Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.
Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeetingloginsert function.
The asn1decodegeneraltime function in lib/krb5/asn.1/asn1decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
A flaw was found in the bash functionality that evaluates specially formatted environment variables passed to it from another environment. An attacker could use this feature to override or bypass restrictions to the environment to execute shell commands before restrictions have been applied. Certain services and applications allow remote unauthenticated attackers to provide environment variables, allowing them to exploit this issue.
Acknowledgements:
Red Hat would like to thank Stephane Chazelas for reporting this issue.
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the modcgi and modcgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.
Jakob Balle and Carsten Eiram of Secunia Research reported a race condition in NPObjWrapperNewResolve when accessing the properties of a NPObject, a wrapped JSObject. Balle and Eiram demonstrated that this condition could be reached by navigating away from a web page during the loading of a Java applet. Under such conditions the Java object would be destroyed but later called into resulting in a free memory read. An attacker could potentially write to the freed memory before it is reused and run arbitrary code on the victim's computer.
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
http://kerneltrap.org/mailarchive/linux-netdev/2010/3/3/6271093/thread "The root cause for this problem is, when the receiver is doing releasesock() (i.e. after userspace recv, kernel udprecvmsg->skbfreedatagramlocked->releasesock), it moves skbs from backlog to skreceivequeue with the softirq enabled. In the above case, multiple busy senders will almost make it an endless loop. The skbs in the backlog end up eat all the system memory.
The issue is not only for UDP. Any protocols using socket backlog is potentially affected. The patch adds limit for socket backlog so that the backlog size cannot be expanded endlessly."
Upstream commits: http://git.kernel.org/linus/2499849ee8f513e795b9f2c19a42d6356e4943a4 http://git.kernel.org/linus/53eecb1be5ae499d399d2923933937a9ea1a284f http://git.kernel.org/linus/50b1a782f845140f4138f14a1ce8a4a6dd0cc82f http://git.kernel.org/linus/79545b681961d7001c1f4c3eb9ffb87bed4485db http://git.kernel.org/linus/55349790d7cbf0d381873a7ece1dcafcffd4aaa9 http://git.kernel.org/linus/6b03a53a5ab7ccf2d5d69f96cf1c739c4d2a8fb9 http://git.kernel.org/linus/8eae939f1400326b06d0c9afe53d2a484a326871 http://git.kernel.org/linus/a3a858ff18a72a8d388e31ab0d98f7e944841a62 http://git.kernel.org/linus/c377411f2494a931ff7facdbb3a6839b1266bcf6
Last updated 24 July 2024
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmapunit value that leads to a buffer overflow.
Multiple buffer overflows in the dissecta11radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and earlier allow remote attackers to execute arbitrary code via RADIUS authentication packets with large length values.
Postfix 2.1.3, when /proc/net/ifinet6 is not available and permitmxbackup is enabled in smtpdrecipientrestrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.
sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.
pamldap in nssldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pamauthenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
Dirk Mueller reported an off by one buffer overflow flaw in the way QT parses certain unicode strings.
To quote Dirk:
Ive found a off-by-one buffer overflow in QUtf8Decoder::toUnicode(). It is not exploitable with Qt 4.x or above because there is an additional QChar(0) being allocated in QString, however it is still a bug there, as the array returned by utf16() etc is no longer terminated properly.
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.
initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors.
Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when using the hugemem kernel, allows local users to read and write to arbitrary kernel memory and gain privileges via certain syscalls.
The bluezsockcreate function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
Multiple drivers in Linux kernel 2.4.19 and earlier do not properly mark memory with the VMIO flag, which causes incorrect reference counts and may lead to a denial of service (kernel panic) when accessing freed kernel pages.
Unspecified vulnerability in the listxattr system call in Linux kernel, when a "bad inode" is present, allows local users to cause a denial of service (data corruption) and possibly gain privileges via unknown vectors.
From Bugzilla Helper: User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.8) Gecko/20050511 Firefox/1.0.4
Description of problem: The following simple reproducer causes a panic on ia64 when run as any user. Due to this I am considering this a security sensitive problem.
This is another situation where bad arguments to setmempolicy causes a system panic. I have verified this on ia64 running the latest kernel however it is likey not a recent regression.
I have not had a chance to dig into the code to narrow down the issue but it is easily reproducable (on ia64 at least, would be interested in seeing if it can be hit elsewhere).
VM: killing process a.out Unable to handle kernel NULL pointer dereference (address 0000000000000000) a.out[7796]: Oops 8847632629764 [1] Modules linked in: nfs lockd nfsacl md5 ipv6 parportpc lp parport autofs4 i2cdev i2ccore sunrpc ds yentasocket pcmciacore scsidump diskdump zlibdeflate vfat fat dmmultipath button ohcihcd ehcihcd e1000 dmsnapshot dmzero dmmirror ext3 jbd dm mod qla2300 qla2xxx lpfc scsitransportfc mptscsih mptsas mptspi mptfc mptscsi mptbase sdmod scsimod
Pid: 7796, CPU 0, comm: a.out psr : 0000101008126010 ifs : 800000000000cc18 ip : [<a00000010024e650>] Not tainted ip is at copyuser+0xb0/0x940 unat: 0000000000000000 pfs : 0000000000000a99 rsc : 0000000000000003 rnat: 0000000000000001 bsps: 0000000000000000 pr : 00000001aa6a0b19 ldrs: 0000000000000000 ccv : 0000000000000000 fpsr: 0009804c0270033f csd : 0000000000000000 ssd : 0000000000000000 b0 : a0000001002fcfe0 b6 : a0000001002f7940 b7 : a0000001002fcc00 f6 : 0ffff8000000000000000 f7 : 000000000000000000000 f8 : 000000000000000000000 f9 : 000000000000000000000 f10 : 000000000000000000000 f11 : 000000000000000000000 r1 : a0000001009adda0 r2 : 0000000000000000 r3 : 00000000000c0221 r8 : 0000000000000000 r9 : ffffffffffffffff r10 : 0000000000000000 r11 : 00000001aa6a0a59 r12 : e00000002c0afd70 r13 : e00000002c0a8000 r14 : e00000002c0afde0 r15 : 0000000000000000 r16 : 0000000000000050 r17 : e00000002c0afde0 r18 : e00000002c0afde1 r19 : 0000000000000000 r20 : e00000002c0afde0 r21 : e00000002c0afdb8 r22 : a0000001006638d0 r23 : a0000001007ae9a8 r24 : e00000002c0afdd0 r25 : e00000002c0afdc8 r26 : 0000000000000000 r27 : 0000001008126010 r28 : 0000000000000000 r29 : 0000000000000000 r30 : 0000000000000008 r31 : 0000000000000a99
Call Trace: [<a000000100016b20>] showstack+0x80/0xa0 sp=e00000002c0af900 bsp=e00000002c0a91e0 [<a000000100017430>] showregs+0x890/0x8c0 sp=e00000002c0afad0 bsp=e00000002c0a9198 [<a00000010003dbb0>] die+0x150/0x240 sp=e00000002c0afaf0 bsp=e00000002c0a9158 [<a000000100061e80>] ia64dopagefault+0x8c0/0xbc0 sp=e00000002c0afaf0 bsp=e00000002c0a90f0 [<a00000010000f540>] ia64leavekernel+0x0/0x260 sp=e00000002c0afba0 bsp=e00000002c0a90f0 [<a00000010024e650>] copyuser+0xb0/0x940 sp=e00000002c0afd70 bsp=e00000002c0a9030 [<a0000001002fcfe0>] writechan+0x3e0/0xc20 sp=e00000002c0afd70 bsp=e00000002c0a8f80 [<a0000001002ed940>] ttywrite+0x440/0x640 sp=e00000002c0afe20 bsp=e00000002c0a8f00 [<a0000001001202d0>] vfswrite+0x290/0x360 sp=e00000002c0afe20 bsp=e00000002c0a8eb0 [<a0000001001204f0>] syswrite+0x70/0xe0 sp=e00000002c0afe20 bsp=e00000002c0a8e38 [<a00000010000f3e0>] ia64retfromsyscall+0x0/0x20 sp=e00000002c0afe30 bsp=e00000002c0a8e38 [<a000000000010640>] 0xa000000000010640 sp=e00000002c0b0000 bsp=e00000002c0a8e38
Version-Release number of selected component (if applicable): kernel-2.6.9-30.EL
How reproducible: Always
Steps to Reproduce: 1. compile the reproducer with cc foo.c -lnuma 2. ./a.out 3. watch smoke fly
Actual Results: panic
Expected Results: no panic!
Additional info:
Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memory space and simultaneously request stack expansion.
Directory traversal vulnerability in the containsdotdot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
Race condition in the (1) loadelflibrary and (2) binfmtaout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.