg or Windows Media file, an attacker could cause
xine-lib to crash, creating a denial of service. This issue only applied to
Ubuntu 6.06 LTS, 7.10, and 8.04 LTS. (CVE-2008-3231)

It was discovered that the MNG, MOD, and Real demuxers in xine-lib did not
correctly handle memory allocation failures. If a user or automated system were
tricked into opening a specially crafted MNG, MOD, or Real file, an attacker

[USN-1073-1] Linux kernel vulnerabilities

Details follow:

Gleb Napatov discovered that KVM did not correctly check certain privileged
operations. A local attacker with access to a guest kernel could exploit
this to crash the host system, leading to a denial of service.
(CVE-2010-0435)

Dan Jacobson discovered that ThinkPad video output was not correctly access
controlled. A local attacker could exploit this to hang the system, leading
to a denial of service. (CVE-2010-3448)

[ MDVSA-2009:283 ] cups

 Problem Description:

 Multiple integer overflows in the JBIG2 decoder in
 Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and
 other products allow remote attackers to cause a denial
 of service (crash) via a crafted PDF file, related to (1)
 JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg,
 and (3) JBIG2Stream::readGenericBitmap. (CVE-2009-0146, CVE-2009-0147)
 
 Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and
 earlier allows remote attackers to cause a denial of service (daemon

[ MDVSA-2010:146 ] libtiff

 Multiple vulnerabilities has been discovered and corrected in libtiff:
 
 The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in
 ImageMagick, does not properly handle invalid ReferenceBlackWhite
 values, which allows remote attackers to cause a denial of service
 (application crash) via a crafted TIFF image that triggers an array
 index error, related to downsampled OJPEG input. (CVE-2010-2595)
 
 Multiple integer overflows in the Fax3SetupState function in tif_fax3.c
 in the FAX3 decoder in LibTIFF before 3.9.3 allow remote attackers to
 execute arbitrary code or cause a denial of service (application crash)

[ MDVSA-2009:282-1 ] cups

 Problem Description:

 Multiple integer overflows in the JBIG2 decoder in
 Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and
 other products allow remote attackers to cause a denial
 of service (crash) via a crafted PDF file, related to (1)
 JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg,
 and (3) JBIG2Stream::readGenericBitmap. (CVE-2009-0146, CVE-2009-0147)
 
 Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and
 earlier allows remote attackers to cause a denial of service (daemon

[ MDVSA-2010:087 ] poppler

 Multiple vulnerabilities has been found and corrected in poppler:
 
 Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2
 and earlier allow remote attackers to cause a denial of service
 (crash) via a crafted PDF file, related to (1) setBitmap and (2)
 readSymbolDictSeg (CVE-2009-0146).
 
 Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and
 earlier allow remote attackers to cause a denial of service (crash)
 via a crafted PDF file (CVE-2009-0147).

[ MDVSA-2009:282 ] cups

 Problem Description:

 Multiple integer overflows in the JBIG2 decoder in
 Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and
 other products allow remote attackers to cause a denial
 of service (crash) via a crafted PDF file, related to (1)
 JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg,
 and (3) JBIG2Stream::readGenericBitmap. (CVE-2009-0146, CVE-2009-0147)
 
 Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and
 earlier allows remote attackers to cause a denial of service (daemon

CORE-2008-0320 - Insufficient argument validation of hooked SSDT functions on multiple Antivirus and Firewalls

"Hooking SSDT functions requires extra caution. SSDT function handlers
are executed in the kernel mode but their callers are executed in the
user mode. Hence all function arguments come from the user mode. This is
why it is necessary to validate these arguments properly. Otherwise a
simple user call can easily crash the whole system. This bug usually
results in a system crash. However, it may happen that this bug is even
more dangerous and may lead to the execution of an arbitrary code in the
privileged kernel mode."

