OLS3's underground

May 18, 2012

CVE

CVE-2012-1589

Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destination URL.

May 18, 2012 10:00 PM

CVE-2012-2010

The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system service is enabled, allows local users to gain privileges via unspecified vectors.

May 18, 2012 10:00 PM

CVE-2012-2406

RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, does not properly parse ASMRuleBook data in RealMedia files, which allows remote attackers to execute arbitrary code via a crafted file.

May 18, 2012 08:00 PM

CVE-2012-2337

sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.

May 18, 2012 08:00 PM

CVE-2012-2411

Buffer overflow in RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted RealJukebox Media file.

May 18, 2012 08:00 PM

Linuxsecurity.com

Facebook Hacker Gets a Year in Jail

<b>LinuxSecurity.com</b>: A British hacker who accessed a U.S. citizen's Facebook account has been given a year-long prison sentence.

May 18, 2012 09:38 AM

Drunken 'Call of Duty' hacker jailed for selling gamers' info

<b>LinuxSecurity.com</b>: A 20-year-old British man will spend the next 18 months behind bars for stealing "Call of Duty" gamers' credit card numbers and other confidential data and selling it to other cybercriminals.

May 18, 2012 09:37 AM

CVE

CVE-2012-2341

Cross-site request forgery (CSRF) vulnerability in the Take Control module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to hijack the authentication of unspecified users for Ajax requests that manipulate files.

May 18, 2012 12:00 AM

CVE-2012-2322

Integer overflow in the dhcpv6_get_option function in gdhcp/client.c in ConnMan before 0.85 allows remote attackers to cause a denial of service (infinite loop and crash) via an invalid length value in a DHCP packet.

May 18, 2012 12:00 AM

CVE-2012-2321

The loopback plug-in in ConnMan before 0.85 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) host name or (2) domain name in a DHCP reply.

May 18, 2012 12:00 AM

CVE-2012-2320

ConnMan before 0.85 does not ensure that netlink messages originate from the kernel, which allows remote attackers to bypass intended access restrictions and cause a denial of service via a crafted netlink message.

May 18, 2012 12:00 AM

CVE-2012-2120

latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

May 18, 2012 12:00 AM

CVE-2012-2118

Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.

May 18, 2012 12:00 AM

CVE-2012-2093

src/common/latex.py in Gajim 0.15 allows local users to overwrite arbitrary files via a symlink attack on a temporary latex file, related to the get_tmpfile_name function.

May 18, 2012 12:00 AM

May 17, 2012

Linuxsecurity.com

Ubuntu: 1445-1: Linux kernel vulnerabilities

<b>LinuxSecurity.com</b>: Several security issues were fixed in the kernel.

May 17, 2012 09:36 PM

Ubuntu: 1445-1: Linux kernel vulnerabilities

<b>LinuxSecurity.com</b>: Several security issues were fixed in the kernel.

May 17, 2012 08:42 PM

CVE

CVE-2011-3637 (linux_kernel)

The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that trigger an m_start error.

May 17, 2012 08:00 PM

CVE-2011-4131 (linux_kernel)

The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.

May 17, 2012 08:00 PM

CVE-2011-4112 (linux_kernel)

The net subsystem in the Linux kernel before 3.1 does not properly restrict use of the IFF_TX_SKB_SHARING flag, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability to access /proc/net/pktgen/pgctrl, and then using the pktgen package in conjunction with a bridge device for a VLAN interface.

May 17, 2012 08:00 PM

CVE-2011-4097 (linux_kernel)

Integer overflow in the oom_badness function in mm/oom_kill.c in the Linux kernel before 3.1.8 on 64-bit platforms allows local users to cause a denial of service (memory consumption or process termination) by using a certain large amount of memory.

May 17, 2012 08:00 PM

CVE-2011-4594 (linux_kernel)

The __sys_sendmsg function in net/socket.c in the Linux kernel before 3.1 allows local users to cause a denial of service (system crash) via crafted use of the sendmmsg system call, leading to an incorrect pointer dereference.

May 17, 2012 08:00 PM

CVE-2011-4326 (linux_kernel)

The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP packets to a bridge device.

May 17, 2012 08:00 PM

CVE-2012-0038 (linux_kernel)

Integer overflow in the xfs_acl_from_disk function in fs/xfs/xfs_acl.c in the Linux kernel before 3.1.9 allows local users to cause a denial of service (panic) via a filesystem with a malformed ACL, leading to a heap-based buffer overflow.

May 17, 2012 08:00 PM

CVE-2011-4621 (linux_kernel)

The Linux kernel before 2.6.37 does not properly implement a certain clock-update optimization, which allows local users to cause a denial of service (system hang) via an application that executes code in a loop.

May 17, 2012 08:00 PM

CVE-2011-4611 (linux_kernel)

Integer overflow in the perf_event_interrupt function in arch/powerpc/kernel/perf_event.c in the Linux kernel before 2.6.39 on powerpc platforms allows local users to cause a denial of service (unhandled performance monitor exception) via vectors that trigger certain outcomes of performance events.

May 17, 2012 08:00 PM

CVE-2012-0058 (linux_kernel)

The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.

May 17, 2012 08:00 PM

CVE-2012-0044 (linux_kernel)

Integer overflow in the drm_mode_dirtyfb_ioctl function in drivers/gpu/drm/drm_crtc.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.1.5 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted ioctl call.

May 17, 2012 08:00 PM

CVE-2012-0879 (linux_kernel)

The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.

May 17, 2012 08:00 PM

CVE-2012-0207 (linux_kernel)

The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and panic) via IGMP packets.

May 17, 2012 08:00 PM

CVE-2012-1097 (linux_kernel)

The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace call.

May 17, 2012 08:00 PM