Vulnerability Summary for the Week of January 7, 2019.Pdf
Total Page:16
File Type:pdf, Size:1020Kb
Vulnerability Summary for the Week of January 7, 2019 The vulnerabilities are based on the CVE vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores: • High - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0 • Medium - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9 • Low - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9 Entries may include additional information provided by organizations and efforts sponsored by Ug-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of Ug-CERT analysis. High Vulnerabilities Primary Vendor -- CVSS Source & Product Description Published Score Patch Info A remote code execution vulnerability exists when CVE-2019- Microsoft Edge improperly accesses objects in 0565 microsoft -- memory, aka "Microsoft Edge Memory Corruption 2019-01- BID edge Vulnerability." This affects Microsoft Edge. 08 7.6 CONFIRM Back to top Medium Vulnerabilities Primary Vendor -- CVSS Source & Product Description Published Score Patch Info CVE-2015- 9275 arc_project -- ARC 5.21q allows directory traversal via a full 2019-01- MISC arc pathname in an archive file. 07 5.0 MISC CVE-2016- 10735 MISC MISC In Bootstrap 3.x before 3.4.0 and 4.x-beta before MISC 4.0.0-beta.2, XSS is possible in the data-target MISC getbootstrap -- attribute, a different vulnerability than CVE-2018- 2019-01- MISC bootstrap 14041. 09 4.3 MISC CVE-2018- ibm -- IBM API Connect 5.0.0.0 through 5.0.8.4 could 2019-01- 1859 api_connect allow a user authenticated as an administrator with 04 6.5 BID Primary Vendor -- CVSS Source & Product Description Published Score Patch Info limited rights to escalate their privileges. IBM X- XF Force ID: 151258. CONFIRM A denial of service vulnerability exists when CVE-2019- ASP.NET Core improperly handles web requests, 0564 aka "ASP.NET Core Denial of Service BID microsoft -- Vulnerability." This affects ASP.NET Core 2.1. 2019-01- REDHAT asp.net_core This CVE ID is unique from CVE-2019-0548. 08 5.0 CONFIRM An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types CVE-2019- of messages, aka "Microsoft Outlook Information 0559 microsoft -- Disclosure Vulnerability." This affects Office 365 2019-01- BID office ProPlus, Microsoft Office, Microsoft Outlook. 08 4.3 CONFIRM An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents CVE-2019- of its memory, aka "Microsoft Office Information 0560 microsoft -- Disclosure Vulnerability." This affects Office 365 2019-01- BID office ProPlus, Microsoft Office. 08 4.3 CONFIRM YUNUCMS 1.1.8 has XSS in app/admin/controller/System.php because crafted data can be written to the sys.php file, as CVE-2019- yunucms -- demonstrated by site_title in an admin/system/basic 2019-01- 5310 yunucms POST request. 04 4.3 MISC An issue was discovered in YUNUCMS V1.1.8. app/index/controller/Show.php has an XSS CVE-2019- yunucms -- vulnerability via the index.php/index/show/index cw 2019-01- 5311 yunucms parameter. 04 4.3 MISC Back to top Low Vulnerabilities Primary CVSS Source & Vendor -- Product Description Published Score Patch Info CVE-2018- frog_cms_project -- Frog CMS 0.9.5 has XSS in the 2019-01- 20680 frog_cms admin/?/page/edit/1 body field. 09 3.5 MISC IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows CVE-2018- users to embed arbitrary JavaScript 1657 code in the Web UI thus altering the BID ibm -- intended functionality potentially 2019-01- XF rational_publishing_engine leading to credentials disclosure within 04 3.5 CONFIRM Primary CVSS Source & Vendor -- Product Description Published Score Patch Info a trusted session. IBM X-force ID: 144883. IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the CVE-2018- intended functionality potentially 1951 leading to credentials disclosure within BID ibm -- a trusted session. IBM X-Force ID: 2019-01- XF rational_publishing_engine 153494. 04 3.5 CONFIRM Back to top Severity Not Yet Assigned CVS Sourc S e & Primary Publ Scor Patch Vendor -- Product Description ished e Info Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject CVE- external XML entities in Apache not 2018- Karaf version prior to 4.1.7 or 4.2.2. 2019 yet 11788 apache -- karaf It has been fixed in Apache Karaf -01- calcuMISC 4.1.7 and 4.2.2 releases. 07 lated BID Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTran sport class. An assert used to determine if the SASL handshake not CVE- had successfully completed could be 2019 yet 2018- disabled in production settings -01- calcu1320 apache -- thrift making the validation incomplete. 07 lated MISC CVS Sourc S e & Primary Publ Scor Patch Vendor -- Product Description ished e Info The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to CVE- contain a security vulnerability in not 2018- which a remote user has the ability 2019 yet 11798 to access files outside the set -01- calcuBID apache -- thrift webservers docroot path. 07 lated MISC An exploitable privilege escalation vulnerability exists in the Clean My Mac X, version 4.04, helper service due to improper input validation. A user with local access can use this vulnerability to modify the file not CVE- system as root. An attacker would 2019 yet 2018- need local access to the machine for -01- calcu4043 apple -- cleanmymac_x a successful exploit. 10 lated MISC An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local not CVE- access could exploit this 2019 yet 2018- vulnerability to modify the file -01- calcu4047 apple -- cleanmymac_x system as root. 10 lated MISC An exploitable privilege escalation vulnerability exists in the way the CleanMyMac X software improperly validates inputs. An attacker with local access could use this vulnerability to modify the file not CVE- system as root. An attacker would 2019 yet 2018- need local access to the machine for -01- calcu4032 apple -- cleanmymac_x a successful exploit. 10 lated MISC The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An not CVE- attacker with local access could use 2019 yet 2018- this vulnerability to modify the file -01- calcu4033 apple -- cleanmymac_x system as root. 10 lated MISC CVS Sourc S e & Primary Publ Scor Patch Vendor -- Product Description ished e Info The CleanMyMac X software contains an exploitable privilege escalation vulnerability that exists due to improper input validation. An not CVE- attacker with local access could use 2019 yet 2018- this vulnerability to modify the file -01- calcu4034 apple -- cleanmymac_x system as root. 10 lated MISC An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local not CVE- access could exploit this 2019 yet 2018- vulnerability to modify the file -01- calcu4045 apple -- cleanmymac_x system as root. 10 lated MISC The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access could use not CVE- this vulnerability to modify the 2019 yet 2018- running kernel extensions on the -01- calcu4036 apple -- cleanmymac_x system. 10 lated MISC The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An not CVE- attacker with local access can use 2019 yet 2018- this vulnerability to modify the file -01- calcu4037 apple -- cleanmymac_x system as root. 10 lated MISC The CleanMyMac X software contains an exploitable privilege escalation vulnerability that exists due to improper input validation. An not CVE- attacker with local access could use 2019 yet 2018- this vulnerability to modify the file -01- calcu4035 apple -- cleanmymac_x system as root. 10 lated MISC An exploitable denial-of-service vulnerability exists in the helper not CVE- service of Clean My Mac X, version 2019 yet 2018- 4.04, due to improper input -01- calcu4046 apple -- cleanmymac_x validation. A user with local access 10 lated MISC CVS Sourc S e & Primary Publ Scor Patch Vendor -- Product Description ished e Info can use this vulnerability to terminate a privileged helper application. An attacker would need local access to the machine for a successful exploit. An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local not CVE- access could exploit this 2019 yet 2018- vulnerability to modify the file -01- calcu4041 apple -- cleanmymac_x system as root. 10 lated MISC An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation.