FreshRSS

๐Ÿ”’
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities

January 31st 2024 at 00:00
GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] RoyalTSX 6.0.1 - RTSZ File Handling Heap Memory Corruption PoC

January 31st 2024 at 00:00
RoyalTSX 6.0.1 - RTSZ File Handling Heap Memory Corruption PoC
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] Proxmox VE - TOTP Brute Force

January 31st 2024 at 00:00
Proxmox VE - TOTP Brute Force
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] 101 News 1.0 - Multiple-SQLi

January 31st 2024 at 00:00
101 News 1.0 - Multiple-SQLi
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Academy LMS 6.2 - SQL Injection

January 31st 2024 at 00:00
Academy LMS 6.2 - SQL Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Academy LMS 6.2 - Reflected XSS

January 31st 2024 at 00:00
Academy LMS 6.2 - Reflected XSS
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] Equipment Rental Script-1.0 - SQLi

January 29th 2024 at 00:00
Equipment Rental Script-1.0 - SQLi
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] Ricoh Printer - Directory and File Exposure

January 29th 2024 at 00:00
Ricoh Printer - Directory and File Exposure
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] Blood Bank & Donor Management System using v2.2 - Stored XSS

January 29th 2024 at 00:00
Blood Bank & Donor Management System using v2.2 - Stored XSS
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Fundraising Script 1.0 - SQLi

January 29th 2024 at 00:00
Fundraising Script 1.0 - SQLi
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] PHP Shopping Cart 4.2 - Multiple-SQLi

January 29th 2024 at 00:00
PHP Shopping Cart 4.2 - Multiple-SQLi
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] Typora v1.7.4 - OS Command Injection

January 29th 2024 at 00:00
Typora v1.7.4 - OS Command Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] 7 Sticky Notes v1.9 - OS Command Injection

January 29th 2024 at 00:00
7 Sticky Notes v1.9 - OS Command Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Bank Locker Management System - SQL Injection

January 29th 2024 at 00:00
Bank Locker Management System - SQL Injection
โ˜ โ˜† โœ‡ Full Disclosure

Re: Buffer Overflow in graphviz via via a crafted config6a file

January 27th 2024 at 22:03

Posted by Matthew Fernandez on Jan 27

More specifically, this issue is an out-of-bounds read.

AFAICT the issue was actually introduced in Graphviz 2.36. It was fixed
in commit a95f977f5d809915ec4b14836d2b5b7f5e74881e (essentially
reverting cf95714837f06f684929b54659523c2c9b1fc19f that introduced the
issue), but there has been no release yet since then. The next release
will be 10.0.0. So affected versions would be [2.36, 10.0.0).

To exploit this issue, you need to modify a...
โ˜ โ˜† โœ‡ Full Disclosure

Re: null pointer deference in nano via read_the_list()

January 27th 2024 at 22:03

Posted by Mark Esler on Jan 27

Hi Meng,

In your recent mass posts to FD, are you reporting vulnerabilities or
bug reports which have words like "segfault" in the title? What benefit
do you see this having? Have you spoken to each upstream project before
requesting a CVE be assigned?

Thank you,
Mark Esler
โ˜ โ˜† โœ‡ Full Disclosure

CVEs based on commit messages

January 27th 2024 at 22:03

Posted by Mark Esler on Jan 27

Dear Meng Rujie,

In regards to your recent FD posts, are you requesting CVEs based on the
presence of strings in commit messages such as "null pointer dereference"?

Are you reaching out to each upstream project before assigning a CVE? Do
you believe that every null pointer bug is a vulnerability? What impact
are you hoping to achieve?

Please reconsider how you are requesting CVEs.

CVE assignment based on commit message allows...
โ˜ โ˜† โœ‡ Full Disclosure

Re: NULL pointer dereference in freedesktop Mesa via check_xshm()

January 27th 2024 at 22:01

Posted by Dan Cross on Jan 27

I find it very difficult to believe that every NULL pointer error in
existence is a security vulnerability.

- Dan C.
โ˜ โ˜† โœ‡ Full Disclosure

Re: Null pointer dereference in Xedit

January 27th 2024 at 22:01

Posted by Alan Coopersmith on Jan 27

I will be asking that this CVE be withdrawn on behalf of the X.Org security team.

While it is a low-priority bug, we did not see any security exposure
when this bug was first brought to our attention because there is no
way for an attacker to change the contents of the lisp.lsp file or to
cause a *.lsp file to be loaded for another user.

The bug report states "replace /usr/local/lib/X11/xedit/lisp/lisp.lsp with
the attached version,"...
โ˜ โ˜† โœ‡ Full Disclosure

null pointer deference in MiniZinc via a crafted Preferences.json file

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
A null pointer deference existed in MiniZinc v.2.7.6 via a crafted Preferences.json file.

[VulnerabilityType Other]
null pointer deference

[Vendor of Product]
MiniZinc

[Affected Product Code Base]
MiniZinc - 2.7.6

[Reference]
https://github.com/MiniZinc/libminizinc/issues/729

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-46050 to this...
โ˜ โ˜† โœ‡ Full Disclosure

arithmetic exception in S-lang via the function tt_sprintf()

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
S-Lang v2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().

[VulnerabilityType Other]
FPE

[Vendor of Product]
S-Lang

[Affected Product Code Base]
S-Lang - 2.3.2

[Reference]
http://lists.jedsoft.org/lists/slang-users/2023/0000003.html

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-45927 to this
vulnerability.
โ˜ โ˜† โœ‡ Full Disclosure

null pointer deference in gnome gtk via parse_settings() at xsettings-client.c

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
gnome gtk ac60bc60 was discovered to contain a segmentation violation via the function parse_settings() at
xsettings-client.c.

[VulnerabilityType Other]
null pointer deference

[Vendor of Product]
gnome

[Affected Product Code Base]
gtk - ac60bc60

[Reference]
https://gitlab.gnome.org/GNOME/gtk/-/issues/5983

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name...
โ˜ โ˜† โœ‡ Full Disclosure

NULL pointer dereference in freedesktop Mesa via check_xshm()

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
freedesktop Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function check_xshm().

[Vulnerability Type]
NULL pointer dereference

[Vendor of Product]
freedesktop

[Affected Product Code Base]
Mesa - 23.0.4

[Reference]
https://gitlab.freedesktop.org/mesa/mesa/-/issues/9859

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-45931 to...
โ˜ โ˜† โœ‡ Full Disclosure

null pointer deference in nano via read_the_list()

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
Nano v6.2 was discovered to contain a segmentation violation via the function read_the_list().

[VulnerabilityType Other]
null pointer deference

[Vendor of Product]
nano

[Affected Product Code Base]
nano - 6.2

[Reference]
https://savannah.gnu.org/bugs/index.php?64465

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-45932 to this
vulnerability.
โ˜ โ˜† โœ‡ Full Disclosure

SEGV in S-Lang via fixup_tgetstr()

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
S-Lang v2.3.2 was discovered to contain a SEGV via the function fixup_tgetstr().

[VulnerabilityType Other]
SEGV

[Vendor of Product]
S-Lang

[Affected Product Code Base]
S-Lang - 2.3.2

[Reference]
http://lists.jedsoft.org/lists/slang-users/2023/0000002.html

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-45929 to this
vulnerability.
โ˜ โ˜† โœ‡ Full Disclosure

null pointer deference in gnome gtk via init_randr15() at gdkscreen-x11.c

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
gnome gtk f2a28891 was discovered to contain a segmentation violation via the function init_randr15() at
gdkscreen-x11.c.

[VulnerabilityType Other]
null pointer deference

[Vendor of Product]
gnome

[Affected Product Code Base]
gtk - f2a28891

[Reference]
https://gitlab.gnome.org/GNOME/gtk/-/issues/5984

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name...
โ˜ โ˜† โœ‡ Full Disclosure

NULL pointer dereference in QT via the function QXcbConnection::initializeAllAtoms()

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
QT v6.2, v6.5, and v6.6 was discovered to contain a NULL pointer dereference via the function
QXcbConnection::initializeAllAtoms().

[VulnerabilityType Other]
null pointer deference

[Vendor of Product]
qt

[Affected Product Code Base]
qt - 6.6, 6.5, 6.2

[Reference]
https://bugreports.qt.io/browse/QTBUG-115599

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name...
โ˜ โ˜† โœ‡ Full Disclosure

Buffer Overflow in graphviz via via a crafted config6a file

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
Buffer Overflow vulnerability in graphviz v.2.43.0 allows a remote attacker to execute arbitrary code via a crafted
config6a file.

[Vulnerability Type]
Buffer Overflow

[Vendor of Product]
graphviz

[Affected Product Code Base]
graphviz - 2.43.0

[Reference]
https://gitlab.com/graphviz/graphviz/-/issues/2441

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name...
โ˜ โ˜† โœ‡ Full Disclosure

null pointer deference in MiniZinc via a crafted .mzn file

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
Null pointer deference happens in MiniZinc v.2.7.6 via a crafted .mzn file.

[VulnerabilityType Other]
null pointer deference

[Vendor of Product]
MiniZinc

[Affected Product Code Base]
MiniZinc - 2.7.6

[Reference]
https://github.com/MiniZinc/libminizinc/issues/730

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-46046 to this
vulnerability.
โ˜ โ˜† โœ‡ Full Disclosure

null pointer deference in Sane via a crafted config file

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
A null pointer deference occurred in Sane v.1.2.1 via a crafted config file to the sanei_configure_attach() function.

[VulnerabilityType Other]
null pointer deference

[Vendor of Product]
sane

[Affected Product Code Base]
sane - 1.2.1

[Reference]
https://gitlab.com/sane-project/backends/-/issues/708

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-46047...
โ˜ โ˜† โœ‡ Full Disclosure

null pointer deference in tex-live

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
A null pointer deference existed in tex-live v.944e257 via a crafted file to the texk/web2c/pdftexdir/tounicode.c
function.

[VulnerabilityType Other]
null pointer deference

[Vendor of Product]
tex-live

[Affected Product Code Base]
tex-live - 944e257

[Reference]
https://tug.org/pipermail/tex-live/2023-August/049406.html

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned...
โ˜ โ˜† โœ‡ Full Disclosure

null pointer deference in tex-live via a crafted cmr10.pfb

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
A null pointer deference occurred in tex-live 944e257 via a crafted cmr10.pfb config file.

[VulnerabilityType Other]
null pointer deference

[Vendor of Product]
tex-live

[Affected Product Code Base]
tex-live - 944e257

[Reference]
https://tug.org/pipermail/tex-live/2023-August/049400.html

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-46048 to this...
โ˜ โ˜† โœ‡ Full Disclosure

Buffer overflow in Sane

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
A buffer overflow existed in Sane v.1.2.1 via a crafted config file to the init_options() function.

[Vulnerability Type]
Buffer Overflow

[Vendor of Product]
sane

[Affected Product Code Base]
sane - 1.2.1

[Reference]
https://gitlab.com/sane-project/backends/-/issues/709

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-46052 to this
vulnerability.
โ˜ โ˜† โœ‡ Full Disclosure

null pointer deference in LLVM

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
A null pointer deference existed in LLVM v.15.0.0 via a crafted pdflatex.fmt file.

[VulnerabilityType Other]
null pointer deference

[Vendor of Product]
llvm

[Affected Product Code Base]
llvm - LLVM-15

[Reference]
https://github.com/llvm/llvm-project/issues/67388

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-46049 to this
vulnerability.
โ˜ โ˜† โœ‡ Full Disclosure

Minor firefox DoS - semi silently polluting ~/Downloads with files (part 2)

January 18th 2024 at 19:34

Posted by Georgi Guninski on Jan 18

Minor firefox DoS - semi silently polluting ~/Downloads with files (part 2)

Tested on: firefox 121 and chrome 120 on GNU/linux

Date: Thu Jan 18 08:38:28 AM UTC 2024

This is barely a DoS, but since it might affect Chrome too we decided
to disclose it.

If firefox user visits a specially crafted page, then firefox
may create many files in `~/Downloads`,
The user is notified about this in a small dialog, but there is
no option to stop the...
โ˜ โ˜† โœ‡ Full Disclosure

Re: ODR violation in Redis Raft

January 18th 2024 at 19:34

Posted by Jeffrey Walton on Jan 18

I fail to see how a One Definition Rule (ODR) violation results in a
Remote Code Execution.

Can you share your PoC, please?

Jeff
โ˜ โ˜† โœ‡ Full Disclosure

Infinite loop leading to buffer overflow in TinyDTLS

January 17th 2024 at 20:26

Posted by Meng Ruijie on Jan 17

[Suggested description]
An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. An infinite loop bug exists during the handling of a
ClientHello handshake message. This bug allows remote attackers to cause a denial of service by sending a malformed
ClientHello handshake message with an odd length of cipher suites, which triggers an infinite loop (consuming all
resources) and a buffer over-read that can disclose sensitive...
โ˜ โ˜† โœ‡ Full Disclosure

Assertion failure in check_certificate_request() of TinyDTLS

January 17th 2024 at 20:26

Posted by Meng Ruijie on Jan 17

[Suggested description]
An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. An assertion failure in check_certificate_request()
causes the server to exit unexpectedly (a denial of service).

[VulnerabilityType Other]
Improper Handling of exception conditions

[Vendor of Product]
https://github.com/contiki-ng/tinydtls

[Affected Product Code Base]
contiki-ng tinydtls - master branch 53a0d97

[Affected Component]
the service of dtls...
โ˜ โ˜† โœ‡ Full Disclosure

Misues same epoch number within TCP lifetime in TinyDTLS

January 17th 2024 at 20:26

Posted by Meng Ruijie on Jan 17

[Suggested description]
An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. DTLS servers allow remote attackers to reuse the
same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulnerability
allows remote attackers to obtain sensitive application (data of connected clients).

[VulnerabilityType Other]
Improper Handling of exception conditions

[Vendor of Product]...
โ˜ โ˜† โœ‡ Full Disclosure

Buffer over-read in TinyDTLS

January 17th 2024 at 20:26

Posted by Meng Ruijie on Jan 17

[Suggested description]
An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. Incorrect handling of over-large packets in
dtls_ccm_decrypt_message() causes a buffer over-read that can expose sensitive information.

[Vulnerability Type]
Buffer Overflow

[Vendor of Product]
https://github.com/contiki-ng/tinydtls

[Affected Product Code Base]
contiki-ng tinydtls - master branch 53a0d97

[Affected Component]
the service of dtls servers...
โ˜ โ˜† โœ‡ Full Disclosure

Buffer over-read in dtls_sha256_update of TinyDTLS

January 17th 2024 at 20:26

Posted by Meng Ruijie on Jan 17

[Suggested description]
An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. A buffer over-read exists in the dtls_sha256_update
function. This bug allows remote attackers to cause a denial of service (crash) and possibly read sensitive information
by sending a malformed packet with an over-large fragment length field, due to servers incorrectly handling malformed
packets.

[Vulnerability Type]
Buffer Overflow

[Vendor of...
โ˜ โ˜† โœ‡ Full Disclosure

Legends of IdleOn - I Reject Your RNG And Substitute My Own

January 17th 2024 at 20:26

Posted by Soatok Dreamseeker on Jan 17

Hello Full Disclosure mailing list!

Legends of IdleOn is a popular free-to-play game on Android, iOS, Steam,
and Web. While playing around with it last year, I got curious and noticed
a trivial way to manipulate the random number generator.

After six months of radio silence from the developer, including asking the
Discord moderators for help getting the developer's attention, I've decided
to publish this publicly:...
โ˜ โ˜† โœ‡ Full Disclosure

ODR violation in Redis Raft

January 17th 2024 at 20:26

Posted by Meng Ruijie on Jan 17

[Suggested description]
Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component
hiredisAllocFns at /opt/fs/redisraft/deps/hiredis/alloc.c.

[VulnerabilityType Other]
AddressSanitizer: odr-violation

[Vendor of Product]
Redis

[Affected Product Code Base]
raft - master-1b8bd86 to master-7b46079

[Affected Component]
affected executable

[Attack Type]
Remote

[Impact Code execution]
true

[Impact...
โ˜ โ˜† โœ‡ Full Disclosure

Incorrect handshake in TinyDTLS

January 17th 2024 at 20:26

Posted by Meng Ruijie on Jan 17

About CVE-2021-42141:

[Suggested description]
An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could complete with
different epoch numbers in the packets Client_Hello, Client_key_exchange, and Change_cipher_spec, which may cause
denial of service.

[VulnerabilityType Other]
Improper Handling of exception conditions

[Vendor of Product]
https://github.com/contiki-ng/tinydtls

[Affected Product Code...
โ˜ โ˜† โœ‡ Full Disclosure

Mishandle epoch number in TinyDTLS servers

January 17th 2024 at 20:26

Posted by Meng Ruijie on Jan 17

About CVE-2021-42142:

[Suggested description]
An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. DTLS servers mishandle the early use of a large
epoch number. This vulnerability allows remote attackers to cause a denial of service and false-positive packet drops.

[VulnerabilityType Other]
Improper Handling of exception conditions

[Vendor of Product]
https://github.com/contiki-ng/tinydtls

[Affected Product Code Base]...
โ˜ โ˜† โœ‡ Full Disclosure

Re: cpio privilege escalation vulnerability via setuid files in cpio archive

January 15th 2024 at 06:08

Posted by Harry Sintonen via Fulldisclosure on Jan 14

Tar does set setuid bit, but tar is not vulnerable. This is not an attack.

The user is responsible for extracting the archives to secure location
and not letting other users access to insecure setuid binaries. See:

https://www.gnu.org/software/tar/manual/html_section/Security.html#Security-rules-of-thumb

These same security considerations also apply to cpio.
โ˜ โ˜† โœ‡ Full Disclosure

Backdoor.Win32 Carbanak (Anunak) / Named Pipe Null DACL

January 15th 2024 at 06:08

Posted by malvuln on Jan 14

Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2024
Original source:
https://malvuln.com/advisory/b8e1e5b832e5947f41fd6ae6ef6d09a1.txt
Contact: malvuln13 () gmail com
Media: twitter.com/malvuln

Threat: Backdoor.Win32 Carbanak (Anunak)
Vulnerability: Named Pipe Null DACL
Family: Carbanak
Type: PE32
MD5: b8e1e5b832e5947f41fd6ae6ef6d09a1
Vuln ID: MVID-2024-0667
Dropped files: AlhEXlUJ.exe, AlhEXlUJbVpfX1EMVw.bin
Disclosure: 01/09/2024...
โ˜ โ˜† โœ‡ Full Disclosure

Re: cpio privilege escalation vulnerability via setuid files in cpio archive

January 15th 2024 at 06:08

Posted by Harry Sintonen via Fulldisclosure on Jan 14

So does for example tar. The same rules that apply to tar also apply to
cpio:

"Extract from an untrusted archive only into an otherwise-empty directory.
This directory and its parent should be accessible only to trusted users."

This is a user error, not a vulnerability in cpio.
โ˜ โ˜† โœ‡ Full Disclosure

CyberDanube Security Research 20240109-0 | Multiple Vulnerabilities in JetNet Series

January 15th 2024 at 06:08

Posted by Thomas Weber via Fulldisclosure on Jan 14

CyberDanube Security Research 20240109-0
-------------------------------------------------------------------------------
title| Multiple Vulnerabilities
product| Korenix JetNet Series
vulnerable version| See "Vulnerable versions"
fixed version| -
CVE number| CVE-2023-5376, CVE-2023-5347
impact| High
homepage| https://www.korenix.com/
found|...
โ˜ โ˜† โœ‡ Full Disclosure

Re: cpio privilege escalation vulnerability via setuid files in cpio archive

January 15th 2024 at 06:06

Posted by Georgi Guninski on Jan 14

Hi, thanks for the feedback :)

Which version of tar is vulnerable to this attack? I am pretty sure
this was fixed in tar and zip `long long` ago.

tar and zip on fedora 38 are definitely not vulnerable, they clear
the setuid bit.

