Security
Apple, iPhones, and encryption
Much of the world appears to be watching—and commenting on—the battle between Apple and the US government over the code running on a particular iPhone. That phone was used by one of the shooters in the San Bernardino terrorist attack in December and its contents are protected by the encryption used by the iOS operating system. There are many facets to the case; its outcome could pose threats to individual privacy as well as the computer industry as a whole. Closer to home, perhaps, is the danger that government overreach could imperil the use and deployment of free software.
The phone in question is an iPhone 5C that was owned by the San Bernardino County Health Department but used by its employee, Syed Rizwan Farook, who was one of the two people who perpetrated the attack. Farook was subsequently killed during a shootout with police, but the phone was recovered. Early on, a mistake was made in the investigation, when the iCloud password for the phone was reset by the Health Department. That prevented the phone from backing up its recent data to the Apple-controlled iCloud site, which would have allowed the company to provide that information to investigators.
That means that there may be useful information stored on the phone itself that did not make it to the iCloud backup. But access to the phone is protected by a four-digit PIN that will unlock the encryption on the device. Because there are only 10,000 possible PINs, brute forcing the phone would seem like a plausible option, but there is a catch. The iOS version that is used on the phone will erase its filesystem key if ten incorrect PINs are entered, which means the flash storage can no longer be decrypted. That auto-erase feature is optional, but it is unknown if it is enabled on the target phone. That set the stage for the US government to ask Apple to create an "update" to iOS that would circumvent the feature.
Updates to iPhones can only be created by Apple because it holds the key needed to sign the code such that the phone will install it. The FBI (or other agencies) could undoubtedly create the code needed, but cannot install it on the phone without the proper signature. So the government first asked Apple to provide such an update and, after the company declined, then has tried to use the courts to compel the company to do so.
There has been a lot of back-and-forth between Apple and the government over the last few weeks as the conflict has largely played out in public. The judge in the case has ordered Apple to assist by providing code that eliminates or bypasses the auto-erase feature of the phone, allows the FBI to submit PINs electronically (rather than enter them via the touchscreen), and gets rid of the delays introduced between PIN entries. Apple is fighting the court order, with a hearing scheduled for March 22.
The government is arguing that the All Writs Act from 1789 applies and that it can use that act to force Apple to comply with the order. Apple strongly disagrees, as its final filing [PDF] that it made before the hearing noted:
The US government has clearly been using the heinous nature of the attack to try to stir up public opinion—and potentially legislative action—against Apple. That has led to calls for Apple boycotts and various types of intemperate posturing by US presidential candidates, state legislators, and the like. Apple has also been trying to sway public opinion, but seems to be fighting an uphill battle at least partly because of the technical nature of the issue. In addition, in today's landscape, terrorism seems to trump privacy at nearly every turn.
While there is a question about how much useful information may reside on the phone, the government seems to be thinking there may be evidence of additional participants in the plot—or perhaps some kind of "dormant cyber pathogen". While that information, if present, might be useful, there are other ways to access at least some of that data. Call records and SMS metadata, for example. Or it may be possible to remove the flash chip to back up its contents and restore it after any failed attempts as Daniel Kahn Gillmor has suggested.
There are a number of concerns that Apple has expressed regarding creating the ordered iOS update. For one thing, if that update falls into the wrong hands, it could lead to widespread decryption of its customers' phones, which is something that the encryption feature is meant to avoid. Beyond that, though, is the likelihood that lots of other law-enforcement agencies will want to use the precedent to force Apple to effectively break the encryption on other phones. A New York prosecutor has already said that there are 175 encrypted phones that he would like access to. The further this code spreads, the more likely it is to fall into the wrong hands.
Apple's resistance has led to renewed calls for mandated backdoors into encryption, of course. There is a persistent and pernicious myth that somehow encryption systems can be made strong enough to resist criminals and others who would like break into them, but still leave a way for legitimate authorities to access the data. It is a kind of magical thinking that is regularly shot down by cryptography and security experts, but still rears its head periodically. When lawmakers can point to the investigation of a horrible crime that is being thwarted by encryption, those calls for a backdoor only increase.
But the truth of that matter is that any kind of backdoor enforced on Apple (and Google, Microsoft, et al.) is only going to lead to those products not being used by terrorists and other criminals. The cryptography cat is out of the bag and no amount of legislation will put it back. Those who want to communicate in ways that cannot be intercepted will find ways to do so.
