본문 바로가기

취약점 정보1

Linux group_info Denial Of Service Linux group_info refcounter overflow memory corruption denial of service exploit. /* * DoS poc for CVE-2014-2851 * Linux group_info refcounter overflow memory corruption * * https://lkml.org/lkml/2014/4/10/736 * * @Tohmaxx - http://thomaspollet.blogspot.be * * If the app doesn't crash your system, try a different count (argv[1]) * Execution takes a while because 2^32 socket() calls * */ #include.. 더보기
Adobe Flash Player Regular Expression Heap Overflow This Metasploit module exploits a vulnerability found in the ActiveX component of Adobe Flash Player before 11.5.502.149. By supplying a specially crafted swf file with special regex value, it is possible to trigger an memory corruption, which results in remote code execution under the context of the user, as exploited in the wild in February 2013. This Metasploit module has been tested successf.. 더보기
2014-04-19 취약점 정리 Oracle MySQL Server CVE-2014-2432 Remote Security Vulnerability 2014-04-19 http://www.securityfocus.com/bid/66875 Oracle MySQL Server CVE-2014-2438 Remote Security Vulnerability 2014-04-19 http://www.securityfocus.com/bid/66846 Oracle MySQL Client CVE-2014-2440 Remote Security Vulnerability 2014-04-19 http://www.securityfocus.com/bid/66850 Oracle MySQL Server CVE-2014-2436 Remote Security Vulner.. 더보기
CVE-2014-2597 - Denial of Service in PCNetSoftware RAC Server Vulnerability title: Denial of Service in PCNetSoftware RAC Server CVE: CVE-2014-2597 Vendor: PCNetSoftware Product: RAC Server Affected version: 4.0.4, 4.0.5 Fixed version: N/A Reported by: Kyriakos Economou Details: Latest and possibly earlier versions of RAC Server software are vulnerable to local DoS attacks that can cause either to disable the keyboard input or to kill the system through a .. 더보기
2014-04-17 취약점 정리 Oracle Java SE CVE-2014-2421 Remote Security Vulnerability 2014-04-17 http://www.securityfocus.com/bid/66881 Oracle Java SE CVE-2014-2398 Remote Security Vulnerability 2014-04-17 http://www.securityfocus.com/bid/66920 Oracle Java SE CVE-2014-0451 Remote Security Vulnerability 2014-04-17 http://www.securityfocus.com/bid/66879 Oracle Java SE CVE-2014-0460 Remote Security Vulnerability 2014-04-17 h.. 더보기
MS14-012 Microsoft Internet Explorer CMarkup Use-After-Free ## # This module requires Metasploit: http//metasploit.com/download # Current source: https://github.com/rapid7/metasploit-framework ## require 'msf/core' class Metasploit3 "MS14-012 Microsoft Internet Explorer CMarkup Use-After-Free", 'Descript.. 더보기
자바 업데이트 권고 이번에 Oracle Java SE Runtime Environment 8과 7이 각각 업데이트 되었습니다. 기본적으로 Java는 자동 업데이트를 지원하고 있습니다만, 만약 업데이트가 되지 않았다면 확인 후 업데이트하시기 바랍니다. * Oracle Critical Patch Update Advisory - April 2014 - http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html * Java™ SE Development Kit 8, Update 5 (JDK 8u5) - http://www.oracle.com/technetwork/java/javase/8train-relnotes-latest-2153846.html * Java™.. 더보기
DNS 포이즈닝 캐쉬 공격주의 DNS 포이즈닝 캐쉬 공격주의 https://www.jpcert.or.jp/at/2014/at140016.html 더보기
2014-04-16 취약점정리 OpenJPEG CVE-2013-6887 Multiple Denial Of Service Vulnerabilities 2014-04-15 http://www.securityfocus.com/bid/64140 OpenJPEG CVE-2013-6053 Multiple Out of Bounds Memory Corruption Vulnerabilities 2014-04-15 http://www.securityfocus.com/bid/64121 OpenJPEG CVE-2013-6052 Multiple Out of Bounds Memory Corruption Vulnerabilities 2014-04-15 http://www.securityfocus.com/bid/64118 OpenJPEG CVE-2013-6054.. 더보기
RSA BSAFE® Micro Edition Suite Security Up date for BEAST (Browser Exploit Against SSL/TLS) attacks -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ESA-2012-032: RSA BSAFE® Micro Edition Suite Security Update for BEAST (Browser Exploit Against SSL/TLS) attacks EMC Identifier: ESA-2012-032 CVE Identifier: CVE-2011-3389 Severity Rating: CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N) Affected Products: All versions of RSA BSAFE Micro Edition Suite (MES) except 4.0.5 and 3.2.6, all platforms U.. 더보기