DISPUTED LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tifopen.c, tiflzw.c, and tifaux.c. NOTE: Third parties were unable to reproduce the issue.
A new exploitation technique called key reinstallation attacks used to break Wi-Fi handshakes that negotiate session keys was discovered. These attacks target the Wi-Fi/WPA2 standard. An adversary can trick a vulnerable Access Point (AP) into reinstalling the pairwise key by retransmitted or replayed FT Reassociation Request. While reinstalling the already in-use key, the associated packet number (sometimes also called nonce) and receive replay counter is reset. This causes nonce reuse, voiding any security the underlying encryption protocol is supposed to provide. For example, it allows decryption or injection of frames, and enables an attacker to replay frames.
A flaw was found in the way memory was being allocated on the stack for user space binaries. If heap and stack memory regions were adjacent to each other, an attacker could use this flaw to jump over the heap/stack gap, cause controlled memory corruption on process stack or heap, and thus increase their privileges on the system.
This is a tracking bug for the glibc part of the mitigation.
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
A vulnerability was found in icoutils in extract.c. It is possible to access unallocated memory via wrestool while parsing maliciously crafted file which would make the application crash or possibly allow code execution.
References:
http://seclists.org/oss-sec/2017/q1/56
Upstream patch:
http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=1aa9f28f7bcbdfff6a84a15ac8d9a87559b1596a
An integer overflow vulnerability was found in extract.c while transferring resources into file memory. A maliciously crafted file could make the application crash or possibly allow code execution.
References:
http://seclists.org/oss-sec/2017/q1/56
Upstream patch:
http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=1a108713ac26215c7568353f6e02e727e6d4b24a
An integer overflow vulnerability was found in icoutils in the wrestool program. A maliciously crafted file could make the application crash or possibly allow code execution. This is a CVE for an insufficient patch for CVE-2017-5208.
References:
http://seclists.org/oss-sec/2017/q1/56
Upstream patch:
http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=4fbe9222fd79ee31b7ec031b0be070a9a400d1d3
A use-after-free vulnerability was found in ImageMagick. A maliciously crafted file could cause the application to crash or possibly have other impact.
Upstream bug:
https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=30245
References:
http://seclists.org/oss-sec/2016/q4/758
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/ecc03a2518c2b7dd375fde3a040fdae0bdf6a521
A heap-buffer overflow vulnerability was found in ImageMagick. A maliciously crafted RLE file could cause the application to crash or possibly have other impact.
References:
http://seclists.org/oss-sec/2016/q4/758 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=833744
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/73fb0aac5b958521e1511e179ecc0ad49f70ebaf
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
Incorrect emulation of the SPC700 audio co-processor of the Super Nintendo Entertainment System allows the execution of arbitrary code if a malformed SPC music file is opened.
References:
http://scarybeastsecurity.blogspot.cz/2016/12/redux-compromising-linux-using-snes.html http://seclists.org/oss-sec/2016/q4/682
CVE assignments:
http://seclists.org/oss-sec/2016/q4/692
An assertion failure was possible to trigger in jpcfloorlog2.
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
A number of issues were found in the cryptography practices of EncFS. These are detailed in the following audit:
https://defuse.ca/audits/encfs.htm
It also notes some of the issues in bug 630460 may not be fixed correctly.
A fix is currently not available. Fedora and EPEL use a 1.x version. A future 2.0 release may correct these issues: https://code.google.com/p/encfs/issues/detail?id=186