And that leads us back to free software, which is instrumental in providing freely available strong encryption. Eventually, lawmakers will realize (as agencies like the NSA already have) that free software is a threat to their dream of backdoors. If someone can buy an Android phone, say, and put their own custom firmware on it, they can ensure (within some limits, obviously) that the encryption in that system does not implement the backdoor. When faced with situations like that, lawmakers typically take that next step and ban the "circumvention" mechanism being used.
If events follow this path—and there is certainly a strong possibility that they won't—it could well be a nightmare for the privacy-conscious as well as for free-software developers and advocates. We have already seen signs that device makers may disallow third-party firmware on their devices due to government regulations. That could certainly expand, such that finding "jail breaks" will be needed to put the code of our choice on "our" devices.
The end game in this dystopian scenario would extend that kind of "protection" to more general-purpose computers: laptops, desktops, and servers, for example. That has been a persistent worry over the years with technologies like DRM, UEFI Secure Boot, and remote attestation of running software being seen as having the potential to enforce this kind of control. Even under those conditions, though, one suspects that criminals, at least, would find ways around this kind of draconian, authoritarian regime.
Encryption is simply a tool. It can be used for an enormous number of important and entirely legitimate tasks, but it can also be used by the "bad guys". As many have noted, that is true of many, if not all, tools. Forcing companies to circumvent the features they have added to protect their customers' data will ultimately not be effective, but it also will have many unintended (hopefully) side-effects that make it a dangerous step down a slippery slope. Apple is on the right side of this fight.
Brief items
Security quotes of the week
We're doomed.
Catanzaro: Do you trust this application?
Michael Catanzaro laments the poor level of security provided by free-software applications, focusing on TLS verification issues in particular. "In the case of Shotwell, the issue has been fixed in git, but it might never be released because nobody works on Shotwell anymore. I informed distributors of the Shotwell vulnerability three months ago via the GNOME distributor list, our official mechanism for communicating with distributions, and advised them to update to a git snapshot. Most distributions ignored it. This is completely typical; to my knowledge, the stable releases of all Linux distributions except Fedora are still vulnerable."
New vulnerabilities
bind: multiple vulnerabilities
| Package(s): | bind | CVE #(s): | CVE-2016-1285 CVE-2016-1286 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | March 10, 2016 | Updated: | June 10, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Arch Linux advisory: CVE-2016-1285: Testing by ISC has uncovered a defect in control channel input handling which can cause named to exit due to an assertion failure in sexpr.c or alist.c when a malformed packet is sent to named's control channel (the interface which allows named to be controlled using the 'rndc" server control utility). This assertion occurs before authentication but after network-address-based access controls have been applied. Or in other words: an attacker does not need to have a key or other authentication, but does need to be within the address list specified in the "controls" statement in named.conf which enables the control channel. If no "controls" statement is present in named.conf, named still defaults to listening for control channel information on loopback addresses (127.0.0.1 and ::1) if the file rndc.key is present in the configuration directory and contains a valid key. A search for similar problems revealed an associated defect in the rndc server control utility whereby a malformed response from the server could cause the rndc program to crash. For completeness, it is being fixed at the same time even though this defect in the rndc utility is not in itself exploitable. CVE-2016-1286: An error when parsing signature records for DNAME records having specific properties can lead to named exiting due to an assertion failure in resolver.c or db.c. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
bind: denial of service
| Package(s): | bind | CVE #(s): | CVE-2016-2088 | ||||||||||||||||||||
| Created: | March 11, 2016 | Updated: | March 16, 2016 | ||||||||||||||||||||
| Description: | From the Mageia advisory: In ISC BIND before 9.10.3-P4, A response containing multiple DNS cookies causes servers with cookie support enabled to exit with an assertion failure in resolver.c. | ||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||
chromium: multiple vulnerabilities
| Package(s): | chromium | CVE #(s): | CVE-2016-1643 CVE-2016-1644 CVE-2016-1645 | ||||||||||||||||||||||||||||
| Created: | March 10, 2016 | Updated: | March 21, 2016 | ||||||||||||||||||||||||||||
| Description: | From the Arch Linux advisory: CVE-2016-1643 (type confusion) Type confusion in Blink. CVE-2016-1644 (use-after-free) Use-after-free in Blink. CVE-2016-1645 (out-of-bounds write) Out-of-bounds write in PDFium. | ||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||
chromium: two vulnerabilities
| Package(s): | chromium | CVE #(s): | CVE-2015-6783 CVE-2016-1621 | ||||||||
| Created: | March 14, 2016 | Updated: | March 21, 2016 | ||||||||
| Description: | From the CVE entries:
The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a signature-validation requirement via a crafted ZIP archive. (CVE-2015-6783) libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser.cpp and other files, aka internal bug 23452792. (CVE-2016-1621) | ||||||||||
| Alerts: |
| ||||||||||
community-mysql: multiple vulnerabilities
| Package(s): | community-mysql | CVE #(s): | CVE-2015-4791 CVE-2015-4905 | ||||||||
| Created: | March 10, 2016 | Updated: | March 16, 2016 | ||||||||
| Description: | From the CVE entries: CVE-2015-4791 - Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Privileges. CVE-2015-4905 - Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML. | ||||||||||
| Alerts: |
| ||||||||||
dropbear: information disclosure
| Package(s): | dropbear | CVE #(s): | CVE-2016-3116 | ||||||||||||||||||||||||
| Created: | March 15, 2016 | Updated: | July 20, 2016 | ||||||||||||||||||||||||
| Description: | From the Arch Linux advisory:
A vulnerability was found in a way dropbear processed X11 forwarding input. By using a specially crafted request, an attacker could bypass the authorized_keys command restrictions. xauth is run under the user's privilege, so this vulnerability offers no additional access to unrestricted accounts, but could circumvent key or account restrictions such as sshd_config ForceCommand, authorized_keys command="..." or restricted shells. A remote authenticated user who is able to request X11 forwarding can inject commands leading to information disclosure, directory traversal and possibly other impact. | ||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||
exim: privilege escalation
| Package(s): | exim | CVE #(s): | CVE-2016-1531 | ||||||||||||||||||||||||
| Created: | March 10, 2016 | Updated: | March 16, 2016 | ||||||||||||||||||||||||
| Description: | From the Arch Linux advisory: All installations having Exim set-uid root and using 'perl_startup' are vulnerable to a local privilege escalation. Any user who can start an instance of Exim (and this is normally *any* user) can gain root privileges. | ||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||
ffmpeg: multiple vulnerabilities
| Package(s): | ffmpeg | CVE #(s): | CVE-2013-0861 CVE-2013-0862 CVE-2013-0863 CVE-2013-0864 CVE-2013-0867 CVE-2013-0872 CVE-2013-0873 CVE-2013-0874 CVE-2013-0875 CVE-2013-0876 CVE-2013-0877 CVE-2013-0878 CVE-2013-4263 CVE-2013-4264 CVE-2013-4265 CVE-2013-7008 CVE-2013-7009 CVE-2013-7011 CVE-2013-7012 CVE-2013-7013 CVE-2013-7016 CVE-2013-7017 CVE-2013-7018 CVE-2013-7019 CVE-2013-7021 CVE-2013-7022 CVE-2013-7023 CVE-2013-7024 CVE-2014-8549 CVE-2014-9319 CVE-2014-9602 | ||||
| Created: | March 14, 2016 | Updated: | March 16, 2016 | ||||
| Description: | From the CVE entries:
The avcodec_decode_audio4 function in libavcodec/utils.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 allows remote attackers to trigger memory corruption via vectors related to the channel layout. (CVE-2013-0861) Multiple integer overflows in the process_frame_obj function in libavcodec/sanm.c in FFmpeg before 1.1.2 allow remote attackers to have an unspecified impact via crafted image dimensions in LucasArts Smush video data, which triggers an out-of-bounds array access. (CVE-2013-0862) Buffer overflow in the rle_decode function in libavcodec/sanm.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via crafted LucasArts Smush video data. (CVE-2013-0863) The gif_copy_img_rect function in libavcodec/gifdec.c in FFmpeg before 1.1.2 performs an incorrect calculation for an "end pointer," which allows remote attackers to have an unspecified impact via crafted GIF data that triggers an out-of-bounds array access. (CVE-2013-0864) The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1.2 does not properly check when the pixel format changes, which allows remote attackers to have unspecified impact via crafted H.264 video data, related to an out-of-bounds array access. (CVE-2013-0867) The swr_init function in libswresample/swresample.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid or unsupported (1) input or (2) output channel layout, related to an out-of-bounds array access. (CVE-2013-0872) The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid channel count, related to "freeing invalid addresses." (CVE-2013-0873) The (1) doubles2str and (2) shorts2str functions in libavcodec/tiff.