From 6fb9264e0e7b0da6bc7329b299c73a5e8dc84194 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 6 Feb 2024 09:32:58 +0000 Subject: [PATCH] Publish Advisories GHSA-6c6r-r3r9-h62j GHSA-83rr-gwhc-x8g8 GHSA-934w-fhc8-qwcj GHSA-959v-9j99-99w5 GHSA-9fc8-v7vw-438w GHSA-crhq-582w-h987 GHSA-mm8x-p4pr-4p9f GHSA-p8pq-6r4w-c75v GHSA-pcmw-6hxc-hqmx GHSA-r3mr-jgh6-phpp GHSA-whvw-59jf-hrx9 GHSA-x379-72wq-8vwf GHSA-xc8c-3cmg-p9qr --- .../GHSA-6c6r-r3r9-h62j.json | 58 +++++++++++++++++++ .../GHSA-83rr-gwhc-x8g8.json | 38 ++++++++++++ .../GHSA-934w-fhc8-qwcj.json | 38 ++++++++++++ .../GHSA-959v-9j99-99w5.json | 38 ++++++++++++ .../GHSA-9fc8-v7vw-438w.json | 38 ++++++++++++ .../GHSA-crhq-582w-h987.json | 38 ++++++++++++ .../GHSA-mm8x-p4pr-4p9f.json | 39 +++++++++++++ .../GHSA-p8pq-6r4w-c75v.json | 46 +++++++++++++++ .../GHSA-pcmw-6hxc-hqmx.json | 47 +++++++++++++++ .../GHSA-r3mr-jgh6-phpp.json | 38 ++++++++++++ .../GHSA-whvw-59jf-hrx9.json | 38 ++++++++++++ .../GHSA-x379-72wq-8vwf.json | 38 ++++++++++++ .../GHSA-xc8c-3cmg-p9qr.json | 43 ++++++++++++++ 13 files changed, 537 insertions(+) create mode 100644 advisories/unreviewed/2024/02/GHSA-6c6r-r3r9-h62j/GHSA-6c6r-r3r9-h62j.json create mode 100644 advisories/unreviewed/2024/02/GHSA-83rr-gwhc-x8g8/GHSA-83rr-gwhc-x8g8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-934w-fhc8-qwcj/GHSA-934w-fhc8-qwcj.json create mode 100644 advisories/unreviewed/2024/02/GHSA-959v-9j99-99w5/GHSA-959v-9j99-99w5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-9fc8-v7vw-438w/GHSA-9fc8-v7vw-438w.json create mode 100644 advisories/unreviewed/2024/02/GHSA-crhq-582w-h987/GHSA-crhq-582w-h987.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mm8x-p4pr-4p9f/GHSA-mm8x-p4pr-4p9f.json create mode 100644 advisories/unreviewed/2024/02/GHSA-p8pq-6r4w-c75v/GHSA-p8pq-6r4w-c75v.json create mode 100644 advisories/unreviewed/2024/02/GHSA-pcmw-6hxc-hqmx/GHSA-pcmw-6hxc-hqmx.json create mode 100644 advisories/unreviewed/2024/02/GHSA-r3mr-jgh6-phpp/GHSA-r3mr-jgh6-phpp.json create mode 100644 advisories/unreviewed/2024/02/GHSA-whvw-59jf-hrx9/GHSA-whvw-59jf-hrx9.json create mode 100644 advisories/unreviewed/2024/02/GHSA-x379-72wq-8vwf/GHSA-x379-72wq-8vwf.json create mode 100644 advisories/unreviewed/2024/02/GHSA-xc8c-3cmg-p9qr/GHSA-xc8c-3cmg-p9qr.json diff --git a/advisories/unreviewed/2024/02/GHSA-6c6r-r3r9-h62j/GHSA-6c6r-r3r9-h62j.json b/advisories/unreviewed/2024/02/GHSA-6c6r-r3r9-h62j/GHSA-6c6r-r3r9-h62j.json new file mode 100644 index 00000000000..61f5ca91084 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6c6r-r3r9-h62j/GHSA-6c6r-r3r9-h62j.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c6r-r3r9-h62j", + "modified": "2024-02-06T09:31:38Z", + "published": "2024-02-06T09:31:38Z", + "aliases": [ + "CVE-2023-4503" + ], + "details": "An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4503" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7637" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7638" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7639" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7641" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-4503" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2184751" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T09:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-83rr-gwhc-x8g8/GHSA-83rr-gwhc-x8g8.json b/advisories/unreviewed/2024/02/GHSA-83rr-gwhc-x8g8/GHSA-83rr-gwhc-x8g8.json new file mode 100644 index 00000000000..a92bff54628 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-83rr-gwhc-x8g8/GHSA-83rr-gwhc-x8g8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83rr-gwhc-x8g8", + "modified": "2024-02-06T09:31:38Z", + "published": "2024-02-06T09:31:38Z", + "aliases": [ + "CVE-2023-28049" + ], + "details": "\nDell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploit this vulnerability in order to perform a privileged arbitrary file delete.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28049" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000211748/dsa-2023-125-dell-command-monitor-dcm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-267" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-934w-fhc8-qwcj/GHSA-934w-fhc8-qwcj.json b/advisories/unreviewed/2024/02/GHSA-934w-fhc8-qwcj/GHSA-934w-fhc8-qwcj.json new file mode 100644 index 00000000000..1d64a25c4b6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-934w-fhc8-qwcj/GHSA-934w-fhc8-qwcj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-934w-fhc8-qwcj", + "modified": "2024-02-06T09:31:38Z", + "published": "2024-02-06T09:31:38Z", + "aliases": [ + "CVE-2023-32454" + ], + "details": "\nDUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to denial of service\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32454" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000216236/dsa-2023-192" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1386" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T08:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-959v-9j99-99w5/GHSA-959v-9j99-99w5.json b/advisories/unreviewed/2024/02/GHSA-959v-9j99-99w5/GHSA-959v-9j99-99w5.json new file mode 100644 index 00000000000..c24f461de13 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-959v-9j99-99w5/GHSA-959v-9j99-99w5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-959v-9j99-99w5", + "modified": "2024-02-06T09:31:38Z", + "published": "2024-02-06T09:31:38Z", + "aliases": [ + "CVE-2023-32474" + ], + "details": "\nDell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this vulnerability during installation leading to arbitrary folder or file deletion\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32474" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000215216/dsa-2023-182-dell" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1386" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T08:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9fc8-v7vw-438w/GHSA-9fc8-v7vw-438w.json b/advisories/unreviewed/2024/02/GHSA-9fc8-v7vw-438w/GHSA-9fc8-v7vw-438w.json new file mode 100644 index 00000000000..f97300fc137 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9fc8-v7vw-438w/GHSA-9fc8-v7vw-438w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fc8-v7vw-438w", + "modified": "2024-02-06T09:31:38Z", + "published": "2024-02-06T09:31:38Z", + "aliases": [ + "CVE-2023-32451" + ], + "details": "\nDell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation and uninstallation\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32451" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000215216/dsa-2023-182-dell" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-272" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T08:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-crhq-582w-h987/GHSA-crhq-582w-h987.json b/advisories/unreviewed/2024/02/GHSA-crhq-582w-h987/GHSA-crhq-582w-h987.json new file mode 100644 index 00000000000..f7b5b6050c5 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-crhq-582w-h987/GHSA-crhq-582w-h987.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crhq-582w-h987", + "modified": "2024-02-06T09:31:38Z", + "published": "2024-02-06T09:31:38Z", + "aliases": [ + "CVE-2024-22433" + ], + "details": "\nDell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated attacker could potentially exploit this vulnerability leading to a loss of Confidentiality, Integrity, Protection, and remote takeover of the system. This is a high-severity vulnerability as it allows an attacker to take complete control of DP Search to affect downstream protected devices.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22433" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000221720/dsa-2024-063-security-update-for-dell-data-protection-search-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-538" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mm8x-p4pr-4p9f/GHSA-mm8x-p4pr-4p9f.json b/advisories/unreviewed/2024/02/GHSA-mm8x-p4pr-4p9f/GHSA-mm8x-p4pr-4p9f.json new file mode 100644 index 00000000000..acf8fd5ae5b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mm8x-p4pr-4p9f/GHSA-mm8x-p4pr-4p9f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm8x-p4pr-4p9f", + "modified": "2024-02-06T09:31:38Z", + "published": "2024-02-06T09:31:38Z", + "aliases": [ + "CVE-2023-52239" + ], + "details": "The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52239" + }, + { + "type": "WEB", + "url": "https://ds-security.com/post/xml_external_entity_injection_magic_xpi/" + }, + { + "type": "WEB", + "url": "https://www2.magicsoftware.com/ver/docs/Downloads/Magicxpi/4.14/Windows/ReleaseNotes4.14.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p8pq-6r4w-c75v/GHSA-p8pq-6r4w-c75v.json b/advisories/unreviewed/2024/02/GHSA-p8pq-6r4w-c75v/GHSA-p8pq-6r4w-c75v.json new file mode 100644 index 00000000000..8fc428637de --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p8pq-6r4w-c75v/GHSA-p8pq-6r4w-c75v.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8pq-6r4w-c75v", + "modified": "2024-02-06T09:31:38Z", + "published": "2024-02-06T09:31:38Z", + "aliases": [ + "CVE-2024-0684" + ], + "details": "A flaw was found in the GNU coreutils \"split\" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0684" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-0684" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258948" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/01/18/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T09:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pcmw-6hxc-hqmx/GHSA-pcmw-6hxc-hqmx.json b/advisories/unreviewed/2024/02/GHSA-pcmw-6hxc-hqmx/GHSA-pcmw-6hxc-hqmx.json new file mode 100644 index 00000000000..69f177ed106 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pcmw-6hxc-hqmx/GHSA-pcmw-6hxc-hqmx.