|
|
Log in / Subscribe / Register

Security

Apple, iPhones, and encryption

By Jake Edge
March 16, 2016

Much of the world appears to be watching—and commenting on—the battle between Apple and the US government over the code running on a particular iPhone. That phone was used by one of the shooters in the San Bernardino terrorist attack in December and its contents are protected by the encryption used by the iOS operating system. There are many facets to the case; its outcome could pose threats to individual privacy as well as the computer industry as a whole. Closer to home, perhaps, is the danger that government overreach could imperil the use and deployment of free software.

The phone in question is an iPhone 5C that was owned by the San Bernardino County Health Department but used by its employee, Syed Rizwan Farook, who was one of the two people who perpetrated the attack. Farook was subsequently killed during a shootout with police, but the phone was recovered. Early on, a mistake was made in the investigation, when the iCloud password for the phone was reset by the Health Department. That prevented the phone from backing up its recent data to the Apple-controlled iCloud site, which would have allowed the company to provide that information to investigators.

That means that there may be useful information stored on the phone itself that did not make it to the iCloud backup. But access to the phone is protected by a four-digit PIN that will unlock the encryption on the device. Because there are only 10,000 possible PINs, brute forcing the phone would seem like a plausible option, but there is a catch. The iOS version that is used on the phone will erase its filesystem key if ten incorrect PINs are entered, which means the flash storage can no longer be decrypted. That auto-erase feature is optional, but it is unknown if it is enabled on the target phone. That set the stage for the US government to ask Apple to create an "update" to iOS that would circumvent the feature.

Updates to iPhones can only be created by Apple because it holds the key needed to sign the code such that the phone will install it. The FBI (or other agencies) could undoubtedly create the code needed, but cannot install it on the phone without the proper signature. So the government first asked Apple to provide such an update and, after the company declined, then has tried to use the courts to compel the company to do so.

There has been a lot of back-and-forth between Apple and the government over the last few weeks as the conflict has largely played out in public. The judge in the case has ordered Apple to assist by providing code that eliminates or bypasses the auto-erase feature of the phone, allows the FBI to submit PINs electronically (rather than enter them via the touchscreen), and gets rid of the delays introduced between PIN entries. Apple is fighting the court order, with a hearing scheduled for March 22.

The government is arguing that the All Writs Act from 1789 applies and that it can use that act to force Apple to comply with the order. Apple strongly disagrees, as its final filing [PDF] that it made before the hearing noted:

The government’s position has sweeping implications. Under the government’s view, the state could force an artist to paint a poster, a singer to perform a song, or an author to write a book, so long as its purpose was to achieve some permissible end, whether increasing military enrollment or promoting public health. [...] The First Amendment does not permit such a wholesale derogation of Americans’ right not to speak.

The US government has clearly been using the heinous nature of the attack to try to stir up public opinion—and potentially legislative action—against Apple. That has led to calls for Apple boycotts and various types of intemperate posturing by US presidential candidates, state legislators, and the like. Apple has also been trying to sway public opinion, but seems to be fighting an uphill battle at least partly because of the technical nature of the issue. In addition, in today's landscape, terrorism seems to trump privacy at nearly every turn.

While there is a question about how much useful information may reside on the phone, the government seems to be thinking there may be evidence of additional participants in the plot—or perhaps some kind of "dormant cyber pathogen". While that information, if present, might be useful, there are other ways to access at least some of that data. Call records and SMS metadata, for example. Or it may be possible to remove the flash chip to back up its contents and restore it after any failed attempts as Daniel Kahn Gillmor has suggested.

There are a number of concerns that Apple has expressed regarding creating the ordered iOS update. For one thing, if that update falls into the wrong hands, it could lead to widespread decryption of its customers' phones, which is something that the encryption feature is meant to avoid. Beyond that, though, is the likelihood that lots of other law-enforcement agencies will want to use the precedent to force Apple to effectively break the encryption on other phones. A New York prosecutor has already said that there are 175 encrypted phones that he would like access to. The further this code spreads, the more likely it is to fall into the wrong hands.

Apple's resistance has led to renewed calls for mandated backdoors into encryption, of course. There is a persistent and pernicious myth that somehow encryption systems can be made strong enough to resist criminals and others who would like break into them, but still leave a way for legitimate authorities to access the data. It is a kind of magical thinking that is regularly shot down by cryptography and security experts, but still rears its head periodically. When lawmakers can point to the investigation of a horrible crime that is being thwarted by encryption, those calls for a backdoor only increase.

But the truth of that matter is that any kind of backdoor enforced on Apple (and Google, Microsoft, et al.) is only going to lead to those products not being used by terrorists and other criminals. The cryptography cat is out of the bag and no amount of legislation will put it back. Those who want to communicate in ways that cannot be intercepted will find ways to do so.

And that leads us back to free software, which is instrumental in providing freely available strong encryption. Eventually, lawmakers will realize (as agencies like the NSA already have) that free software is a threat to their dream of backdoors. If someone can buy an Android phone, say, and put their own custom firmware on it, they can ensure (within some limits, obviously) that the encryption in that system does not implement the backdoor. When faced with situations like that, lawmakers typically take that next step and ban the "circumvention" mechanism being used.

If events follow this path—and there is certainly a strong possibility that they won't—it could well be a nightmare for the privacy-conscious as well as for free-software developers and advocates. We have already seen signs that device makers may disallow third-party firmware on their devices due to government regulations. That could certainly expand, such that finding "jail breaks" will be needed to put the code of our choice on "our" devices.

The end game in this dystopian scenario would extend that kind of "protection" to more general-purpose computers: laptops, desktops, and servers, for example. That has been a persistent worry over the years with technologies like DRM, UEFI Secure Boot, and remote attestation of running software being seen as having the potential to enforce this kind of control. Even under those conditions, though, one suspects that criminals, at least, would find ways around this kind of draconian, authoritarian regime.

Encryption is simply a tool. It can be used for an enormous number of important and entirely legitimate tasks, but it can also be used by the "bad guys". As many have noted, that is true of many, if not all, tools. Forcing companies to circumvent the features they have added to protect their customers' data will ultimately not be effective, but it also will have many unintended (hopefully) side-effects that make it a dangerous step down a slippery slope. Apple is on the right side of this fight.

Comments (22 posted)

Brief items

Security quotes of the week

It's basically as bad as it could be - once I'd figured out the gateway, I could access the control systems on every floor and query other rooms to figure out whether the lights were on or not, which strongly implies that I could control them as well. Jesus Molina talked about doing this kind of thing a couple of years ago [PDF], so it's not some kind of one-off - instead, hotels are happily deploying systems with no meaningful security, and the outcome of sending a constant stream of "Set room lights to full" and "Open curtain" commands at 3AM seems fairly predictable.

We're doomed.

Matthew Garrett stays in an Android-powered hotel room

LinkNYC, which was publicly launched in January, will eventually become a network of as many as 7,500 to 10,000 public kiosks offering fast and free Wi-Fi throughout all five boroughs. The sheer volume of information gathered by this powerful network will create a massive database of information that will present attractive opportunities for hackers and for law enforcement surveillance, and will carry an undue risk of abuse, misuse and unauthorized access.
New York Civil Liberties Union

If you're developing a messaging system that relies on a centralized, trusted key server, now is the time to rethink that design.
Matthew Green

I think the Justice Department and the FBI are on their own here. You know, the secretary of defense has said how important encryption is when asked about this case. The National Security Agency director and three past National Security Agency directors, a former CIA director, a former Homeland Security secretary have all said that they're much more sympathetic with Apple in this case. You really have to understand that the FBI director is exaggerating the need for this and is trying to build it up as an emotional case, organizing the families of the victims and all of that.
Richard Clarke, former US national security official

Comments (1 posted)

Catanzaro: Do you trust this application?

Michael Catanzaro laments the poor level of security provided by free-software applications, focusing on TLS verification issues in particular. "In the case of Shotwell, the issue has been fixed in git, but it might never be released because nobody works on Shotwell anymore. I informed distributors of the Shotwell vulnerability three months ago via the GNOME distributor list, our official mechanism for communicating with distributions, and advised them to update to a git snapshot. Most distributions ignored it. This is completely typical; to my knowledge, the stable releases of all Linux distributions except Fedora are still vulnerable."

Comments (85 posted)

New vulnerabilities

bind: multiple vulnerabilities

Package(s):bind CVE #(s):CVE-2016-1285 CVE-2016-1286
Created:March 10, 2016 Updated:June 10, 2016
Description:

From the Arch Linux advisory:

CVE-2016-1285: Testing by ISC has uncovered a defect in control channel input handling which can cause named to exit due to an assertion failure in sexpr.c or alist.c when a malformed packet is sent to named's control channel (the interface which allows named to be controlled using the 'rndc" server control utility).

This assertion occurs before authentication but after network-address-based access controls have been applied. Or in other words: an attacker does not need to have a key or other authentication, but does need to be within the address list specified in the "controls" statement in named.conf which enables the control channel. If no "controls" statement is present in named.conf, named still defaults to listening for control channel information on loopback addresses (127.0.0.1 and ::1) if the file rndc.key is present in the configuration directory and contains a valid key.

A search for similar problems revealed an associated defect in the rndc server control utility whereby a malformed response from the server could cause the rndc program to crash. For completeness, it is being fixed at the same time even though this defect in the rndc utility is not in itself exploitable.

CVE-2016-1286: An error when parsing signature records for DNAME records having specific properties can lead to named exiting due to an assertion failure in resolver.c or db.c.

Alerts:
Oracle ELSA-2016-2094 bind97 2016-10-21
Oracle ELSA-2016-2093 bind 2016-10-21
Gentoo 201610-07 bind 2016-10-11
SUSE SUSE-SU-2016:1541-1 bind 2016-06-10
Red Hat RHSA-2016:0601-01 bind 2016-04-06
Fedora FEDORA-2016-161b73fc2c bind99 2016-04-02
Fedora FEDORA-2016-364c0a9df4 bind 2016-04-02
Red Hat RHSA-2016:0562-01 bind 2016-03-31
openSUSE openSUSE-SU-2016:0859-1 bind 2016-03-23
SUSE SUSE-SU-2016:0825-1 bind 2016-03-18
openSUSE openSUSE-SU-2016:0830-1 bind 2016-03-19
openSUSE openSUSE-SU-2016:0827-1 bind 2016-03-19
openSUSE openSUSE-SU-2016:0834-1 bind 2016-03-19
Scientific Linux SLSA-2016:0459-1 bind 2016-03-16
Oracle ELSA-2016-0458 bind97 2016-03-16
Oracle ELSA-2016-0459 bind 2016-03-16
Oracle ELSA-2016-0459 bind 2016-03-16
Oracle ELSA-2016-0459 bind 2016-03-16
CentOS CESA-2016:0458 bind97 2016-03-16
CentOS CESA-2016:0459 bind 2016-03-16
CentOS CESA-2016:0459 bind 2016-03-16
CentOS CESA-2016:0459 bind 2016-03-16
Red Hat RHSA-2016:0458-01 bind97 2016-03-16
Red Hat RHSA-2016:0459-01 bind 2016-03-16
SUSE SUSE-SU-2016:0780-1 bind 2016-03-15
Fedora FEDORA-2016-5047abe4a9 bind99 2016-03-16
SUSE SUSE-SU-2016:0759-1 bind 2016-03-14
Fedora FEDORA-2016-b593e84223 bind 2016-03-13
Arch Linux ASA-201603-13 bind 2016-03-12
Mageia MGASA-2016-0107 bind 2016-03-11
Ubuntu USN-2925-1 bind9 2016-03-09
Slackware SSA:2016-069-01 bind 2016-03-09
Debian DSA-3511-1 bind9 2016-03-09
Arch Linux ASA-201603-7 bind 2016-03-10

Comments (none posted)

bind: denial of service

Package(s):bind CVE #(s):CVE-2016-2088
Created:March 11, 2016 Updated:March 16, 2016
Description:

From the Mageia advisory:

In ISC BIND before 9.10.3-P4, A response containing multiple DNS cookies causes servers with cookie support enabled to exit with an assertion failure in resolver.c.