I continue to suspect this is vulnerability because:
1. There is directory traversal protection for untrusted archives
2. tar and zip and not vulnerable

bash script for setuid files in tar:

#!/bin/bash

mkdir -p...
โ˜ โ˜† โœ‡ Full Disclosure

Re: cpio privilege escalation vulnerability via setuid files in cpio archive

January 15th 2024 at 06:05

Posted by fulldisclosure on Jan 14

Am 08.01.24 um 10:25 schrieb Georgi Guninski:

It's not a vulnerability, as

a) cpio archives must archive that flag as cpio is part of RPM packages
and those
must be able to contain setuid flags. Otherwise, you would need to add
chmod u+sย  cmds to any %POST
section. Breaking this, would invalidate so many existing packages =>
won't happen

note: initramfs makes use of cpio as well, but setuid is not needed
here, as it's...
โ˜ โ˜† โœ‡ Full Disclosure

Re: [SBA-ADV-20220120-01] MOKOSmart MKGW1 Gateway Improper Session Management

January 15th 2024 at 06:04

Posted by SBA - Advisory via Fulldisclosure on Jan 14

MITRE assigned CVE-2023-51059 for this issue.
โ˜ โ˜† โœ‡ Advisory Files โ‰ˆ Packet Storm

Ubuntu Security Notice USN-6571-1

January 9th 2024 at 20:45
Ubuntu Security Notice 6571-1 - Youssef Rebahi-Gilbert discovered that Monit did not properly process credentials for disabled accounts. An attacker could possibly use this issue to login to the platform with an expired account and a valid password.
โ˜ โ˜† โœ‡ Advisory Files โ‰ˆ Packet Storm

Ubuntu Security Notice USN-6038-2

January 9th 2024 at 17:01
Ubuntu Security Notice 6038-2 - USN-6038-1 fixed several vulnerabilities in Go 1.18. This update provides the corresponding updates for Go 1.13 and Go 1.16. CVE-2022-29526 and CVE-2022-30630 only affected Go 1.16. It was discovered that the Go net/http module incorrectly handled Transfer-Encoding headers in the HTTP/1 client. A remote attacker could possibly use this issue to perform an HTTP Request Smuggling attack.
โ˜ โ˜† โœ‡ Advisory Files โ‰ˆ Packet Storm

Ubuntu Security Notice USN-6568-1

January 9th 2024 at 16:50
Ubuntu Security Notice 6568-1 - The ClamAV package was updated to a new upstream version to remain compatible with signature database downloads.
โ˜ โ˜† โœ‡ Advisory Files โ‰ˆ Packet Storm

OX App Suite 7.10.6 Access Control / Cross Site Scripting

January 9th 2024 at 16:42
OX App Suite version 7.10.6-rev51 suffers from an access control vulnerability. Version 7.10.6-rev34 suffers from multiple cross site scripting vulnerabilities.
โ˜ โ˜† โœ‡ Advisory Files โ‰ˆ Packet Storm

OX App Suite 7.10.6 XSS / Command Execution / LDAP Injection

January 9th 2024 at 16:15
OX App Suite version 7.10.6-rev50 suffers from remote code execution and LDAP injection vulnerabilities. Version 7.10.6-rev33 suffers from a cross site scripting vulnerability.
โ˜ โ˜† โœ‡ Advisory Files โ‰ˆ Packet Storm

Ubuntu Security Notice USN-6569-1

January 9th 2024 at 16:07
Ubuntu Security Notice 6569-1 - it was discovered that libclamunrar incorrectly handled directories when extracting RAR archives. A remote attacker could possibly use this issue to overwrite arbitrary files and execute arbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04. It was discovered that libclamunrar incorrectly validated certain structures when extracting RAR archives. A remote attacker could possibly use this issue to execute arbitrary code.
โ˜ โ˜† โœ‡ Advisory Files โ‰ˆ Packet Storm

Microsoft SQL Server db_ddladmin Privilege Escalation

January 9th 2024 at 16:04
Microsoft SQL Server versions 2014 through 2022 suffers from a db_ddladmin privilege escalation vulnerability. When escalated to Microsoft as a concern, they instead opted to update their documentation to note that this is possible instead of addressing the issue.
โŒ