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via a crafted TIFF image, related to an out-of-bounds array access. (CVE-2013-0874) The ff_add_png_paeth_prediction function in libavcodec/pngdec.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via a crafted PNG image, related to an out-of-bounds array access. (CVE-2013-0875) Multiple integer overflows in the (1) old_codec37 and (2) old_codec47 functions in libavcodec/sanm.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via crafted LucasArts Smush data, which triggers an out-of-bounds array access. (CVE-2013-0876) The old_codec37 function in libavcodec/sanm.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted LucasArts Smush data that has a large size when decoded, related to an out-of-bounds array access. (CVE-2013-0877) The advance_line function in libavcodec/targa.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted Targa image data, related to an out-of-bounds array access. (CVE-2013-0878) libavfilter in FFmpeg before 2.0.1 has unspecified impact and remote vectors related to a crafted "plane," which triggers an out-of-bounds heap write. (CVE-2013-4263) The kempf_decode_tile function in libavcodec/g2meet.c in FFmpeg before 2.0.1 allows remote attackers to cause a denial of service (out-of-bounds heap write) via a G2M4 encoded file. (CVE-2013-4264) The av_reallocp_array function in libavutil/mem.c in FFmpeg before 2.0.1 has an unspecified impact and remote vectors related to a "wrong return code" and a resultant NULL pointer dereference. (CVE-2013-4265) The decode_slice_header function in libavcodec/h264.c in FFmpeg before 2.1 incorrectly relies on a certain droppable field, which allows remote attackers to cause a denial of service (deadlock) or possibly have unspecified other impact via crafted H.264 data. (CVE-2013-7008) The rpza_decode_stream function in libavcodec/rpza.c in FFmpeg before 2.1 does not properly maintain a pointer to pixel data, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Apple RPZA data. (CVE-2013-7009) The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not prevent changes to global parameters, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted FFV1 data. (CVE-2013-7011) The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not prevent attempts to use non-zero image offsets, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data. (CVE-2013-7012) The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 uses an incorrect ordering of arithmetic operations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Go2Webinar data. (CVE-2013-7013) The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the expected sample separation, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data. (CVE-2013-7016) libavcodec/jpeg2000.c in FFmpeg before 2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) or possibly have unspecified other impact via crafted JPEG2000 data. (CVE-2013-7017) libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the use of valid code-block dimension values, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data. (CVE-2013-7018) The get_cox function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not properly validate the reduction factor, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data. (CVE-2013-7019) The filter_frame function in libavfilter/vf_fps.c in FFmpeg before 2.1 does not properly ensure the availability of FIFO content, which allows remote attackers to cause a denial of service (double free) or possibly have unspecified other impact via crafted data. (CVE-2013-7021) The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 does not properly allocate memory for tiles, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Go2Webinar data. (CVE-2013-7022) The ff_combine_frame function in libavcodec/parser.c in FFmpeg before 2.1 does not properly handle certain memory-allocation errors, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted data. (CVE-2013-7023) The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not consider the component number in certain calculations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data. (CVE-2013-7024) libavcodec/on2avc.c in FFmpeg before 2.4.2 does not constrain the number of channels to at most 2, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted On2 data. (CVE-2014-8549) The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted .bit file. (CVE-2014-9319) libavcodec/xface.h in FFmpeg before 2.5.2 establishes certain digits and words array dimensions that do not satisfy a required mathematical relationship, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted X-Face image data. (CVE-2014-9602) | ||||||
| Alerts: |
| ||||||
firefox: multiple vulnerabilities
| Package(s): | firefox | CVE #(s): | CVE-2016-1970 CVE-2016-1971 CVE-2016-1972 CVE-2016-1975 CVE-2016-1976 | ||||||||||||||||||||
| Created: | March 10, 2016 | Updated: | March 21, 2016 | ||||||||||||||||||||