Alerts:
Gentoo 201610-07 bind 2016-10-11
Fedora FEDORA-2016-364c0a9df4 bind 2016-04-02
Fedora FEDORA-2016-b593e84223 bind 2016-03-13
Arch Linux ASA-201603-13 bind 2016-03-12
Mageia MGASA-2016-0107 bind 2016-03-11

Comments (none posted)

chromium: multiple vulnerabilities

Package(s):chromium CVE #(s):CVE-2016-1643 CVE-2016-1644 CVE-2016-1645
Created:March 10, 2016 Updated:March 21, 2016
Description:

From the Arch Linux advisory:

CVE-2016-1643 (type confusion) Type confusion in Blink.

CVE-2016-1644 (use-after-free) Use-after-free in Blink.

CVE-2016-1645 (out-of-bounds write) Out-of-bounds write in PDFium.

Alerts:
Mageia MGASA-2016-0127 chromium-browser-stable 2016-03-31
openSUSE openSUSE-SU-2016:0828-1 Chromium 2016-03-19
openSUSE openSUSE-SU-2016:0818-1 Chromium 2016-03-18
openSUSE openSUSE-SU-2016:0817-1 Chromium 2016-03-18
Red Hat RHSA-2016:0429-01 chromium-browser 2016-03-10
Debian DSA-3513-1 chromium-browser 2016-03-10
Arch Linux ASA-201603-5 chromium 2016-03-09

Comments (none posted)

chromium: two vulnerabilities

Package(s):chromium CVE #(s):CVE-2015-6783 CVE-2016-1621
Created:March 14, 2016 Updated:March 21, 2016
Description: From the CVE entries:

The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a signature-validation requirement via a crafted ZIP archive. (CVE-2015-6783)

libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser.cpp and other files, aka internal bug 23452792. (CVE-2016-1621)

Alerts:
Fedora FEDORA-2016-fae59061fe libvpx 2016-03-21
Gentoo 201603-09 chromium 2016-03-12

Comments (none posted)

community-mysql: multiple vulnerabilities

Package(s):community-mysql CVE #(s):CVE-2015-4791 CVE-2015-4905
Created:March 10, 2016 Updated:March 16, 2016
Description:

From the CVE entries:

CVE-2015-4791 - Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Privileges.

CVE-2015-4905 - Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML.

Alerts:
Fedora FEDORA-2016-65a1f22818 community-mysql 2016-03-09
Fedora FEDORA-2016-5cb344dd7e community-mysql 2016-03-09

Comments (none posted)

dropbear: information disclosure

Package(s):dropbear CVE #(s):CVE-2016-3116
Created:March 15, 2016 Updated:July 20, 2016
Description: From the Arch Linux advisory:

A vulnerability was found in a way dropbear processed X11 forwarding input. By using a specially crafted request, an attacker could bypass the authorized_keys command restrictions.

xauth is run under the user's privilege, so this vulnerability offers no additional access to unrestricted accounts, but could circumvent key or account restrictions such as sshd_config ForceCommand, authorized_keys command="..." or restricted shells.

A remote authenticated user who is able to request X11 forwarding can inject commands leading to information disclosure, directory traversal and possibly other impact.

Alerts:
Gentoo 201607-08 dropbear 2016-07-20
openSUSE openSUSE-SU-2016:0882-1 dropbear 2016-03-24
Fedora FEDORA-2016-332491de28 dropbear 2016-03-23
Fedora FEDORA-2016-40a657cee1 dropbear 2016-03-24
Mageia MGASA-2016-0113 dropbear 2016-03-16
Arch Linux ASA-201603-19 dropbear 2016-03-14

Comments (none posted)

exim: privilege escalation

Package(s):exim CVE #(s):CVE-2016-1531
Created:March 10, 2016 Updated:March 16, 2016
Description:

From the Arch Linux advisory:

All installations having Exim set-uid root and using 'perl_startup' are vulnerable to a local privilege escalation. Any user who can start an instance of Exim (and this is normally *any* user) can gain root privileges.

Alerts:
Ubuntu USN-2933-1 exim4 2016-03-15
Fedora FEDORA-2016-0e3ca94d88 exim 2016-03-13
Fedora FEDORA-2016-e062971917 exim 2016-03-12
Debian DSA-3517-1 exim4 2016-03-14
openSUSE openSUSE-SU-2016:0721-1 exim 2016-03-11
Arch Linux ASA-201603-8 exim 2016-03-10

Comments (none posted)

ffmpeg: multiple vulnerabilities

Package(s):ffmpeg CVE #(s):CVE-2013-0861 CVE-2013-0862 CVE-2013-0863 CVE-2013-0864 CVE-2013-0867 CVE-2013-0872 CVE-2013-0873 CVE-2013-0874 CVE-2013-0875 CVE-2013-0876 CVE-2013-0877 CVE-2013-0878 CVE-2013-4263 CVE-2013-4264 CVE-2013-4265 CVE-2013-7008 CVE-2013-7009 CVE-2013-7011 CVE-2013-7012 CVE-2013-7013 CVE-2013-7016 CVE-2013-7017 CVE-2013-7018 CVE-2013-7019 CVE-2013-7021 CVE-2013-7022 CVE-2013-7023 CVE-2013-7024 CVE-2014-8549 CVE-2014-9319 CVE-2014-9602
Created:March 14, 2016 Updated:March 16, 2016
Description: From the CVE entries:

The avcodec_decode_audio4 function in libavcodec/utils.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 allows remote attackers to trigger memory corruption via vectors related to the channel layout. (CVE-2013-0861)

Multiple integer overflows in the process_frame_obj function in libavcodec/sanm.c in FFmpeg before 1.1.2 allow remote attackers to have an unspecified impact via crafted image dimensions in LucasArts Smush video data, which triggers an out-of-bounds array access. (CVE-2013-0862)

Buffer overflow in the rle_decode function in libavcodec/sanm.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via crafted LucasArts Smush video data. (CVE-2013-0863)

The gif_copy_img_rect function in libavcodec/gifdec.c in FFmpeg before 1.1.2 performs an incorrect calculation for an "end pointer," which allows remote attackers to have an unspecified impact via crafted GIF data that triggers an out-of-bounds array access. (CVE-2013-0864)

