New User, Welcome!     Login

escape sequence

Nginx, Varnish, Cherokee, thttpd, mini-httpd, WEBrick, Orion, AOLserver, Yaws and Boa log escape sequence injection

Nginx, Varnish, Cherokee, thttpd, mini-httpd, WEBrick, Orion, AOLserver,
Yaws and Boa log escape sequence injection

 Name              Nginx, Varnish, Cherokee, thttpd, mini-httpd,
                   WEBrick, Orion, AOLserver, Yaws and Boa log escape
                   sequence injection
 Systems Affected  nginx 0.7.64
                   Varnish 2.0.6
                   Cherokee 0.99.30
                   mini_httpd 1.19

Jetty 6.x and 7.x Multiple Vulnerabilities

    (Affected versions: Any)

 D) "Session Dump Servlet" stored XSS
    (Affected versions: Any)

 E) "Cookie Dump Servlet" escape sequence injection
    (Affected versions: Any)

 F) Http Content-Length header escape sequence injection
    (Affected versions: Any)


[ MDVSA-2009:005 ] xterm

 Problem Description:

 A vulnerability has been discovered in xterm, which can be exploited
 by malicious people to compromise a user's system. The vulnerability
 is caused due to xterm not properly processing the DECRQSS Device
 Control Request Status String escape sequence. This can be exploited
 to inject and execute arbitrary shell commands by e.g. tricking a
 user into displaying a malicious text file containing a specially
 crafted escape sequence via the more command in xterm (CVE-2008-2383).
 
 The updated packages have been patched to prevent this.

Re: Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

(And try dealing with Microsoft licensing sometime if you think security 
communication is lacking)

Tavis Ormandy wrote:
> Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly
> ----------------------------------------------------------------------------
>
> Help and Support Centre is the default application provided to access online
> documentation for Microsoft Windows. Microsoft supports accessing help documents
> directly via URLs by installing a protocol handler for the scheme "hcp", 

[ GLSA 200812-02 ] enscript: User-assisted execution of arbitrary code

Two stack-based buffer overflows in the read_special_escape() function
in src/psgen.c have been reported. Ulf Harnhammar of Secunia Research
discovered a vulnerability related to the "setfilename" command
(CVE-2008-3863), and Kees Cook of Ubuntu discovered a vulnerability
related to the "font" escape sequence (CVE-2008-4306).

Impact
======

An attacker could entice a user or automated system to process

Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly
----------------------------------------------------------------------------

Help and Support Centre is the default application provided to access online
documentation for Microsoft Windows. Microsoft supports accessing help documents
directly via URLs by installing a protocol handler for the scheme "hcp", 
a typical example is provided in the Windows XP Command Line Reference,
available at http://technet.microsoft.com/en-us/library/bb490918.aspx.

Using hcp:// URLs is intended to be safe, as when invoked via the registered

Re: Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

----- Original Message ----
From: Tavis Ormandy <taviso@cmpxchg8b.com>
To: full-disclosure@lists.grok.org.uk
Cc: bugtraq@securityfocus.com
Sent: Wed, June 9, 2010 4:46:21 PM
Subject: Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly
----------------------------------------------------------------------------

Help and Support Centre is the default application provided to access online

[ MDVSA-2010:017 ] ruby

 WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through
 patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev
 writes data to a log file without sanitizing non-printable characters,
 which might allow remote attackers to modify a window's title,
 or possibly execute arbitrary commands or overwrite files, via an
 HTTP request containing an escape sequence for a terminal emulator
 (CVE-2009-4492).
 
 Packages for 2008.0 are provided for Corporate Desktop 2008.0
 customers.
 

TPTI-09-04: Apple Terminal xterm Resize Escape Sequence Memory Corruption Vulnerability

TPTI-09-04: Apple Terminal xterm Resize Escape Sequence Memory Corruption
Vulnerability
http://dvlabs.tippingpoint.com/advisory/TPTI-09-04
June 2, 2009

-- CVE ID:
CVE-2009-1717

-- Affected Vendors:
Apple



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!