A local DoS attack, despite not being a very sophisticated intrusion

Multiple vulnerabilities in Babo Violent 2 2.08.00

Application:  Babo Violent 2
              http://www.rndlabs.ca
              http://baboviolent.net
Versions:     <= 2.08.00
Platforms:    Windows and Linux
Bugs:         A] crash through malformed value
              B] format string
              C] crash through unexistent map
              D] crash through malformed UDP packet
Exploitation: A, B and C versus server (both dedicated and game)
              D versus both clients and server

[ MDVSA-2010:198 ] kernel

 node that is not part of the kernel node set. (CVE-2010-0415)
 
 The ATI Rage 128 (aka r128) driver in the Linux kernel before
 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE)
 state initialization, which allows local users to cause a denial of
 service (NULL pointer dereference and system crash) or possibly gain
 privileges via unspecified ioctl calls. (CVE-2009-3620)
 
 The wake_futex_pi function in kernel/futex.c in the Linux kernel
 before 2.6.33-rc7 does not properly handle certain unlock operations
 for a Priority Inheritance (PI) futex, which allows local users to

[ MDVSA-2010:188 ] kernel

 node that is not part of the kernel node set. (CVE-2010-0415)
 
 The ATI Rage 128 (aka r128) driver in the Linux kernel before
 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE)
 state initialization, which allows local users to cause a denial of
 service (NULL pointer dereference and system crash) or possibly gain
 privileges via unspecified ioctl calls. (CVE-2009-3620)
 
 The wake_futex_pi function in kernel/futex.c in the Linux kernel
 before 2.6.33-rc7 does not properly handle certain unlock operations
 for a Priority Inheritance (PI) futex, which allows local users to

MITKRB5-SA-2011-002 KDC denial of service attacks [CVE-2011-0281 CVE-2011-0282 CVE-2011-0283]

Exploitability:         High
Remediation Level:      Official Fix
Report Confidence:      Confirmed

CVE-2011-0282: KDC vulnerable to crash when using LDAP back end

CVSSv2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:H/RL:OF/RC:C
CVSSv2 Base Score:      7.8
CVSSv2 Temporal Score:  6.8


[ MDVSA-2011:029 ] kernel

 The blk_rq_map_user_iov function in block/blk-map.c allows local
 users to cause a denial of service (panic) via a zero-length I/O
 request in a device ioctl to a SCSI device. (CVE-2010-4163)
 
 Multiple integer underflows in the x25_parse_facilities function in
 allow remote attackers to cause a denial of service (system crash)
 via malformed X.25 (1) X25_FAC_CLASS_A, (2) X25_FAC_CLASS_B, (3)
 X25_FAC_CLASS_C, or (4) X25_FAC_CLASS_D facility data. (CVE-2010-4164)
 
 Race condition in the do_setlk function allows local users to cause a
 denial of service (crash) via vectors resulting in an interrupted RPC

[USN-1085-1] tiff vulnerabilities

Details follow:

Sauli Pahlman discovered that the TIFF library incorrectly handled invalid
td_stripbytecount fields. If a user or automated system were tricked into
opening a specially crafted TIFF image, a remote attacker could crash the
application, leading to a denial of service. This issue only affected
Ubuntu 10.04 LTS and 10.10. (CVE-2010-2482)

Sauli Pahlman discovered that the TIFF library incorrectly handled TIFF
files with an invalid combination of SamplesPerPixel and Photometric

[USN-1085-2] tiff regression

Original advisory details:

 Sauli Pahlman discovered that the TIFF library incorrectly handled invalid
 td_stripbytecount fields. If a user or automated system were tricked into
 opening a specially crafted TIFF image, a remote attacker could crash the
 application, leading to a denial of service. This issue only affected
 Ubuntu 10.04 LTS and 10.10. (CVE-2010-2482)
 
 Sauli Pahlman discovered that the TIFF library incorrectly handled TIFF
 files with an invalid combination of SamplesPerPixel and Photometric

[ MDVSA-2011:052 ] php

 Multiple vulnerabilities has been identified and fixed in php:
 
 The _zip_name_locate function in zip_name_locate.c in the Zip extension
 in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED
 argument, which might allow context-dependent attackers to cause
 a denial of service (application crash) via an empty ZIP archive
 that is processed with a (1) locateName or (2) statName operation
 (CVE-2011-0421).
 
 exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms
 performs an incorrect cast, which allows remote attackers to cause a

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!