Showing posts with label FIXES. Show all posts
Showing posts with label FIXES. Show all posts

Sunday, February 3, 2013

VULNERABILITIES / FIXES - January 21, 2013

Moodle Multiple Vulnerabilities

Release Date : 2013-01-21

Criticality level : Moderately critical
Impact : Unknown
Security Bypass
Cross Site Scripting
Spoofing
Exposure of sensitive information
Where: From remote
Solution Status : Vendor Patch

Software: Moodle 1.9.x
Moodle 2.1.x
Moodle 2.2.x
Moodle 2.3.x
Moodle 2.4.x

Description:
Multiple weaknesses, two security issues, and multiple vulnerabilities have been reported in Moodle, where one has an unknown impact and the others can be exploited by malicious users to bypass certain security restrictions and by malicious people to conduct spoofing and cross-site request forgery attacks and disclose potentially sensitive information.

1) An unspecified error exists in the spellchecker plugin for TinyMCE. No further information is currently available.

This vulnerability is reported in versions 2.4, 2.3 through 2.3.3+, 2.2 through 2.2.6+, and 2.1 through 2.1.9+.

2) The application does not properly verify capabilities when editing outcomes, which can be exploited to set outcomes to be a site-wide standard.

Successful exploitation of this security issue requires teacher permission.

This security issue is reported in versions 2.4, 2.3 through 2.3.3+, 2.2 through 2.2.6+, 2.1 through 2.1.9+, and 1.9 through 1.9.19.

3) Input passed via the "returnurl" parameter to multiple scripts is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.

List of affected scripts:
http://[host]/backup/backupfilesedit.php
http://[host]/comment/comment_post.php
http://[host]/course/switchrole.php
http://[host]/mod/wiki/filesedit.php
http://[host]/tag/coursetags_add.php
http://[host]/user/files.php

This weakness is reported in versions 2.4, 2.3 through 2.3.3+, and 2.2 to 2.2.6+.

4) The application does not properly restrict access to the feedback comment viewing functionality, which can be exploited to view otherwise restricted feedback comments provided on other students' submissions.

Successful exploitation of this vulnerability requires student permission.

This vulnerability is reported in versions 2.4 and 2.3 through 2.3.3+.

5) The application allows users to perform certain actions via HTTP requests without performing proper validity checks to verify the requests. This can be exploited to e.g. send course messages when a logged-in user visits a specially crafted web page.

6) The application does not properly restrict access to certain blog posts, which can be exploited to disclose contents of otherwise restricted blog posts via related RSS feeds.

The vulnerabilities #5 and #6 are reported in versions 2.4, 2.3 through 2.3.3+, and 2.2 to 2.2.6+.

7) The application does not properly verify capabilities when handling calendars, which can be exploited to delete a teacher created course level calendar subscription.

Successful exploitation of this security issue requires student permission.

This security issue is reported in version 2.4.

Solution:
Update to version 2.4.1, 2.3.4, 2.2.7, 2.1.10, or 1.9.19+ weekly build (2012-12-20) or later.

Provided and/or discovered by:
The vendor credits:
1) Petr Skoda
2) Elena Ivanova
3) Simon Coggins
4) Dan Poltawski
5) Andrew Nicols
6) Charles Fulton
7) David O'Brien

Original Advisory:
Moodle (MSA-13-0001, MSA-13-0002, MSA-13-0005, MSA-13-0006, MSA-13-0007, MSA-13-0008, MSA-13-0010):
https://moodle.org/mod/forum/discuss.php?d=219612
https://moodle.org/mod/forum/discuss.php?d=220157
https://moodle.org/mod/forum/discuss.php?d=220158
https://moodle.org/mod/forum/discuss.php?d=220162
https://moodle.org/mod/forum/discuss.php?d=220163
https://moodle.org/mod/forum/discuss.php?d=220164
https://moodle.org/mod/forum/discuss.php?d=220165
https://moodle.org/mod/forum/discuss.php?d=220167

http://secunia.com/advisories/51842/

VULNERABILITIES / FIXES - January 29, 2013

Apple iOS Multiple Vulnerabilities

Release Date: 2013-01-29

Criticality level : Highly critical
Impact : Security Bypass
Cross Site Scripting
System access
Where : From remote
Solution Status : Vendor Patch

Operating System:
Apple iOS 6.x for iPhone 3GS and later
Apple iOS for iPad 6.x
Apple iOS for iPod touch 6.x

Description:
Two security issues and multiple vulnerabilities have been reported in Apple iOS, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's device.

1) An error when handling a validation failure of a AppleID certificate within the IdentityService can be exploited to potentially bypass the certificate-based AppleID authentication via an invalid AppleID certificate.

2) An error exists in International Components for Unicode.

3) An input validation error within the kernel can be exploited to bypass the validation check by using a pointer length of less than a page and access the first page of kernel memory.

4) An error when handling the JavaScript preferences of Safari in StoreKit can be exploited to re-enable JavaScript without user notice by visiting a site displaying a Smart App Banner.

5) Multiple vulnerabilities are caused due to a bundled vulnerable version of WebKit.

6) An unspecified error within WebKit can be exploited to corrupt memory.

7) Another unspecified error within WebKit can be exploited to corrupt memory.

8) Another unspecified error within WebKit can be exploited to corrupt memory.

9) Another unspecified error within WebKit can be exploited to corrupt memory.

10) Another unspecified error within WebKit can be exploited to corrupt memory.

11) Another unspecified error within WebKit can be exploited to corrupt memory.

12) Another unspecified error within WebKit can be exploited to corrupt memory.

13) Another unspecified error within WebKit can be exploited to corrupt memory.

14) Another unspecified error within WebKit can be exploited to corrupt memory.

15) Another unspecified error within WebKit can be exploited to corrupt memory.

16) Another unspecified error within WebKit can be exploited to corrupt memory.

17) Another unspecified error within WebKit can be exploited to corrupt memory.

Successful exploitation of vulnerabilities #3 and #5 through #17 may allow execution of arbitrary code.

18) Certain input pasted from a different origin is not properly sanitised in WebKit before being used. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

19) Certain unspecified input related to frame handling is not properly sanitised before being returned to the user.

NOTE: Additionally a weakness exists within the handling of 802.11i information elements within Broadcom's BCM4325 and BCM4329 firmware, which can be exploited to disable WiFi.

Solution:
Apply iOS 6.1 Software Update.

Provided and/or discovered by:
1, 9, 13, and 14) Reported by the vendor

The vendor credits:
3) Mark Dowd, Azimuth Security
4) Andrew Plotkin, Zarfhome Software Consulting, Ben Madison, BitCloud, and Marek Durcek
6, 7, 8, 10, 11, 15, and 16) Abhishek Arya (Inferno), Google Chrome Security Team
12) Dominic Cooney, Google and Martin Barbella, Google Chrome Security Team
17) Aaron Nelson
18) Mario Heiderich, Cure53

Original Advisory:
APPLE-SA-2013-01-28-1:
http://support.apple.com/kb/HT5642

http://secunia.com/advisories/52002/

Friday, February 1, 2013

VULNERABILITIES / FIXES - January 30, 2013

Wireshark Multiple Vulnerabilities

Release Date : 2013-01-30

Criticality level : Highly critical
Impact : DoS
System access
Where : From remote
Solution Status : Vendor Patch

Software: Wireshark 1.x

Description:
Multiple vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.

1) Errors in the Bluetooth HCI, CSN.1, DCP-ETSI DOCSIS CM-STAUS, IEEE 802.3 Slow Protocols, MPLS, R3, RTPS, SDP, and SIP dissectors can be exploited to trigger infinite loops and consume CPU resources via specially crafted packets.

2) An error in the CLNP dissector when processing certain packets can be exploited to cause a crash via a specially crafted packet.

3) An error in the DTN dissector when processing certain packets can be exploited to cause a crash via a specially crafted packet.

4) An error in the MS-MMC dissector when processing certain packets can be exploited to cause a crash via a specially crafted packet.

5) An error in the DTLS dissector when processing certain packets can be exploited to cause a crash via a specially crafted packet.

6) An error in the ROHC dissector when processing certain packets can be exploited to cause a crash via a specially crafted packet.

7) An error in the DCP-ETSI dissector when processing certain packets can be exploited to cause a memory corruption via a specially crafted packet.

8) An error in the dissection engine when processing certain packets can be exploited to cause a crash via a specially crafted packet.

9) An error in the NTLMSSP dissector when processing certain packets can be exploited to cause a buffer overflow via a specially crafted packet.

Successful exploitation of this vulnerability may allow execution of arbitrary code.

The vulnerabilities are reported in versions prior to 1.8.5 and 1.6.13.

Solution:
Update to version 1.8.5 or 1.6.13.

Provided and/or discovered by:
1, 5, 7, 8) The vendor credits Laurent Butti
2) The vendor credits Laurent Butti and the Wireshark Development Team
3, 4, 6) Reported by the vendor
9) The vendor credits Ulf Harnhammar

Original Advisory:
http://www.wireshark.org/docs/relnotes/wireshark-1.8.5.html

http://secunia.com/advisories/51968/