CVE-2008-3277 – ibutils: insecure relative RPATH
https://notcve.org/view.php?id=CVE-2008-3277
Untrusted search path vulnerability in a certain Red Hat build script for the ibmssh executable in ibutils packages before ibutils-1.5.7-2.el6 in Red Hat Enterprise Linux (RHEL) 6 and ibutils-1.2-11.2.el5 in Red Hat Enterprise Linux (RHEL) 5 allows local users to gain privileges via a Trojan Horse program in refix/lib/, related to an incorrect RPATH setting in the ELF header. Vulnerabilidad de búsqueda de ruta no confiable en cierto build script de Red Hat para el ejecutable ibmssh en paquetes ibutils anterior a ibutils-1.5.7-2.el6 en Red Hat Enterprise Linux (RHEL) 6 y ibutils-1.2-11.2.el5 en Red Hat Enterprise Linux (RHEL) 5 permite a usuarios locales ganar privilegios a través de un programa caballo de troya en refix/lib/, relacionado con una configuración RPATH incorrecta en la cabecera ELF. • http://rhn.redhat.com/errata/RHSA-2012-0311.html https://bugzilla.redhat.com/show_bug.cgi?id=457935 https://access.redhat.com/security/cve/CVE-2008-3277 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2012-0053 – Apache - httpOnly Cookie Disclosure
https://notcve.org/view.php?id=CVE-2012-0053
protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script. protocol.c en Apache HTTP Server v2.2.x hasta la v2.2.21 no limita adecuadamente la información de cabecera durante la construcción de mensajes de error Bad Request (errores 400), lo que permite obtener los valores de las cookies HTTPOnly a atacantes remotos a través de vectores relacionados con una cabecera (1) demasiado larga o (2) mal formada con un script web desarrollado para este fin. • https://www.exploit-db.com/exploits/18442 http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041 http://httpd.apache.org/security/vulnerabilities_22.html http://kb.juniper.net/JSA10585 http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.html http://marc.info/?l=bugtraq&m=133294460209056&w=2 http:// •
CVE-2012-0067 – Wireshark - Buffer Underflow / Denial of Service
https://notcve.org/view.php?id=CVE-2012-0067
wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in an AIX iptrace file. wiretap/iptrace.c de Wireshark 1.4.x anteriores a 1.4.11 y 1.6.x anteriores a 1.6.5 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) a través de un paquete extenso en un archivo AIX iptrace. • https://www.exploit-db.com/exploits/36633 http://anonsvn.wireshark.org/viewvc?view=revision&revision=40167 http://rhn.redhat.com/errata/RHSA-2013-0125.html http://secunia.com/advisories/47494 http://secunia.com/advisories/48947 http://secunia.com/advisories/54425 http://www.gentoo.org/security/en/glsa/glsa-201308-05.xml http://www.openwall.com/lists/oss-security/2012/01/11/7 http://www.openwall.com/lists/oss-security/2012/01/20/4 http://www.wireshark.org/secur • CWE-20: Improper Input Validation CWE-190: Integer Overflow or Wraparound •
CVE-2012-0066 – Wireshark: Dos via large buffer allocation request
https://notcve.org/view.php?id=CVE-2012-0066
Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a (1) Accellent 5Views (aka .5vw) file, (2) I4B trace file, or (3) NETMON 2 capture file. Wireshark v1.4.x anteriores a v1.4.11 y v1.6.x anteriores a v1.6.5 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) a través de un paquete muy grande en un (1) fichero Accellent 5Views (también conocido como .5vw), (2) fichero de traza I4B, o (3) fichero de captura NETMON 2. • http://anonsvn.wireshark.org/viewvc?view=revision&revision=40165 http://anonsvn.wireshark.org/viewvc?view=revision&revision=40166 http://rhn.redhat.com/errata/RHSA-2013-0125.html http://secunia.com/advisories/47494 http://secunia.com/advisories/48947 http://secunia.com/advisories/54425 http://www.gentoo.org/security/en/glsa/glsa-201308-05.xml http://www.openwall.com/lists/oss-security/2012/01/11/7 http://www.openwall.com/lists/oss-security/2012/01/20/4 http://www • CWE-20: Improper Input Validation •
CVE-2012-0041 – wireshark: multiple file parser vulnerabilities (wnpa-sec-2012-01)
https://notcve.org/view.php?id=CVE-2012-0041
The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a capture file, as demonstrated by an airopeek file. La función dissect_packet en epan/packet.c en Wireshark v1.4.x anteriores a v1.4.11 y v1.6.x anterior a v1.6.5 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) a través de de un paquete largo en un fichero de captura, como se demostró con fichero airopeek. • http://anonsvn.wireshark.org/viewvc?view=revision&revision=40164 http://rhn.redhat.com/errata/RHSA-2013-0125.html http://secunia.com/advisories/47494 http://secunia.com/advisories/48947 http://secunia.com/advisories/54425 http://www.gentoo.org/security/en/glsa/glsa-201308-05.xml http://www.openwall.com/lists/oss-security/2012/01/11/7 http://www.openwall.com/lists/oss-security/2012/01/20/4 http://www.wireshark.org/security/wnpa-sec-2012-01.html https://bugs. • CWE-20: Improper Input Validation •