Publish Advisories

GHSA-6c6r-r3r9-h62j
GHSA-83rr-gwhc-x8g8
GHSA-934w-fhc8-qwcj
GHSA-959v-9j99-99w5
GHSA-9fc8-v7vw-438w
GHSA-crhq-582w-h987
GHSA-mm8x-p4pr-4p9f
GHSA-p8pq-6r4w-c75v
GHSA-pcmw-6hxc-hqmx
GHSA-r3mr-jgh6-phpp
GHSA-whvw-59jf-hrx9
GHSA-x379-72wq-8vwf
GHSA-xc8c-3cmg-p9qr
This commit is contained in:
advisory-database[bot]
2024-02-06 09:32:58 +00:00
parent 28ae3700ee
commit 6fb9264e0e
13 changed files with 537 additions and 0 deletions
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6c6r-r3r9-h62j",
"modified": "2024-02-06T09:31:38Z",
"published": "2024-02-06T09:31:38Z",
"aliases": [
"CVE-2023-4503"
],
"details": "An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4503"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7637"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7638"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7639"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2023:7641"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-4503"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2184751"
}
],
"database_specific": {
"cwe_ids": [
"CWE-665"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T09:15:52Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-83rr-gwhc-x8g8",
"modified": "2024-02-06T09:31:38Z",
"published": "2024-02-06T09:31:38Z",
"aliases": [
"CVE-2023-28049"
],
"details": "\nDell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploit this vulnerability in order to perform a privileged arbitrary file delete.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28049"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000211748/dsa-2023-125-dell-command-monitor-dcm"
}
],
"database_specific": {
"cwe_ids": [
"CWE-267"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T07:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-934w-fhc8-qwcj",
"modified": "2024-02-06T09:31:38Z",
"published": "2024-02-06T09:31:38Z",
"aliases": [
"CVE-2023-32454"
],
"details": "\nDUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to denial of service\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32454"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000216236/dsa-2023-192"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1386"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T08:15:49Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-959v-9j99-99w5",
"modified": "2024-02-06T09:31:38Z",
"published": "2024-02-06T09:31:38Z",
"aliases": [
"CVE-2023-32474"
],
"details": "\nDell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this vulnerability during installation leading to arbitrary folder or file deletion\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32474"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000215216/dsa-2023-182-dell"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1386"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T08:15:50Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9fc8-v7vw-438w",
"modified": "2024-02-06T09:31:38Z",
"published": "2024-02-06T09:31:38Z",
"aliases": [
"CVE-2023-32451"
],
"details": "\nDell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation and uninstallation\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32451"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000215216/dsa-2023-182-dell"
}
],
"database_specific": {
"cwe_ids": [
"CWE-272"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T08:15:48Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-crhq-582w-h987",
"modified": "2024-02-06T09:31:38Z",
"published": "2024-02-06T09:31:38Z",
"aliases": [
"CVE-2024-22433"
],
"details": "\nDell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated attacker could potentially exploit this vulnerability leading to a loss of Confidentiality, Integrity, Protection, and remote takeover of the system. This is a high-severity vulnerability as it allows an attacker to take complete control of DP Search to affect downstream protected devices.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22433"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000221720/dsa-2024-063-security-update-for-dell-data-protection-search-multiple-security-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-538"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T07:15:11Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mm8x-p4pr-4p9f",
"modified": "2024-02-06T09:31:38Z",
"published": "2024-02-06T09:31:38Z",
"aliases": [
"CVE-2023-52239"
],
"details": "The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52239"
},
{
"type": "WEB",
"url": "https://ds-security.com/post/xml_external_entity_injection_magic_xpi/"
},
{
"type": "WEB",
"url": "https://www2.magicsoftware.com/ver/docs/Downloads/Magicxpi/4.14/Windows/ReleaseNotes4.14.pdf"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T07:15:10Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p8pq-6r4w-c75v",
"modified": "2024-02-06T09:31:38Z",
"published": "2024-02-06T09:31:38Z",
"aliases": [
"CVE-2024-0684"
],
"details": "A flaw was found in the GNU coreutils \"split\" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0684"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0684"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258948"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/01/18/2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-122"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T09:15:52Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pcmw-6hxc-hqmx",
"modified": "2024-02-06T09:31:38Z",
"published": "2024-02-06T09:31:38Z",
"aliases": [
"CVE-2024-22365"
],
"details": "linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22365"
},
{
"type": "WEB",
"url": "https://github.com/linux-pam/linux-pam/commit/031bb5a5d0d950253b68138b498dc93be69a64cb"
},
{
"type": "WEB",
"url": "https://github.com/linux-pam/linux-pam"
},
{
"type": "WEB",
"url": "https://github.com/linux-pam/linux-pam/releases/tag/v1.6.0"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/01/18/3"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T08:15:52Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r3mr-jgh6-phpp",
"modified": "2024-02-06T09:31:37Z",
"published": "2024-02-06T09:31:37Z",
"aliases": [
"CVE-2023-25543"
],
"details": "\nDell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privileged malicious user could potentially exploit this vulnerability in order to elevate privileges on the system. \n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25543"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000209464/dsa-2023-075"
}
],
"database_specific": {
"cwe_ids": [
"CWE-280"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T07:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-whvw-59jf-hrx9",
"modified": "2024-02-06T09:31:38Z",
"published": "2024-02-06T09:31:38Z",
"aliases": [
"CVE-2023-32479"
],
"details": "\nDell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32479"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000215881/dsa-2023-260"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T08:15:51Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x379-72wq-8vwf",
"modified": "2024-02-06T09:31:38Z",
"published": "2024-02-06T09:31:38Z",
"aliases": [
"CVE-2023-28063"
],
"details": "\nDell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28063"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000214780/dsa-2023-176-dell-client-bios-security-update-for-a-signed-to-unsigned-conversion-error-vulnerability"
}
],
"database_specific": {
"cwe_ids": [
"CWE-195"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T08:15:46Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xc8c-3cmg-p9qr",
"modified": "2024-02-06T09:31:38Z",
"published": "2024-02-06T09:31:38Z",
"aliases": [
"CVE-2024-25140"
],
"details": "A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5.5.7.3.3), valid from 2023 until 2033. This is potentially unwanted, e.g., because there is no public documentation of security measures for the private key, and arbitrary software could be signed if the private key were to be compromised. NOTE: the vendor's position is \"we do not have EV cert, so we use test cert as a workaround.\" Insertion into Trusted Root Certification Authorities was the originally intended behavior, and the UI ensured that the certificate installation step (checked by default) was visible to the user before proceeding with the product installation.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25140"
},
{
"type": "WEB",
"url": "https://github.com/rustdesk/rustdesk/discussions/6444"
},
{
"type": "WEB",
"url": "https://news.ycombinator.com/item?id=39256493"
},
{
"type": "WEB",
"url": "https://serverfault.com/questions/837994"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-06T09:15:52Z"
}
}