The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1.2 does not properly check when the pixel format changes, which allows remote attackers to have unspecified impact via crafted H.264 video data, related to an out-of-bounds array access. (CVE-2013-0867)

The swr_init function in libswresample/swresample.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid or unsupported (1) input or (2) output channel layout, related to an out-of-bounds array access. (CVE-2013-0872)

The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid channel count, related to "freeing invalid addresses." (CVE-2013-0873)

The (1) doubles2str and (2) shorts2str functions in libavcodec/tiff.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via a crafted TIFF image, related to an out-of-bounds array access. (CVE-2013-0874)

The ff_add_png_paeth_prediction function in libavcodec/pngdec.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via a crafted PNG image, related to an out-of-bounds array access. (CVE-2013-0875)

Multiple integer overflows in the (1) old_codec37 and (2) old_codec47 functions in libavcodec/sanm.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via crafted LucasArts Smush data, which triggers an out-of-bounds array access. (CVE-2013-0876)

The old_codec37 function in libavcodec/sanm.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted LucasArts Smush data that has a large size when decoded, related to an out-of-bounds array access. (CVE-2013-0877)

The advance_line function in libavcodec/targa.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted Targa image data, related to an out-of-bounds array access. (CVE-2013-0878)

libavfilter in FFmpeg before 2.0.1 has unspecified impact and remote vectors related to a crafted "plane," which triggers an out-of-bounds heap write. (CVE-2013-4263)

The kempf_decode_tile function in libavcodec/g2meet.c in FFmpeg before 2.0.1 allows remote attackers to cause a denial of service (out-of-bounds heap write) via a G2M4 encoded file. (CVE-2013-4264)

The av_reallocp_array function in libavutil/mem.c in FFmpeg before 2.0.1 has an unspecified impact and remote vectors related to a "wrong return code" and a resultant NULL pointer dereference. (CVE-2013-4265)

The decode_slice_header function in libavcodec/h264.c in FFmpeg before 2.1 incorrectly relies on a certain droppable field, which allows remote attackers to cause a denial of service (deadlock) or possibly have unspecified other impact via crafted H.264 data. (CVE-2013-7008)

The rpza_decode_stream function in libavcodec/rpza.c in FFmpeg before 2.1 does not properly maintain a pointer to pixel data, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Apple RPZA data. (CVE-2013-7009)

The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not prevent changes to global parameters, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted FFV1 data. (CVE-2013-7011)

The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not prevent attempts to use non-zero image offsets, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data. (CVE-2013-7012)

The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 uses an incorrect ordering of arithmetic operations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Go2Webinar data. (CVE-2013-7013)

The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the expected sample separation, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data. (CVE-2013-7016)

libavcodec/jpeg2000.c in FFmpeg before 2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) or possibly have unspecified other impact via crafted JPEG2000 data. (CVE-2013-7017)

libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the use of valid code-block dimension values, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data. (CVE-2013-7018)

The get_cox function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not properly validate the reduction factor, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data. (CVE-2013-7019)

The filter_frame function in libavfilter/vf_fps.c in FFmpeg before 2.1 does not properly ensure the availability of FIFO content, which allows remote attackers to cause a denial of service (double free) or possibly have unspecified other impact via crafted data. (CVE-2013-7021)

The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 does not properly allocate memory for tiles, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Go2Webinar data. (CVE-2013-7022)

The ff_combine_frame function in libavcodec/parser.c in FFmpeg before 2.1 does not properly handle certain memory-allocation errors, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted data. (CVE-2013-7023)

The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not consider the component number in certain calculations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data. (CVE-2013-7024)

libavcodec/on2avc.c in FFmpeg before 2.4.2 does not constrain the number of channels to at most 2, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted On2 data. (CVE-2014-8549)

The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted .bit file. (CVE-2014-9319)

libavcodec/xface.h in FFmpeg before 2.5.2 establishes certain digits and words array dimensions that do not satisfy a required mathematical relationship, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted X-Face image data. (CVE-2014-9602)

Alerts:
Gentoo 201603-06 ffmpeg 2016-03-12

Comments (none posted)

firefox: multiple vulnerabilities

Package(s):firefox CVE #(s):CVE-2016-1970 CVE-2016-1971 CVE-2016-1972 CVE-2016-1975 CVE-2016-1976
Created:March 10, 2016 Updated:March 21, 2016
Description:

From the Arch Linux advisory:

CVE-2016-1970 CVE-2016-1971 CVE-2016-1972 CVE-2016-1975 CVE-2016-1976: Security researcher Ronald Crane reported five "moderate" rated vulnerabilities affecting released code that were found through code inspection. These included the following issues in WebRTC: an integer underflow, a missing status check, race condition, and a use of deleted pointers to create new object. A race condition in LibVPX was also identified. These do not all have clear mechanisms to be exploited through web content but are vulnerable if a mechanism can be found to trigger them.

Alerts:
Gentoo 201605-06 nss 2016-05-31
Fedora FEDORA-2016-9e3ff0938c firefox 2016-03-20
openSUSE openSUSE-SU-2016:0731-1 firefox nss nspr 2016-03-12
openSUSE openSUSE-SU-2016:0733-1 Firefox 2016-03-12
Arch Linux ASA-201603-4 firefox 2016-03-09

Comments (none posted)

firefox: use-after-free

Package(s):firefox CVE #(s):CVE-2016-1979
Created:March 10, 2016 Updated:May 19, 2016
Description:

From the Mageia advisory:

Mozilla developer Tim Taubert used the Address Sanitizer tool and software fuzzing to discover a use-after-free vulnerability while processing DER encoded keys in the Network Security Services (NSS) libraries. The vulnerability overwrites the freed memory with zeroes.

Alerts:
Debian DSA-3688-1 nss 2016-10-05
Gentoo 201605-06 nss 2016-05-31
Ubuntu USN-2973-1 thunderbird 2016-05-19
Debian-LTS DLA-480-1 nss 2016-05-18
Debian-LTS DLA-472-2 icedove 2016-05-18
Debian-LTS DLA-472-1 icedove 2016-05-14
Debian DSA-3576-1 icedove 2016-05-13
Scientific Linux SLSA-2016:0685-1 nss, nspr, nss-softokn, nss-util 2016-04-25
Oracle ELSA-2016-0685 nss, nspr, nss-softokn, and nss-util 2016-04-25
Oracle ELSA-2016-0684 nss and nspr 2016-04-25
CentOS CESA-2016:0685 nss-util 2016-04-25
CentOS CESA-2016:0685 nss-softokn 2016-04-25
CentOS CESA-2016:0685 nss 2016-04-25
CentOS CESA-2016:0685 nspr 2016-04-25
CentOS CESA-2016:0684 nss 2016-04-25
CentOS CESA-2016:0684 nspr 2016-04-25
Scientific Linux SLSA-2016:0684-1 nss, nspr 2016-04-25
Red Hat RHSA-2016:0685-01 nss, nspr, nss-softokn, nss-util 2016-04-25
Red Hat RHSA-2016:0684-01 nss, nspr 2016-04-25
Scientific Linux SLSA-2016:0591-1 nss, nss-util, nspr 2016-04-05
CentOS CESA-2016:0591 nss-util 2016-04-05
CentOS CESA-2016:0591 nss 2016-04-05
CentOS CESA-2016:0591 nspr 2016-04-05
Red Hat RHSA-2016:0591-01 nss, nss-util, nspr 2016-04-05
SUSE SUSE-SU-2016:0909-1 firefox, nspr, nss 2016-03-30
SUSE SUSE-SU-2016:0820-1 firefox 2016-03-18
SUSE SUSE-SU-2016:0777-1 firefox nspr nss 2016-03-15
SUSE SUSE-SU-2016:0727-1 firefox, nspr, nss 2016-03-11
openSUSE openSUSE-SU-2016:0731-1 firefox nss nspr 2016-03-12
openSUSE openSUSE-SU-2016:0733-1 Firefox 2016-03-12
Slackware SSA:2016-069-02 mozilla-nss 2016-03-09
Mageia MGASA-2016-0105 firefox 2016-03-09

Comments (none posted)

git: code execution

Package(s):git CVE #(s):CVE-2016-2315 CVE-2016-2324
Created:March 16, 2016 Updated:March 24, 2016
Description: From the oss-sec posting:

Server and client side remote code execution through a buffer overflow in all git versions before 2.7.1

Alerts:
Gentoo 201605-01 git 2016-05-02
openSUSE openSUSE-SU-2016:0958-1 git 2016-04-05
Fedora FEDORA-2016-cee7647200 git 2016-03-30
Mageia MGASA-2016-0119 git 2016-03-25
Oracle ELSA-2016-0496 git 2016-03-23
Oracle ELSA-2016-0496 git 2016-03-23
CentOS CESA-2016:0496 git 2016-03-23
CentOS CESA-2016:0496 git 2016-03-23
Scientific Linux SLSA-2016:0496-1 git 2016-03-23
Red Hat RHSA-2016:0497-01 git19-git 2016-03-23
Red Hat RHSA-2016:0496-01 git 2016-03-23
Ubuntu USN-2938-1 git 2016-03-21
openSUSE openSUSE-SU-2016:0826-1 git 2016-03-19
openSUSE openSUSE-SU-2016:0832-1 git 2016-03-19
openSUSE openSUSE-SU-2016:0831-1 cgit 2016-03-19
openSUSE openSUSE-SU-2016:0829-1 cgit 2016-03-19
Fedora FEDORA-2016-6554eff611 git 2016-03-21
Debian DSA-3521-1 git 2016-03-19
Arch Linux ASA-201603-20 git 2016-03-20
SUSE SUSE-SU-2016:0798-1 git 2016-03-17
SUSE SUSE-SU-2016:0796-1 git 2016-03-16
openSUSE openSUSE-SU-2016:0802-1 git 2016-03-17
openSUSE openSUSE-SU-2016:0803-1 cgit 2016-03-17
Slackware SSA:2016-075-01 git 2016-03-15

Comments (none posted)

kernel: denial of service

Package(s):kernel CVE #(s):CVE-2016-2847
Created:March 11, 2016 Updated:March 16, 2016
Description:

From the Red Hat bug report:

On no-so-small systems, it is possible for a single process to cause an OOM condition by filling large pipes with data that are never read. A typical process filling 4096 pipes with 1 MB of data will use 4 GB of memory. On small systems it may be tricky to set the pipe max size to prevent this from happening. The result is an OOM condition and oom-killer is not able to help much, as the memory for the pipe data is a kernel memory and a memory footprint of offensive processes is small.

Alerts:
Oracle ELSA-2016-2574 kernel 2016-11-10
Red Hat RHSA-2016:2584-02 kernel-rt 2016-11-03
Red Hat RHSA-2016:2574-02 kernel 2016-11-03
openSUSE openSUSE-SU-2016:2649-1 kernel 2016-10-26
openSUSE openSUSE-SU-2016:2290-1 kernel 2016-09-12
Oracle ELSA-2016-3596 kernel 4.1.12 2016-08-26
Oracle ELSA-2016-3596 kernel 4.1.12 2016-08-26
openSUSE openSUSE-SU-2016:2144-1 kernel 2016-08-24
SUSE SUSE-SU-2016:2074-1 kernel 2016-08-15
SUSE SUSE-SU-2016:1937-1 kernel 2016-08-02
Red Hat RHSA-2017:0217-01 kernel 2017-01-31
SUSE SUSE-SU-2016:1707-1 the Linux Kernel 2016-06-30
SUSE SUSE-SU-2016:1690-1 kernel 2016-06-27
SUSE SUSE-SU-2016:1696-1 kernel 2016-06-28
SUSE SUSE-SU-2016:1672-1 the Linux Kernel 2016-06-24
openSUSE openSUSE-SU-2016:1382-1 kernel 2016-05-23
Ubuntu USN-2967-2 linux-ti-omap4 2016-05-09
Ubuntu USN-2967-1 kernel 2016-05-09
Ubuntu USN-2965-2 linux-lts-xenial 2016-05-06
SUSE SUSE-SU-2016:1203-1 kernel 2016-05-03
Scientific Linux SLSA-2016:2574-2 kernel 2016-12-14
Ubuntu USN-2948-2 linux-lts-utopic 2016-04-11
Ubuntu USN-2947-3 linux-raspi2 2016-04-06
Ubuntu USN-2947-2 linux-lts-wily 2016-04-06
Ubuntu USN-2949-1 linux-lts-vivid 2016-04-06
Ubuntu USN-2948-1 linux-lts-utopic 2016-04-06
Ubuntu USN-2946-2 linux-lts-trusty 2016-04-06
Ubuntu USN-2946-1 kernel 2016-04-06
Ubuntu USN-2947-1 kernel 2016-04-06
Fedora FEDORA-2016-746bb5851d kernel 2016-03-12
Fedora FEDORA-2016-e6cfaff4b1 kernel 2016-03-11

Comments (none posted)

kernel: multiple vulnerabilities

Package(s):kernel CVE #(s):CVE-2016-3134 CVE-2016-3135 CVE-2016-2782
Created:March 15, 2016 Updated:March 24, 2016
Description: From the Ubuntu advisory:

Ben Hawkes discovered that the Linux netfilter implementation did not correctly perform validation when handling IPT_SO_SET_REPLACE events. A local unprivileged attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code with administrative privileges. (CVE-2016-3134)

Ben Hawkes discovered an integer overflow in the Linux netfilter implementation. On systems running 32 bit kernels, a local unprivileged attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code with administrative privileges. (CVE-2016-3135)

Ralf Spenneberg discovered that the USB driver for Treo devices in the Linux kernel did not properly sanity check the endpoints reported by the device. An attacker with physical access could cause a denial of service (system crash). (CVE-2016-2782)

Alerts:
Oracle ELSA-2016-2574 kernel 2016-11-10
openSUSE openSUSE-SU-2016:2649-1 kernel 2016-10-26
Oracle ELSA-2016-3624 kernel 2.6.39 2016-10-06
Oracle ELSA-2016-3624 kernel 2.6.39 2016-10-06
Oracle ELSA-2016-3623 kernel 3.8.13 2016-10-06
Oracle ELSA-2016-3623 kernel 3.8.13 2016-10-06
Oracle ELSA-2016-3625 kernel 4.1.12 2016-10-06
Oracle ELSA-2016-3625 kernel 4.1.12 2016-10-06
CentOS CESA-2016:1847 kernel 2016-09-19
Scientific Linux SLSA-2016:1847-1 kernel 2016-09-15
Oracle ELSA-2016-1847 kernel 2016-09-14
Red Hat RHSA-2016:1875-01 kernel-rt 2016-09-15
Red Hat RHSA-2016:1883-01 kernel-rt 2016-09-15
Red Hat RHSA-2016:1847-01 kernel 2016-09-15
openSUSE openSUSE-SU-2016:2290-1 kernel 2016-09-12
SUSE SUSE-SU-2016:2245-1 kernel 2016-09-06
openSUSE openSUSE-SU-2016:2144-1 kernel 2016-08-24
SUSE SUSE-SU-2016:2074-1 kernel 2016-08-15
Ubuntu USN-3050-1 linux-ti-omap4 2016-08-10
Ubuntu USN-3057-1 linux-snapdragon 2016-08-10
Ubuntu USN-3056-1 linux-raspi2 2016-08-10
Ubuntu USN-3054-1 linux-lts-xenial 2016-08-10
Ubuntu USN-3049-1 kernel 2016-08-10
Ubuntu USN-3055-1 kernel 2016-08-10
SUSE SUSE-SU-2016:1985-1 kernel 2016-08-08
SUSE SUSE-SU-2016:1961-1 kernel 2016-08-04
SUSE SUSE-SU-2016:1764-1 kernel 2016-07-08
SUSE SUSE-SU-2016:1707-1 the Linux Kernel 2016-06-30
SUSE SUSE-SU-2016:1690-1 kernel 2016-06-27
SUSE SUSE-SU-2016:1696-1 kernel 2016-06-28
Debian DSA-3607-1 kernel 2016-06-28
SUSE SUSE-SU-2016:1672-1 the Linux Kernel 2016-06-24
openSUSE openSUSE-SU-2016:1641-1 kernel 2016-06-21
Debian-LTS DLA-516-1 kernel 2016-06-17
Ubuntu USN-2967-2 linux-ti-omap4 2016-05-09
Ubuntu USN-2967-1 kernel 2016-05-09
SUSE SUSE-SU-2016:1203-1 kernel 2016-05-03
SUSE SUSE-SU-2016:1019-1 kernel 2016-04-12
Ubuntu USN-2948-2 linux-lts-utopic 2016-04-11
Ubuntu USN-2948-1 linux-lts-utopic 2016-04-06
Fedora FEDORA-2016-02ed08bf15 kernel 2016-03-23
Fedora FEDORA-2016-3a57b19360 kernel 2016-03-24
Ubuntu USN-2930-3 linux-raspi2 2016-03-16
Ubuntu USN-2930-2 linux-lts-wily 2016-03-14
Ubuntu USN-2932-1 linux-lts-vivid 2016-03-14
Ubuntu USN-2931-1 linux-lts-utopic 2016-03-14
Ubuntu USN-2929-2 linux-lts-trusty 2016-03-14
Ubuntu USN-2929-1 kernel 2016-03-14
Ubuntu USN-2930-1 kernel 2016-03-14

Comments (none posted)

libmodbus: buffer overflow

Package(s):libmodbus CVE #(s):
Created:March 10, 2016 Updated:March 16, 2016
Description:

From the Fedora advisory:

Remote buffer overflow vulnerability on write requests.

Alerts:
Fedora FEDORA-2016-ae14784e4e libmodbus 2016-03-09
Fedora FEDORA-2016-ffffab2aa9 libmodbus 2016-03-09

Comments (none posted)

libotr: code execution

Package(s):libotr CVE #(s):CVE-2016-2851
Created:March 10, 2016 Updated:March 21, 2016
Description:

From the Arch Linux advisory:

Versions 4.1.0 and earlier of libotr in 64-bit builds contain an integer overflow security flaw. This flaw could potentially be exploited by a remote attacker to cause a heap buffer overflow and subsequently for arbitrary code to be executed on the user's machine.

Alerts:
Gentoo 201701-10 libotr 2017-01-02
Mageia MGASA-2016-0117 libotr 2016-03-25
Fedora FEDORA-2016-fde759f627 libotr 2016-03-19
Fedora FEDORA-2016-8b4f643f3d libotr 2016-03-20
openSUSE openSUSE-SU-2016:0732-1 libotr,libotr2 2016-03-12
Ubuntu USN-2926-1 libotr 2016-03-10
openSUSE openSUSE-SU-2016:0708-1 libotr,libotr2 2016-03-10
Debian DSA-3512-1 libotr 2016-03-09
Arch Linux ASA-201603-6 libotr 2016-03-09

Comments (none posted)

nss: denial of service

Package(s):firefox nss CVE #(s):CVE-2016-1978
Created:March 14, 2016 Updated:March 16, 2016
Description: From the CVE entry:

Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.

Alerts:
Debian DSA-3688-1 nss 2016-10-05
Gentoo 201605-06 nss 2016-05-31
Ubuntu USN-2973-1 thunderbird 2016-05-19
Debian-LTS DLA-480-1 nss 2016-05-18
Scientific Linux SLSA-2016:0685-1 nss, nspr, nss-softokn, nss-util 2016-04-25
Oracle ELSA-2016-0685 nss, nspr, nss-softokn, and nss-util 2016-04-25
Oracle ELSA-2016-0684 nss and nspr 2016-04-25
CentOS CESA-2016:0685 nss-util 2016-04-25
CentOS CESA-2016:0685 nss-softokn 2016-04-25
CentOS CESA-2016:0685 nss 2016-04-25
CentOS CESA-2016:0685 nspr 2016-04-25
CentOS CESA-2016:0684 nss 2016-04-25
CentOS CESA-2016:0684 nspr 2016-04-25
Scientific Linux SLSA-2016:0684-1 nss, nspr 2016-04-25
Red Hat RHSA-2016:0685-01 nss, nspr, nss-softokn, nss-util 2016-04-25
Red Hat RHSA-2016:0684-01 nss, nspr 2016-04-25
Scientific Linux SLSA-2016:0591-1 nss, nss-util, nspr 2016-04-05
CentOS CESA-2016:0591 nss-util 2016-04-05
CentOS CESA-2016:0591 nss 2016-04-05
CentOS CESA-2016:0591 nspr 2016-04-05
Red Hat RHSA-2016:0591-01 nss, nss-util, nspr 2016-04-05
SUSE SUSE-SU-2016:0909-1 firefox, nspr, nss 2016-03-30
SUSE SUSE-SU-2016:0820-1 firefox 2016-03-18
SUSE SUSE-SU-2016:0777-1 firefox nspr nss 2016-03-15
SUSE SUSE-SU-2016:0727-1 firefox, nspr, nss 2016-03-11

Comments (none posted)

openssh: command injection

Package(s):openssh CVE #(s):CVE-2016-3115
Created:March 11, 2016 Updated:April 26, 2016
Description:

From the Mageia advisory:

Missing sanitisation of untrusted input allows an authenticated user who is able to request X11 forwarding to inject commands to xauth(1).

Alerts:
openSUSE openSUSE-SU-2016:1455-1 openssh 2016-05-31
Ubuntu USN-2966-1 openssh 2016-05-09
Fedora FEDORA-2016-fc1cc33e05 gsi-openssh 2016-04-25
Fedora FEDORA-2016-188267b485 gsi-openssh 2016-04-25
Oracle ELSA-2016-3531 openssh 2016-04-03
Fedora FEDORA-2016-d339d610c1 openssh 2016-03-29
Scientific Linux SLSA-2016:0466-1 openssh 2016-03-21
Scientific Linux SLSA-2016:0465-1 openssh 2016-03-21
Oracle ELSA-2016-0466 openssh 2016-03-21
Oracle ELSA-2016-0465 openssh 2016-03-21
CentOS CESA-2016:0466 openssh 2016-03-21
CentOS CESA-2016:0465 openssh 2016-03-21
Red Hat RHSA-2016:0466-01 openssh 2016-03-21
Red Hat RHSA-2016:0465-01 openssh 2016-03-21
Fedora FEDORA-2016-bb59db3c86 openssh 2016-03-13
Arch Linux ASA-201603-12 openssh 2016-03-11
Slackware SSA:2016-070-01 openssh 2016-03-10
Mageia MGASA-2016-0108 openssh 2016-03-11
Gentoo 201612-18 openssh 2016-12-07

Comments (none posted)

OpenVPN: multiple vulnerabilities

Package(s):OpenVPN CVE #(s):
Created:March 10, 2016 Updated:March 16, 2016
Description:

From the openSUSE advisory:

boo#959714: heap overflow on read accessing getaddrinfo result

boo#934237: multiple low severity issues

Alerts:
openSUSE openSUSE-SU-2016:0710-1 OpenVPN 2016-03-10

Comments (none posted)

oracle-jre-bin: code execution

Package(s):oracle-jre-bin CVE #(s):CVE-2015-7840
Created:March 14, 2016 Updated:March 16, 2016
Description: From the CVE entry:

The command line management console (CMC) in SolarWinds Log and Event Manager (LEM) before 6.2.0 allows remote attackers to execute arbitrary code via unspecified vectors involving the ping feature.

Alerts:
Gentoo 201603-11 oracle-jre-bin 2016-03-12

Comments (none posted)

php: multiple vulnerabilities

Package(s):php CVE #(s):
Created:March 11, 2016 Updated:March 16, 2016
Description:

From the Mageia advisory:

The php package has been updated to version 5.6.19, which fixes several security issues and other bugs. See the upstream ChangeLog for more details.

Alerts:
Fedora FEDORA-2016-baa32758d0 php 2016-03-13
Mageia MGASA-2016-0110 php, timezone, php-timezonedb 2016-03-11

Comments (none posted)

php5: stack overflow

Package(s):php5 CVE #(s):CVE-2016-2554
Created:March 10, 2016 Updated:March 16, 2016
Description:

From the openSUSE advisory:

A stack overflow vulnerability when decompressing tar phar archives was fixed.

