Computer Security
[EN] securityvulns.ru no-pyccku


PHP multiple security vulnerabilities
updated since 28.09.2009
Published:20.10.2009
Source:
SecurityVulns ID:10269
Type:library
Threat Level:
7/10
Description:Certificates spoofing, memory corruptions on images parsing, information leakage.
Affected:PHP : PHP 5.2
 PHP : PHP 5.3
CVE:CVE-2009-3546 (The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.)
 CVE-2009-3293 (Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index.")
 CVE-2009-3292 (Unspecified vulnerability in PHP before 5.2.11 has unknown impact and attack vectors related to "missing sanity checks around exif processing.")
 CVE-2009-3291 (The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.)
Original documentdocumentMANDRIVA, [ MDVSA-2009:284 ] gd (20.10.2009)
 documentdavid_(at)_majorsecurity.info, [MajorSecurity Advisory #59]PHP <=5.3 - mysqli_real_escape_string() full path disclosure (28.09.2009)
 documentdavid_(at)_majorsecurity.info, [MajorSecurity Advisory #57]PHP <=5.3 - preg_match() full path disclosure (28.09.2009)
 documentMANDRIVA, [ MDVSA-2009:248 ] php (28.09.2009)

Web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
Published:20.10.2009
Source:
SecurityVulns ID:10334
Type:remote
Threat Level:
5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
CVE:CVE-2009-1479 (Directory traversal vulnerability in client/desktop/default.htm in Boxalino before 09.05.25-0421 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter.)
Original documentdocumentAxel Neumann, [CVE-2009-1479] Boxalino - Directory Traversal Vulnerability (20.10.2009)

South River Technologies WebDrive privilege escalation
Published:20.10.2009
Source:
SecurityVulns ID:10335
Type:local
Threat Level:
5/10
Description:Weak service permissions.
Affected:SOUTHRIVER : WebDrive 9.02
Original documentdocumentrgod, South River Technologies WebDrive Service Bad Security Descriptor Local Elevation Of Privileges (20.10.2009)

EMC Replistor DoS
Published:20.10.2009
Source:
SecurityVulns ID:10336
Type:remote
Threat Level:
5/10
Description:Crash on TCP/7144 data parsing.
Affected:EMC : RepliStor 6.3
Original documentdocumentrgod, EMC RepliStor Server (rep_serv.exe) 6.3.1.3 remote denial of service (20.10.2009)
Files:EMC RepliStor Server (rep_serv.exe) 6.3.1.3 remote denial of service poc

CUPS / poppler / xpdf / Adobe Reader multipls security vulnerabilities
updated since 20.10.2009
Published:28.10.2009
Source:
SecurityVulns ID:10333
Type:library
Threat Level:
7/10
Description:Integer overflows, race condiotions.
Affected:CUPS : cups 1.1
 CUPS : cups 1.3
 XPDF : xpdf 3.02
 POPPLER : poppler 0.10
CVE:CVE-2009-3609 (Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.)
 CVE-2009-3608 (Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.)
 CVE-2009-3606 (Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.)
 CVE-2009-3604 (The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-based buffer overflow.)
 CVE-2009-3603 (Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.)
Original documentdocumentadam_(at)_hispasec.com, Adobe Acrobat Reader up to 9.1.1 ONLY Linux integer overflow to heap overflow. (28.10.2009)
 documentWill Drewry, [oCERT-2009-016] Poppler, xpdf integer overflow during heap allocation (22.10.2009)
 documentUBUNTU, [USN-850-1] poppler vulnerabilities (22.10.2009)
 documentMANDRIVA, [ MDVSA-2009:283 ] cups (20.10.2009)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod