[Full-disclosure] [PRE-SA-2011-04] Heap overflow in EFI partition handling code of the Linux kernel

2011-05-11 Thread Timo Warns
PRE-CERT Security Advisory == * Advisory: PRE-SA-2011-04 * Released on: 10 May 2011 * Last updated on: 10 May 2011 * Affected product: Linux Kernel 2.4 and 2.6 * Impact: information disclosure, denial-of-service * Origin: storage devices * Credit: Timo Warns (PRESENSE

[Full-disclosure] [PRE-SA-2011-05] Buffer overflow in tftp-hpa daemon

2011-06-23 Thread Timo Warns
PRE-CERT Security Advisory == * Advisory: PRE-SA-2011-05 * Released on: 22 Jun 2011 * Last updated on: 22 Jun 2011 * Affected product: tftp-hpa 0.30 - 5.0 * Impact: buffer overflow * Origin: remote tftp client * Credit: Timo Warns (PRESENSE Technologies GmbH) * CVE

[Full-disclosure] [PRE-SA-2011-06] Linux kernel: ZERO_SIZE_PTR dereference for long symlinks in Be FS

2011-08-19 Thread Timo Warns
PRE-CERT Security Advisory == * Advisory: PRE-SA-2011-06 * Released on: 19 August 2011 * Last updated on: 19 August 2011 * Affected product: Linux Kernel 2.4, 2.6, and 3.0 * Impact: denial-of-service * Origin: Be file system * Credit: Timo Warns (PRESENSE Technologies GmbH

[Full-disclosure] [PRE-SA-2012-01] Denial-of-service vulnerability in java.util.zip

2012-02-16 Thread Timo Warns
IcedTea6 1.9.x below 1.9.13 IcedTea6 1.10.x below 1.10.6 IcedTea6 1.11.x below 1.11.1 IcedTea 2.x below 2.0.1 Older versions may also be affected. * Impact: denial-of-service * Origin: java.util.zip * Credit: Timo Warns

[Full-disclosure] [PRE-SA-2012-02] Incorrect loop construct and numeric overflow in libzip

2012-03-27 Thread Timo Warns
tion leak * Credit: - Thomas Klausner - Timo Warns (PRESENSE Technologies GmbH) * CVE Identifier: - CVE-2012-1162 - CVE-2012-1163 Summary --- libzip (version <= 0.10) has two vulnerabilities that may lead to a heap overflow or an information leak via corrupted zi

[Full-disclosure] [PRE-SA-2012-03] Linux kernel: Buffer overflow in HFS plus filesystem

2012-05-16 Thread Timo Warns
Credit: Timo Warns (PRESENSE Technologies GmbH) * CVE Identifier: CVE-2012-2319 Summary --- The Linux kernel contains a vulnerability in the driver for HFS plus file systems that may be exploited for code execution or privilege escalation. A specially-crafted HFS plus filesystem can cause a

[Full-disclosure] [PRE-SA-2012-05] Multiple heap-based buffer overflows in LibreOffice / OpenOffice

2012-08-10 Thread Timo Warns
bscore: 10 Exploitability Subscore: 8.6 CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C) * Credit: Timo Warns (PRESENSE Technologies GmbH) * CVE Identifier: CVE-2012-2665 Summary --- Multiple issues have been identified in LibreOffice / OpenOffice that allow to execute arbitrary code via spe

[Full-disclosure] [PRE-SA-2012-06] FreeRADIUS: Stack Overflow in TLS-based EAP Methods

2012-09-10 Thread Timo Warns
Exploitability Subscore: 10 CVSS Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C) * Credit: Timo Warns (PRESENSE Technologies GmbH) * CVE Identifier: CVE-2012-3547 Summary --- A stack overflow vulnerability has been identified in FreeRADIUS that allows to remotely execute arbitrary code via specially crafted

[Full-disclosure] [PRE-SA-2012-07] hostapd: Missing EAP-TLS message length validation

2012-10-08 Thread Timo Warns
: 10 CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C) * Credit: Timo Warns (PRESENSE Technologies GmbH) * CVE Identifier: CVE-2012-4445 Summary --- The internal EAP authentication server of hostapd does not sufficiently validate the message length field of EAP-TLS messages, which can be exploited

[Full-disclosure] [PRE-SA-2011-01] Multiple Linux kernel vulnerabilities in partition handling code of LDM and MAC partition tables

2011-02-23 Thread Timo Warns
* CVE Identifier: - CVE-2011-1010 ## Summary ## Timo Warns (PRESENSE Technologies GmbH) reported some vulnerabilities in the Linux kernel that may lead to privilege escalation, denial-of-service, or information leakage via corrupted partition tables. Exploiting these vulnerabilities has been

[Full-disclosure] [PRE-SA-2011-02] Information disclosure vulnerability in the OSF partition handling code of the Linux kernel

2011-03-17 Thread Timo Warns
PRE-CERT Security Advisory == * Advisory: PRE-SA-2011-02 * Released on: 16 Mar 2011 * Last updated on: 16 Mar 2011 * Affected product: Linux Kernel 2.4 and 2.6 * Impact: disclosure of sensitive information * Origin: storage devices * Credit: Timo Warns (PRESENSE

[Full-disclosure] [PRE-SA-2011-03] Denial-of-service vulnerability in EFI partition handling code of the Linux kernel

2011-04-13 Thread Timo Warns
PRE-CERT Security Advisory == * Advisory: PRE-SA-2011-03 * Released on: 13 Apr 2011 * Last updated on: 13 Apr 2011 * Affected product: Linux Kernel 2.4 and 2.6 * Impact: denial-of-service * Origin: storage devices * Credit: Timo Warns (PRESENSE Technologies GmbH) * CVE