Alerts:
Red Hat RHSA-2016:2750-01 rh-php56 2016-11-15
Debian-LTS DLA-818-1 php5 2017-02-07
SUSE SUSE-SU-2016:1638-1 php53 2016-06-21
SUSE SUSE-SU-2016:1581-1 php53 2016-06-14
openSUSE openSUSE-SU-2016:1173-1 php5 2016-04-28
Ubuntu USN-2952-2 php5 2016-04-27
SUSE SUSE-SU-2016:1166-1 php5 2016-04-27
SUSE SUSE-SU-2016:1145-1 php53 2016-04-25
Ubuntu USN-2952-1 php5 2016-04-21
openSUSE openSUSE-SU-2016:0709-1 php5 2016-03-10

Comments (none posted)

php-htmLawed: unspecified vulnerability

Package(s):php-htmLawed CVE #(s):
Created:March 11, 2016 Updated:March 16, 2016
Description:

From the Fedora advisory:

Version 1.1.21 - Improvement and security fix in transforming 'font' element.

Alerts:
Fedora FEDORA-2016-0a1a2dd98d php-htmLawed 2016-03-12
Fedora FEDORA-2016-6b977c4737 php-htmLawed 2016-03-11

Comments (none posted)

php-udan11-sql-parser: multiple vulnerabilities

Package(s):php-udan11-sql-parser CVE #(s):CVE-2016-2562 CVE-2016-2559
Created:March 10, 2016 Updated:March 16, 2016
Description:

From the CVE entries:

CVE-2016-2562 - The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.

CVE-2016-2559 - Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted query.

Alerts:
Fedora FEDORA-2016-02ee5b4002 phpMyAdmin 2016-03-14
Fedora FEDORA-2016-02ee5b4002 php-udan11-sql-parser 2016-03-14
Fedora FEDORA-2016-65da02b95c phpMyAdmin 2016-03-09
Fedora FEDORA-2016-65da02b95c php-udan11-sql-parser 2016-03-09

Comments (none posted)

pidgin-otr: code execution

Package(s):pidgin-otr CVE #(s):CVE-2015-8833
Created:March 14, 2016 Updated:March 24, 2016
Description: From the Arch Linux advisory:

The pidgin-otr plugin fixes a heap use after free error. The bug is triggered when a user tries to authenticate a buddy and happens in the function create_smp_dialog. This issue is leading to denial of service or possibly remote code execution.

A remote attacker is able to trigger a user-after-free during otr authentication and possibly execute arbitrary code.

Alerts:
Gentoo 201701-10 libotr 2017-01-02
SUSE SUSE-SU-2016:0912-1 pidgin-otr 2016-03-30
Mageia MGASA-2016-0125 pidgin-otr 2016-03-25
openSUSE openSUSE-SU-2016:0878-1 pidgin-otr 2016-03-24
Debian DSA-3528-1 pidgin-otr 2016-03-23
Arch Linux ASA-201603-14 pidgin-otr 2016-03-12

Comments (none posted)

rails: multiple vulnerabilities

Package(s):rails CVE #(s):CVE-2016-2097 CVE-2016-2098
Created:March 10, 2016 Updated:April 26, 2016
Description:

From the Debian advisory:

CVE-2016-2097 - Crafted requests to Action View, one of the components of Action Pack, might result in rendering files from arbitrary locations, including files beyond the application's view directory. This vulnerability is the result of an incomplete fix of CVE-2016-0752.

CVE-2016-2098 - If a web applications does not properly sanitize user inputs, an attacker might control the arguments of the render method in a controller or a view, resulting in the possibility of executing arbitrary ruby code.

Alerts:
Debian-LTS DLA-604-1 ruby-actionpack-3.2 2016-08-28
SUSE SUSE-SU-2016:1146-1 portus 2016-04-25
SUSE SUSE-SU-2016:0967-1 rubygem-actionpack-3_2 2016-04-07
SUSE SUSE-SU-2016:0867-1 rubygem-actionview-4_2 2016-03-23
SUSE SUSE-SU-2016:0854-1 rubygem-actionview-4_1 2016-03-22
openSUSE openSUSE-SU-2016:0835-1 rubygem-actionpack-3_2 2016-03-19
Fedora FEDORA-2016-3954061e32 rubygem-actionview 2016-03-17
Fedora FEDORA-2016-f6af14570f rubygem-actionview 2016-03-17
Fedora FEDORA-2016-3954061e32 rubygem-actionpack 2016-03-17
Fedora FEDORA-2016-f6af14570f rubygem-actionpack 2016-03-17
openSUSE openSUSE-SU-2016:0790-1 rubygem-actionview-4_2 2016-03-16
Red Hat RHSA-2016:0455-01 ruby193 2016-03-15
Red Hat RHSA-2016:0454-01 ror40 2016-03-15
Red Hat RHSA-2016:0456-01 rh-ror41-rubygem-actionview 2016-03-15
Debian DSA-3509-1 rails 2016-03-09

Comments (none posted)

spip: two vulnerabilities

Package(s):spip CVE #(s):CVE-2016-3153 CVE-2016-3154
Created:March 16, 2016 Updated:March 16, 2016
Description: From the Debian advisory:

CVE-2016-3153: g0uZ et sambecks, from team root-me, discovered that arbitrary PHP code could be injected when adding content.

CVE-2016-3154: Gilles Vincent discovered that deserializing untrusted content could result in arbitrary objects injection.

Alerts:
Debian DSA-3518-1 spip 2016-03-16

Comments (none posted)

vlc: multiple vulnerabilities

Package(s):vlc CVE #(s):CVE-2014-1684 CVE-2014-9597 CVE-2014-9598 CVE-2015-1202 CVE-2015-1203
Created:March 14, 2016 Updated:March 16, 2016
Description: From the CVE entries:

The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Player before 2.1.3 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero minimum and maximum data packet size in an ASF file. (CVE-2014-1684)

The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file. (CVE-2014-9597)

The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file. (CVE-2014-9598)

Unspecified (CVE-2015-1202 and CVE-2015-1203)

Alerts:
Gentoo 201603-08 vlc 2016-03-12

Comments (none posted)

Page editor: Jake Edge
Next page: Kernel development>>


Copyright © 2016, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds