OOBR and OOBW in pcapetheraton() in libpcap
https://seclists.org/tcpdump/2024/q3/3 announced: I hope this finds you well. tcpdump 4.99.5 and libpcap 1.10.5 are now available in the usual places [1]. It has been almost 1.5 years since the previous .4 releases, so this time it is many more bug fixes and improvements than usual. Among other things libpcap 1.10.5 addresses two CVEs that only apply if libpcap was built with the remote packet capture support (which is not the default). [...] 1: https://www.tcpdump.org/release/ https://www.tcpdump.org/index.html#latest-releases further says: This libpcap release makes various improvements and bug fixes available whilst the work on libpcap 1.11 is still in progress. Among other things this includes the fixes to two vulnerabilities (CVE-2023-7256 discovered by Dora Sweet and CVE-2024-8006 discovered by Flavio Toffalini and reported by Nicolas Badoux) in the remote packet capture code, which is disabled by default. -- -Alan Coopersmith- alan.coopersmith () oracle com Oracle Solaris Engineering - https://blogs.oracle.com/solaris
libpcap. Multiple issues were addressed by updating to libpcap version 1.9.1
libpcap. Multiple issues were addressed by updating to libpcap version 1.9.1
libpcap. Multiple issues were addressed by updating to libpcap version 1.9.1
libpcap. Multiple issues were addressed by updating to libpcap version 1.9.1
nselibssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.
Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service.
nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.
The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.
1. ffmpeg/libav out of array write in AMV parsing
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=624339 http://seclists.org/bugtraq/2011/Apr/257 http://git.videolan.org/?p=ffmpeg.git;a=commit;h=89f903b3d5ec38c9c5d90fba7e626fa0eda61a32 Use CVE-2011-1931 2. widelands directory traversal
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=617960 http://bazaar.launchpad.net/~widelands-dev/widelands/build-15/revision/5021 Use CVE-2011-1932 3. SQL injection in Jifty::DBI
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622919 http://lists.jifty.org/pipermail/jifty-devel/2011-April/002426.html Use CVE-2011-1933 4. lilo: lilo-uuid-diskid makes lilo.conf world-readable
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=615103 Use CVE-2011-1934 5. libpcap packet truncation
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=623868 http://thread.gmane.org/gmane.network.tcpdump.devel/5018 Use CVE-2011-1935
Thanks.
-- JB