| Description: | From the Arch Linux advisory: CVE-2016-1970 CVE-2016-1971 CVE-2016-1972 CVE-2016-1975 CVE-2016-1976: Security researcher Ronald Crane reported five "moderate" rated vulnerabilities affecting released code that were found through code inspection. These included the following issues in WebRTC: an integer underflow, a missing status check, race condition, and a use of deleted pointers to create new object. A race condition in LibVPX was also identified. These do not all have clear mechanisms to be exploited through web content but are vulnerable if a mechanism can be found to trigger them. | ||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||
firefox: use-after-free
| Package(s): | firefox | CVE #(s): | CVE-2016-1979 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | March 10, 2016 | Updated: | May 19, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Mageia advisory: Mozilla developer Tim Taubert used the Address Sanitizer tool and software fuzzing to discover a use-after-free vulnerability while processing DER encoded keys in the Network Security Services (NSS) libraries. The vulnerability overwrites the freed memory with zeroes. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
git: code execution
| Package(s): | git | CVE #(s): | CVE-2016-2315 CVE-2016-2324 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | March 16, 2016 | Updated: | March 24, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the oss-sec posting:
Server and client side remote code execution through a buffer overflow in all git versions before 2.7.1 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
kernel: denial of service
| Package(s): | kernel | CVE #(s): | CVE-2016-2847 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | March 11, 2016 | Updated: | March 16, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Red Hat bug report: On no-so-small systems, it is possible for a single process to cause an OOM condition by filling large pipes with data that are never read. A typical process filling 4096 pipes with 1 MB of data will use 4 GB of memory. On small systems it may be tricky to set the pipe max size to prevent this from happening. The result is an OOM condition and oom-killer is not able to help much, as the memory for the pipe data is a kernel memory and a memory footprint of offensive processes is small. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
kernel: multiple vulnerabilities
| Package(s): | kernel | CVE #(s): | CVE-2016-3134 CVE-2016-3135 CVE-2016-2782 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | March 15, 2016 | Updated: | March 24, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Ubuntu advisory:
Ben Hawkes discovered that the Linux netfilter implementation did not correctly perform validation when handling IPT_SO_SET_REPLACE events. A local unprivileged attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code with administrative privileges. (CVE-2016-3134) Ben Hawkes discovered an integer overflow in the Linux netfilter implementation. On systems running 32 bit kernels, a local unprivileged attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code with administrative privileges. (CVE-2016-3135) Ralf Spenneberg discovered that the USB driver for Treo devices in the Linux kernel did not properly sanity check the endpoints reported by the device. An attacker with physical access could cause a denial of service (system crash). (CVE-2016-2782) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
libmodbus: buffer overflow
| Package(s): | libmodbus | CVE #(s): | |||||||||
| Created: | March 10, 2016 | Updated: | March 16, 2016 | ||||||||
| Description: | From the Fedora advisory: Remote buffer overflow vulnerability on write requests. | ||||||||||
| Alerts: |
| ||||||||||
libotr: code execution
| Package(s): | libotr | CVE #(s): | CVE-2016-2851 | ||||||||||||||||||||||||||||||||||||
| Created: | March 10, 2016 | Updated: | March 21, 2016 | ||||||||||||||||||||||||||||||||||||
| Description: | From the Arch Linux advisory: Versions 4.1.0 and earlier of libotr in 64-bit builds contain an integer overflow security flaw. This flaw could potentially be exploited by a remote attacker to cause a heap buffer overflow and subsequently for arbitrary code to be executed on the user's machine. | ||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||
nss: denial of service
| Package(s): | firefox nss | CVE #(s): | CVE-2016-1978 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | March 14, 2016 | Updated: | March 16, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the CVE entry:
Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
openssh: command injection
| Package(s): | openssh | CVE #(s): | CVE-2016-3115 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | March 11, 2016 | Updated: | April 26, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Mageia advisory: Missing sanitisation of untrusted input allows an authenticated user who is able to request X11 forwarding to inject commands to xauth(1). | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