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcmw-6hxc-hqmx", + "modified": "2024-02-06T09:31:38Z", + "published": "2024-02-06T09:31:38Z", + "aliases": [ + "CVE-2024-22365" + ], + "details": "linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22365" + }, + { + "type": "WEB", + "url": "https://github.com/linux-pam/linux-pam/commit/031bb5a5d0d950253b68138b498dc93be69a64cb" + }, + { + "type": "WEB", + "url": "https://github.com/linux-pam/linux-pam" + }, + { + "type": "WEB", + "url": "https://github.com/linux-pam/linux-pam/releases/tag/v1.6.0" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/18/3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T08:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-r3mr-jgh6-phpp/GHSA-r3mr-jgh6-phpp.json b/advisories/unreviewed/2024/02/GHSA-r3mr-jgh6-phpp/GHSA-r3mr-jgh6-phpp.json new file mode 100644 index 00000000000..ab2c50fd7d8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-r3mr-jgh6-phpp/GHSA-r3mr-jgh6-phpp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3mr-jgh6-phpp", + "modified": "2024-02-06T09:31:37Z", + "published": "2024-02-06T09:31:37Z", + "aliases": [ + "CVE-2023-25543" + ], + "details": "\nDell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privileged malicious user could potentially exploit this vulnerability in order to elevate privileges on the system. \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25543" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000209464/dsa-2023-075" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-whvw-59jf-hrx9/GHSA-whvw-59jf-hrx9.json b/advisories/unreviewed/2024/02/GHSA-whvw-59jf-hrx9/GHSA-whvw-59jf-hrx9.json new file mode 100644 index 00000000000..7a6d766a2fa --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-whvw-59jf-hrx9/GHSA-whvw-59jf-hrx9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whvw-59jf-hrx9", + "modified": "2024-02-06T09:31:38Z", + "published": "2024-02-06T09:31:38Z", + "aliases": [ + "CVE-2023-32479" + ], + "details": "\nDell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32479" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000215881/dsa-2023-260" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T08:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-x379-72wq-8vwf/GHSA-x379-72wq-8vwf.json b/advisories/unreviewed/2024/02/GHSA-x379-72wq-8vwf/GHSA-x379-72wq-8vwf.json new file mode 100644 index 00000000000..b6188d8f3cc --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-x379-72wq-8vwf/GHSA-x379-72wq-8vwf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x379-72wq-8vwf", + "modified": "2024-02-06T09:31:38Z", + "published": "2024-02-06T09:31:38Z", + "aliases": [ + "CVE-2023-28063" + ], + "details": "\nDell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28063" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000214780/dsa-2023-176-dell-client-bios-security-update-for-a-signed-to-unsigned-conversion-error-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-195" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T08:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-xc8c-3cmg-p9qr/GHSA-xc8c-3cmg-p9qr.json b/advisories/unreviewed/2024/02/GHSA-xc8c-3cmg-p9qr/GHSA-xc8c-3cmg-p9qr.json new file mode 100644 index 00000000000..9d8777a7dc5 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-xc8c-3cmg-p9qr/GHSA-xc8c-3cmg-p9qr.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc8c-3cmg-p9qr", + "modified": "2024-02-06T09:31:38Z", + "published": "2024-02-06T09:31:38Z", + "aliases": [ + "CVE-2024-25140" + ], + "details": "A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5.5.7.3.3), valid from 2023 until 2033. This is potentially unwanted, e.g., because there is no public documentation of security measures for the private key, and arbitrary software could be signed if the private key were to be compromised. NOTE: the vendor's position is \"we do not have EV cert, so we use test cert as a workaround.\" Insertion into Trusted Root Certification Authorities was the originally intended behavior, and the UI ensured that the certificate installation step (checked by default) was visible to the user before proceeding with the product installation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25140" + }, + { + "type": "WEB", + "url": "https://github.com/rustdesk/rustdesk/discussions/6444" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=39256493" + }, + { + "type": "WEB", + "url": "https://serverfault.com/questions/837994" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T09:15:52Z" + } +} \ No newline at end of file