OpenVPN: multiple vulnerabilities
| Package(s): | OpenVPN | CVE #(s): | |||||
| Created: | March 10, 2016 | Updated: | March 16, 2016 | ||||
| Description: | From the openSUSE advisory: boo#959714: heap overflow on read accessing getaddrinfo result boo#934237: multiple low severity issues | ||||||
| Alerts: |
| ||||||
oracle-jre-bin: code execution
| Package(s): | oracle-jre-bin | CVE #(s): | CVE-2015-7840 | ||||
| Created: | March 14, 2016 | Updated: | March 16, 2016 | ||||
| Description: | From the CVE entry:
The command line management console (CMC) in SolarWinds Log and Event Manager (LEM) before 6.2.0 allows remote attackers to execute arbitrary code via unspecified vectors involving the ping feature. | ||||||
| Alerts: |
| ||||||
php: multiple vulnerabilities
| Package(s): | php | CVE #(s): | |||||||||
| Created: | March 11, 2016 | Updated: | March 16, 2016 | ||||||||
| Description: | From the Mageia advisory: The php package has been updated to version 5.6.19, which fixes several security issues and other bugs. See the upstream ChangeLog for more details. | ||||||||||
| Alerts: |
| ||||||||||
php5: stack overflow
| Package(s): | php5 | CVE #(s): | CVE-2016-2554 | ||||||||||||||||||||||||||||||||||||||||
| Created: | March 10, 2016 | Updated: | March 16, 2016 | ||||||||||||||||||||||||||||||||||||||||
| Description: | From the openSUSE advisory: A stack overflow vulnerability when decompressing tar phar archives was fixed. | ||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||
php-htmLawed: unspecified vulnerability
| Package(s): | php-htmLawed | CVE #(s): | |||||||||
| Created: | March 11, 2016 | Updated: | March 16, 2016 | ||||||||
| Description: | From the Fedora advisory: Version 1.1.21 - Improvement and security fix in transforming 'font' element. | ||||||||||
| Alerts: |
| ||||||||||
php-udan11-sql-parser: multiple vulnerabilities
| Package(s): | php-udan11-sql-parser | CVE #(s): | CVE-2016-2562 CVE-2016-2559 | ||||||||||||||||
| Created: | March 10, 2016 | Updated: | March 16, 2016 | ||||||||||||||||
| Description: | From the CVE entries: CVE-2016-2562 - The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate. CVE-2016-2559 - Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted query. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
pidgin-otr: code execution
| Package(s): | pidgin-otr | CVE #(s): | CVE-2015-8833 | ||||||||||||||||||||||||
| Created: | March 14, 2016 | Updated: | March 24, 2016 | ||||||||||||||||||||||||
| Description: | From the Arch Linux advisory:
The pidgin-otr plugin fixes a heap use after free error. The bug is triggered when a user tries to authenticate a buddy and happens in the function create_smp_dialog. This issue is leading to denial of service or possibly remote code execution. A remote attacker is able to trigger a user-after-free during otr authentication and possibly execute arbitrary code. | ||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||
rails: multiple vulnerabilities
| Package(s): | rails | CVE #(s): | CVE-2016-2097 CVE-2016-2098 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | March 10, 2016 | Updated: | April 26, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Debian advisory: CVE-2016-2097 - Crafted requests to Action View, one of the components of Action Pack, might result in rendering files from arbitrary locations, including files beyond the application's view directory. This vulnerability is the result of an incomplete fix of CVE-2016-0752. CVE-2016-2098 - If a web applications does not properly sanitize user inputs, an attacker might control the arguments of the render method in a controller or a view, resulting in the possibility of executing arbitrary ruby code. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
spip: two vulnerabilities
| Package(s): | spip | CVE #(s): | CVE-2016-3153 CVE-2016-3154 | ||||
| Created: | March 16, 2016 | Updated: | March 16, 2016 | ||||
| Description: | From the Debian advisory:
CVE-2016-3153: g0uZ et sambecks, from team root-me, discovered that arbitrary PHP code could be injected when adding content. CVE-2016-3154: Gilles Vincent discovered that deserializing untrusted content could result in arbitrary objects injection. | ||||||
| Alerts: |
| ||||||
vlc: multiple vulnerabilities
| Package(s): | vlc | CVE #(s): | CVE-2014-1684 CVE-2014-9597 CVE-2014-9598 CVE-2015-1202 CVE-2015-1203 | ||||
| Created: | March 14, 2016 | Updated: | March 16, 2016 | ||||
| Description: | From the CVE entries:
The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Player before 2.1.3 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero minimum and maximum data packet size in an ASF file. (CVE-2014-1684) The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file. (CVE-2014-9597) The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file. (CVE-2014-9598) Unspecified (CVE-2015-1202 and CVE-2015-1203) | ||||||
| Alerts: |
| ||||||
Page editor: Jake Edge
Next page:
Kernel development>>
