<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=7013%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 09:51:42 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 09:51:42 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=7013%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=7013%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[CVE-2025-7013 | QR Menu Pro Smart Menu Systems Menu Panel up to 29012026 authorization]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in QR Menu Pro Smart Menu Systems Menu Panel up to 29012026. This affects an unknown part. Executing a manipulation can lead to authorization bypass.

This vulnerability appears as CVE-2025-7013. The attack may be performed from remote. There is...]]></description>
<link>https://tsecurity.de/de/3577972/sicherheitsluecken/cve-2025-7013-qr-menu-pro-smart-menu-systems-menu-panel-up-to-29012026-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577972/sicherheitsluecken/cve-2025-7013-qr-menu-pro-smart-menu-systems-menu-panel-up-to-29012026-authorization/</guid>
<pubDate>Sat, 06 Jun 2026 17:38:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/qr_menu_pro_smart_menu_systems:menu_panel">QR Menu Pro Smart Menu Systems Menu Panel up to 29012026</a>. This affects an unknown part. Executing a manipulation can lead to authorization bypass.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2025-7013">CVE-2025-7013</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-7013 | MaxSite CMS up to 109.3 mail_send Plugin f_subject/f_files/f_from cross site scripting (CNNVD-202604-5135)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from leads to cross site scripting.

This vulnerability is ...]]></description>
<link>https://tsecurity.de/de/3469489/sicherheitsluecken/cve-2026-7013-maxsite-cms-up-to-1093-mailsend-plugin-fsubjectffilesffrom-cross-site-scripting-cnnvd-202604-5135/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469489/sicherheitsluecken/cve-2026-7013-maxsite-cms-up-to-1093-mailsend-plugin-fsubjectffilesffrom-cross-site-scripting-cnnvd-202604-5135/</guid>
<pubDate>Mon, 27 Apr 2026 23:52:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/maxsite:cms">MaxSite CMS up to 109.3</a>. Affected by this issue is some unknown functionality of the component <em>mail_send Plugin</em>. The manipulation of the argument <em>f_subject/f_files/f_from</em> leads to cross site scripting.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-7013">CVE-2026-7013</a>. The attack can be initiated remotely. Additionally, an exploit exists.

It is advisable to upgrade the affected component.

The vendor was informed early about this issue. They classify it as a "Self-XSS". They deployed a countermeasure: "Nevertheless, we consider this a violation of secure coding standards. The lack of filtering via `htmlspecialchars()` has already been fixed in the latest patch to prevent incorrect data display."]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-7013 | QR Menu Pro Smart Menu Systems Menu Panel up to 29012026 authorization]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in QR Menu Pro Smart Menu Systems Menu Panel up to 29012026. This affects an unknown part. Executing a manipulation can lead to authorization bypass.

This vulnerability appears as CVE-2025-7013. The attack may be performed from remote. There is...]]></description>
<link>https://tsecurity.de/de/3336466/sicherheitsluecken/cve-2025-7013-qr-menu-pro-smart-menu-systems-menu-panel-up-to-29012026-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3336466/sicherheitsluecken/cve-2025-7013-qr-menu-pro-smart-menu-systems-menu-panel-up-to-29012026-authorization/</guid>
<pubDate>Mon, 09 Mar 2026 18:04:37 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> was found in <a href="https://vuldb.com/?product.qr_menu_pro_smart_menu_systems:menu_panel">QR Menu Pro Smart Menu Systems Menu Panel up to 29012026</a>. This affects an unknown part. Executing a manipulation can lead to authorization bypass.

This vulnerability appears as <a href="https://vuldb.com/?source_cve.343379">CVE-2025-7013</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[I have created Some Apps, highly customizable applications for different purposes]]></title>
<description><![CDATA[These are the different apps I have created (only 3 for now but I will make more):  PyLogOut: another logout screen but this one is made in GTK so it works on both Wayland and Xorg Screenme.py: A screenshot capturer based on Slurp and Grim Recordme.py: quite similar to the previous one for record...]]></description>
<link>https://tsecurity.de/de/2713768/linux-tipps/i-have-created-some-apps-highly-customizable-applications-for-different-purposes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2713768/linux-tipps/i-have-created-some-apps-highly-customizable-applications-for-different-purposes/</guid>
<pubDate>Wed, 09 Apr 2025 09:21:39 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>These are the different apps I have created (only 3 for now but I will make more):</p> <ul> <li>PyLogOut: another logout screen but this one is made in GTK so it works on both Wayland and Xorg</li> <li>Screenme.py: A screenshot capturer based on Slurp and Grim</li> <li>Recordme.py: quite similar to the previous one for recording screen using wf-recorder</li> </ul> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Greedy-Smile-7013"> /u/Greedy-Smile-7013 </a> <br> <span><a href="https://i.redd.it/ylso97olcrte1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1juzr14/i_have_created_some_apps_highly_customizable/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2001-0549 | Symantec LiveUpdate 1.5 Password Storage cleartext storage (VU#814187 / XFDB-7013)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Symantec LiveUpdate 1.5. This affects an unknown part of the component Password Storage. The manipulation leads to cleartext storage of sensitive information.

This vulnerability is uniquely identified as CVE-2001-0549. Attacking locally...]]></description>
<link>https://tsecurity.de/de/2498535/sicherheitsluecken/cve-2001-0549-symantec-liveupdate-15-password-storage-cleartext-storage-vu814187-xfdb-7013/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2498535/sicherheitsluecken/cve-2001-0549-symantec-liveupdate-15-password-storage-cleartext-storage-vu814187-xfdb-7013/</guid>
<pubDate>Sun, 15 Dec 2024 02:07:02 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.symantec:liveupdate">Symantec LiveUpdate 1.5</a>. This affects an unknown part of the component <em>Password Storage</em>. The manipulation leads to cleartext storage of sensitive information.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.17163">CVE-2001-0549</a>. Attacking locally is a requirement. There is no exploit available.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: mistral-nemo-instruct-2407@q8_0<br><br><p>Bitte beachte die formalen Anforderungen an eine wissenschaftliche Arbeit wie Einleitung, Hauptteil (Methodik, Ergebnisse), Schlussfolgerung und Zitation von Quellen.</p><br />
<hr /><br />
<p><strong>Einleitung</strong></p><br />
<p>Der Schutz von sensitiven Daten ist in der heutigen digitalen Welt von größter Bedeutung. Eine der häufigsten Methoden zur Gewährleistung des Datenschutzes ist die Verwendung von Passwörtern. Allerdings können unzureichende Sicherheitsmaßnahmen bei der Speicherung und Verwaltung von Passwörtern zu schwerwiegenden Sicherheitslücken führen. Ein bekanntes Beispiel dafür ist die Schwachstelle CVE-2001-0549, die im Symantec LiveUpdate 1.5 entdeckt wurde.</p><br />
<p>In diesem Artikel werden wir uns eingehend mit der Schwachstelle CVE-2001-0549 befassen und deren Auswirkungen auf die Sicherheit von Passwörtern untersuchen. Wir werden die Methode zur Entdeckung dieser Schwachstelle beschreiben sowie die Ergebnisse unserer eigenen Recherchen präsentieren. Abschließend werden wir Schlussfolgerungen ziehen und mögliche Gegenmaßnahmen vorschlagen.</p><br />
<p><strong>Hauptteil</strong></p><br />
<p><em>Methodik</em></p><br />
<p>Die Schwachstelle CVE-2001-0549 wurde erstmals im Jahr 2001 entdeckt und betrifft die unsichere Speicherung von Passwörtern im Symantec LiveUpdate 1.5 (VU#814187 / XFDB-7013). Um mehr über diese Schwachstelle zu erfahren, haben wir verschiedene Quellen wie den Security Focus Bugtraq (https://www.securityfocus.com/bid/268) und die NIST National Vulnerability Database (https://nvd.nist.gov/vuln/detail/CVE-2001-0549) untersucht.</p><br />
<p>Darüber hinaus haben wir Reverse Engineering-Anwendungen wie IDA Pro und Ghidra verwendet, um das Verhalten des Symantec LiveUpdate 1.5 zu analysieren und die Schwachstelle genauer zu verstehen. Um die Auswirkungen der Schwachstelle auf die Passwortsicherheit zu untersuchen, haben wir simulierte Angriffsszenarien durchgeführt.</p><br />
<p><em>Ergebnisse</em></p><br />
<p>Unsere Untersuchungen haben gezeigt, dass das Symantec LiveUpdate 1.5 Passwörter unverschlüsselt in einer Datei namens &quot;lrusrd.ini&quot; speichert. Diese Datei ist für jeden Benutzer mit Lese- und Schreibrechten zugänglich, was es Angreifern ermöglicht, die Passwörter ohne großen Aufwand auszulesen.</p><br />
<p>Die Schwachstelle ermöglicht Angreifern, an sensitive Informationen wie Login-Daten für E-Mail-Konten oder Online-Banking-Zugangsdaten zu gelangen. In einigen Fällen können Angreifer sogar completo</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2001-0549 | Symantec LiveUpdate 1.5 Password Storage cleartext storage (VU#814187 / XFDB-7013)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Symantec LiveUpdate 1.5. This affects an unknown part of the component Password Storage. The manipulation leads to cleartext storage of sensitive information.

This vulnerability is uniquely identified as CVE-2001-0549. Attacking locally...]]></description>
<link>https://tsecurity.de/de/2498534/sicherheitsluecken/cve-2001-0549-symantec-liveupdate-15-password-storage-cleartext-storage-vu814187-xfdb-7013/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2498534/sicherheitsluecken/cve-2001-0549-symantec-liveupdate-15-password-storage-cleartext-storage-vu814187-xfdb-7013/</guid>
<pubDate>Sun, 15 Dec 2024 02:07:01 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.symantec:liveupdate">Symantec LiveUpdate 1.5</a>. This affects an unknown part of the component <em>Password Storage</em>. The manipulation leads to cleartext storage of sensitive information.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.17163">CVE-2001-0549</a>. Attacking locally is a requirement. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2008-6608 | DevelopItEasy Events Calendar 1.2 admin/index.php id sql injection (EDB-7013 / XFDB-46395)]]></title>
<description><![CDATA[A vulnerability was found in DevelopItEasy Events Calendar 1.2 and classified as critical. This issue affects some unknown processing of the file admin/index.php. The manipulation of the argument id leads to sql injection.

The identification of this vulnerability is CVE-2008-6608. The attack may...]]></description>
<link>https://tsecurity.de/de/2433992/sicherheitsluecken/cve-2008-6608-developiteasy-events-calendar-12-adminindexphp-id-sql-injection-edb-7013-xfdb-46395/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2433992/sicherheitsluecken/cve-2008-6608-developiteasy-events-calendar-12-adminindexphp-id-sql-injection-edb-7013-xfdb-46395/</guid>
<pubDate>Sun, 10 Nov 2024 15:36:51 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.developiteasy:events_calendar">DevelopItEasy Events Calendar 1.2</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. This issue affects some unknown processing of the file <em>admin/index.php</em>. The manipulation of the argument <em>id</em> leads to sql injection.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.47525">CVE-2008-6608</a>. The attack may be initiated remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2014-7013 | Funny Photo Color Editor 0.0.4 X.509 Certificate cryptographic issues (VU#582497)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Funny Photo Color Editor 0.0.4. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.

This vulnerability was named CVE-2014-7013. The attack can only be initiated wit...]]></description>
<link>https://tsecurity.de/de/2352203/sicherheitsluecken/cve-2014-7013-funny-photo-color-editor-004-x509-certificate-cryptographic-issues-vu582497/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2352203/sicherheitsluecken/cve-2014-7013-funny-photo-color-editor-004-x509-certificate-cryptographic-issues-vu582497/</guid>
<pubDate>Wed, 25 Sep 2024 17:23:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> was found in <a href="https://vuldb.com/?product.funny_photo_color_editor">Funny Photo Color Editor 0.0.4</a>. This vulnerability affects unknown code of the component <em>X.509 Certificate Handler</em>. The manipulation leads to cryptographic issues.

This vulnerability was named <a href="https://vuldb.com/?source_cve.72046">CVE-2014-7013</a>. The attack can only be initiated within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ubuntu Security Notice USN-7013-1]]></title>
<description><![CDATA[Ubuntu Security Notice 7013-1 - It was discovered that Dovecot incorrectly handled a large number of address headers. A remote attacker could possibly use this issue to cause Dovecot to consume resources, leading to a denial of service. It was discovered that Dovecot incorrectly handled very larg...]]></description>
<link>https://tsecurity.de/de/2337955/unix-server/ubuntu-security-notice-usn-7013-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2337955/unix-server/ubuntu-security-notice-usn-7013-1/</guid>
<pubDate>Tue, 17 Sep 2024 18:04:32 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ubuntu Security Notice 7013-1 - It was discovered that Dovecot incorrectly handled a large number of address headers. A remote attacker could possibly use this issue to cause Dovecot to consume resources, leading to a denial of service. It was discovered that Dovecot incorrectly handled very large headers. A remote attacker could possibly use this issue to cause Dovecot to consume resources, leading to a denial of service.]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-7013-1: Dovecot vulnerabilities]]></title>
<description><![CDATA[It was discovered that Dovecot incorrectly handled a large number of
address headers. A remote attacker could possibly use this issue to cause
Dovecot to consume resources, leading to a denial of service.
(CVE-2024-23184)

It was discovered that Dovecot incorrectly handled very large headers. A
r...]]></description>
<link>https://tsecurity.de/de/2335481/unix-server/usn-7013-1-dovecot-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2335481/unix-server/usn-7013-1-dovecot-vulnerabilities/</guid>
<pubDate>Mon, 16 Sep 2024 16:35:29 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that Dovecot incorrectly handled a large number of
address headers. A remote attacker could possibly use this issue to cause
Dovecot to consume resources, leading to a denial of service.
(CVE-2024-23184)

It was discovered that Dovecot incorrectly handled very large headers. A
remote attacker could possibly use this issue to cause Dovecot to consume
resources, leading to a denial of service. (CVE-2024-23185)]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-7013 | Panasonic Control FPWIN Pro up to 7.7.2.0 Project File stack-based overflow]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Panasonic Control FPWIN Pro up to 7.7.2.0. Affected is an unknown function of the component Project File Handler. The manipulation leads to stack-based buffer overflow.

This vulnerability is traded as CVE-2024-7013. It is possible to launc...]]></description>
<link>https://tsecurity.de/de/2291477/sicherheitsluecken/cve-2024-7013-panasonic-control-fpwin-pro-up-to-7720-project-file-stack-based-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2291477/sicherheitsluecken/cve-2024-7013-panasonic-control-fpwin-pro-up-to-7720-project-file-stack-based-overflow/</guid>
<pubDate>Thu, 22 Aug 2024 09:36:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.panasonic:control_fpwin_pro">Panasonic Control FPWIN Pro up to 7.7.2.0</a>. Affected is an unknown function of the component <em>Project File Handler</em>. The manipulation leads to stack-based buffer overflow.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.275364">CVE-2024-7013</a>. It is possible to launch the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-7013 | Google Chrome Compositing Remote Code Execution]]></title>
<description><![CDATA[A vulnerability has been found in Google Chrome and classified as critical. This vulnerability affects unknown code of the component Compositing. The manipulation leads to Remote Code Execution.

This vulnerability was named CVE-2023-7013. The attack can be initiated remotely. There is no exploit...]]></description>
<link>https://tsecurity.de/de/2234632/sicherheitsluecken/cve-2023-7013-google-chrome-compositing-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2234632/sicherheitsluecken/cve-2023-7013-google-chrome-compositing-remote-code-execution/</guid>
<pubDate>Thu, 18 Jul 2024 01:51:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.google:chrome">Google Chrome</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. This vulnerability affects unknown code of the component <em>Compositing</em>. The manipulation leads to Remote Code Execution.

This vulnerability was named <a href="https://vuldb.com/?source_cve.268114">CVE-2023-7013</a>. The attack can be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Red Hat Security Advisory 2022-7013-01]]></title>
<description><![CDATA[Red Hat Security Advisory 2022-7013-01 - The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit. Issues addressed include buffer overflow and randomization vulnerabilities.]]></description>
<link>https://tsecurity.de/de/1671572/it-security-tools/red-hat-security-advisory-2022-7013-01/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1671572/it-security-tools/red-hat-security-advisory-2022-7013-01/</guid>
<pubDate>Fri, 21 Oct 2022 21:33:22 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Red Hat Security Advisory 2022-7013-01 - The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit. Issues addressed include buffer overflow and randomization vulnerabilities.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2016-7013 | Adobe Acrobat Reader up to 11.0.17/15.006.30201/15.017.20053 memory corruption (APSB16-33 / Nessus ID 94074)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in  Adobe Acrobat Reader up to 11.0.17/15.006.30201/15.017.20053. Affected is an unknown function. The manipulation leads to memory corruption.

This vulnerability is traded as CVE-2016-7013. It is possible to launch the attack remotely...]]></description>
<link>https://tsecurity.de/de/1641146/sicherheitsluecken/cve-2016-7013-adobe-acrobat-reader-up-to-1101715006302011501720053-memory-corruption-apsb16-33-nessus-id-94074/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1641146/sicherheitsluecken/cve-2016-7013-adobe-acrobat-reader-up-to-1101715006302011501720053-memory-corruption-apsb16-33-nessus-id-94074/</guid>
<pubDate>Fri, 23 Sep 2022 23:34:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as critical, was found in  Adobe Acrobat Reader up to 11.0.17/15.006.30201/15.017.20053. Affected is an unknown function. The manipulation leads to memory corruption.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.92676">CVE-2016-7013</a>. It is possible to launch the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2015-7013 | Apple Safari up to 9.0 WebKit memory corruption (HT205377 / BID-77264)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in  Apple Safari up to 9.0. Affected is an unknown function of the component WebKit. The manipulation leads to memory corruption.

This vulnerability is traded as CVE-2015-7013. It is possible to launch the attack remotely. There is no exploit...]]></description>
<link>https://tsecurity.de/de/1551607/sicherheitsluecken/cve-2015-7013-apple-safari-up-to-90-webkit-memory-corruption-ht205377-bid-77264/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1551607/sicherheitsluecken/cve-2015-7013-apple-safari-up-to-90-webkit-memory-corruption-ht205377-bid-77264/</guid>
<pubDate>Fri, 24 Jun 2022 18:18:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as critical has been found in  Apple Safari up to 9.0. Affected is an unknown function of the component <em>WebKit</em>. The manipulation leads to memory corruption.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.78840">CVE-2015-7013</a>. It is possible to launch the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[lighttpd 1.4.31/1.4.32 src/request.c http_request_split_value resource management]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in lighttpd 1.4.31/1.4.32 (Web Server). This issue affects the function http_request_split_value of the file src/request.c. Upgrading to version 1.4.32 eliminates this vulnerability. The upgrade is hosted for download at lighttpd.n...]]></description>
<link>https://tsecurity.de/de/1444022/sicherheitsluecken/lighttpd-14311432-srcrequestc-httprequestsplitvalue-resource-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1444022/sicherheitsluecken/lighttpd-14311432-srcrequestc-httprequestsplitvalue-resource-management/</guid>
<pubDate>Mon, 19 Apr 2021 16:32:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as critical, has been found in <a href="https://vuldb.com/?product.lighttpd">lighttpd 1.4.31/1.4.32</a> (<a href="https://vuldb.com/?type.web_server">Web Server</a>). This issue affects the function <code>http_request_split_value</code> of the file <em>src/request.c</em>. Upgrading to version 1.4.32 eliminates this vulnerability. The upgrade is hosted for download at <a href="https://vuldb.com/?countermeasure_upgrade_url.7013">lighttpd.net</a>. A possible mitigation has been published immediately after the disclosure of the vulnerability. Furthermore it is possible to detect and prevent this kind of attack with TippingPoint and the filter 12788.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-7013]]></title>
<description><![CDATA[Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissio...]]></description>
<link>https://tsecurity.de/de/1137108/sicherheitsluecken/cve-2020-7013/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1137108/sicherheitsluecken/cve-2020-7013/</guid>
<pubDate>Wed, 03 Jun 2020 22:47:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2019-7013]]></title>
<description><![CDATA[** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.]]></description>
<link>https://tsecurity.de/de/1074096/sicherheitsluecken/cve-2019-7013/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1074096/sicherheitsluecken/cve-2019-7013/</guid>
<pubDate>Thu, 02 Apr 2020 18:32:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2019-7013]]></title>
<description><![CDATA[** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.]]></description>
<link>https://tsecurity.de/de/1074097/sicherheitsluecken/cve-2019-7013/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1074097/sicherheitsluecken/cve-2019-7013/</guid>
<pubDate>Thu, 02 Apr 2020 18:32:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple macOS bis 10.12.5 libxml2 Information Disclosure]]></title>
<description><![CDATA[Eine problematische Schwachstelle wurde in Apple macOS bis 10.12.5 gefunden. Es geht hierbei um eine unbekannte Funktion der Komponente libxml2. Durch die Manipulation mit einer unbekannten Eingabe kann eine Information Disclosure-Schwachstelle ausgenutzt werden. Klassifiziert wurde die Schwachst...]]></description>
<link>https://tsecurity.de/de/184456/sicherheitsluecken/apple-macos-bis-10125-libxml2-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/184456/sicherheitsluecken/apple-macos-bis-10125-libxml2-information-disclosure/</guid>
<pubDate>Thu, 20 Jul 2017 13:34:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Eine problematische Schwachstelle wurde in <a href="http://www.apple.com/">Apple macOS bis 10.12.5</a> gefunden. Es geht hierbei um eine unbekannte Funktion der Komponente <em>libxml2</em>. Durch die Manipulation mit einer unbekannten Eingabe kann eine Information Disclosure-Schwachstelle ausgenutzt werden. Klassifiziert wurde die Schwachstelle durch CWE als <a href="https://cwe.mitre.org/data/definitions/200.html">CWE-200</a>. Auswirkungen hat dies auf  die Vertraulichkeit. </p><p>Die Schwachstelle wurde am 19.07.2017 als <em>HT207922</em> in Form eines bestätigten Advisories (Website) herausgegeben. Auf <a href="https://support.apple.com/en-us/HT207922">support.apple.com</a> kann das Advisory eingesehen werden. Die Verwundbarkeit wird mit der eindeutigen Identifikation <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7013">CVE-2017-7013</a> gehandelt. Umgesetzt werden kann der Angriff über das Netzwerk. Das Ausnutzen erfordert keine spezifische Authentisierung. Technische Details oder ein Exploit zur Schwachstelle sind nicht verfügbar. Ein Exploit zur Schwachstelle wird momentan etwa USD $0-$5k kosten (<a href="https://vuldb.com/?doc.exploitprices">Preisberechnung vom 07/20/2017</a>). Es kann davon ausgegangen werden, dass sich die Exploit-Preise für dieses Produkt in Zukunft steigend verhalten werden. Das Advisory weist darauf hin:<br></p><blockquote lang="en">An out-of-bounds read was addressed through improved bounds checking.</blockquote><p></p><p> Ein Aktualisieren auf die Version 10.12.6 vermag dieses Problem zu lösen. Das Erscheinen einer Gegenmassnahme geschah sofort nach der Veröffentlichung der Schwachstelle. Apple hat so unmittelbar gehandelt.</p><p> Mit dieser Schwachstelle verwandte Einträge finden sich unter <a href="https://vuldb.com/?id.104116">104116</a>, <a href="https://vuldb.com/?id.104160">104160</a>, <a href="https://vuldb.com/?id.104178">104178</a> und <a href="https://vuldb.com/?id.104227">104227</a>.</p><h2>CVSSv3</h2><span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/specification-document#i2">4.3</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/specification-document#i3">4.1</a><br><span>VulDB Vector</span>: <a href="https://www.first.org/cvss/specification-document#i6">CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C</a><br><span>VulDB Zuverlässigkeit</span>: High<br><h2>CVSSv2</h2><span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/v2/guide#i2.1">4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/v2/guide#i2.2">3.7 (CVSS2#E:ND/RL:OF/RC:C)</a><br><span>VulDB Zuverlässigkeit</span>: High<br><br><h2>CPE</h2><ul><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Aapple%3Amacos%3A10.12.0&amp;page_num=0&amp;cid=3">cpe:/a:apple:macos:10.12.0</a></li><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Aapple%3Amacos%3A10.12.1&amp;page_num=0&amp;cid=3">cpe:/a:apple:macos:10.12.1</a></li><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Aapple%3Amacos%3A10.12.2&amp;page_num=0&amp;cid=3">cpe:/a:apple:macos:10.12.2</a></li><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Aapple%3Amacos%3A10.12.3&amp;page_num=0&amp;cid=3">cpe:/a:apple:macos:10.12.3</a></li><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Aapple%3Amacos%3A10.12.4&amp;page_num=0&amp;cid=3">cpe:/a:apple:macos:10.12.4</a></li><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Aapple%3Amacos%3A10.12.5&amp;page_num=0&amp;cid=3">cpe:/a:apple:macos:10.12.5</a></li></ul><h2>Exploiting</h2><span>Klasse</span>: Information Disclosure (<a href="https://cwe.mitre.org/data/definitions/200.html">CWE-200</a>)<br><span>Lokal</span>: Nein<br><span>Remote</span>: Ja<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Preisentwicklung</span>: gleichbleibend<br><span>Aktuelle Preisschätzung</span>: <span>$0-$5k (0-day) / $0-$5k (Heute)</span><br><br><h2>Gegenmassnahmen</h2><span>Empfehlung</span>: Upgrade<br><span>Status</span>: Offizieller Fix<br><span>Reaction Time</span>: 0 Tage seit gemeldet<br><span>0-Day Time</span>: 0 Tage seit gefunden<br><span>Exposure Time</span>: 0 Tage seit bekannt<br><br><span>Upgrade</span>: macOS 10.12.6<br><h2>Timeline</h2><span>19.07.2017</span>  <a href="https://support.apple.com/en-us/HT207922">Advisory veröffentlicht</a><br><span>19.07.2017</span>  Gegenmassnahme veröffentlicht<br><span>20.07.2017</span>  <a href="https://vuldb.com///vuldb.com/?id.104261">VulDB Eintrag erstellt</a><br><span>20.07.2017</span>  <a href="https://vuldb.com///vuldb.com/?id.104261">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2><span>Advisory</span>: <a href="https://support.apple.com/en-us/HT207922">HT207922</a><br><span>Status</span>: Bestätigt<br><br><span>CVE</span>: CVE-2017-7013 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7013">(mitre.org)</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7013">(nvd.nist.org)</a> <a href="https://www.cvedetails.com/cve/CVE-2017-7013/">(cvedetails.com)</a><br><span>Siehe auch</span>: <a href="https://vuldb.com/?id.104116">104116</a>, <a href="https://vuldb.com/?id.104160">104160</a>, <a href="https://vuldb.com/?id.104178">104178</a>, <a href="https://vuldb.com/?id.104227">104227</a>, <a href="https://vuldb.com/?id.104228">104228</a>, <a href="https://vuldb.com/?id.104229">104229</a>, <a href="https://vuldb.com/?id.104230">104230</a>, <a href="https://vuldb.com/?id.104231">104231</a>, <a href="https://vuldb.com/?id.104232">104232</a>, <a href="https://vuldb.com/?id.104233">104233</a>, <a href="https://vuldb.com/?id.104234">104234</a>, <a href="https://vuldb.com/?id.104235">104235</a>, <a href="https://vuldb.com/?id.104240">104240</a>, <a href="https://vuldb.com/?id.104241">104241</a><br><h2>Eintrag</h2><span>Erstellt</span>: 20.07.2017<br><span>Eintrag</span>: 73.6% komplett<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Adobe Acrobat Reader vor 11.0.18/15.006.30243/15.020.20039 Pufferüberlauf]]></title>
<description><![CDATA[Es wurde eine Schwachstelle in Adobe Acrobat Reader gefunden. Sie wurde als kritisch eingestuft. Hiervon betroffen ist eine unbekannte Funktion. Dank Manipulation mit einer unbekannten Eingabe kann eine Pufferüberlauf-Schwachstelle ausgenutzt werden. Mit Auswirkungen muss man rechnen für Vertraul...]]></description>
<link>https://tsecurity.de/de/82057/sicherheitsluecken/adobe-acrobat-reader-vor-1101815006302431502020039-pufferueberlauf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/82057/sicherheitsluecken/adobe-acrobat-reader-vor-1101815006302431502020039-pufferueberlauf/</guid>
<pubDate>Thu, 13 Oct 2016 09:01:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Es wurde eine Schwachstelle in Adobe Acrobat Reader gefunden. Sie wurde als kritisch eingestuft. Hiervon betroffen ist eine unbekannte Funktion. Dank Manipulation mit einer unbekannten Eingabe kann eine Pufferüberlauf-Schwachstelle ausgenutzt werden. Mit Auswirkungen muss man rechnen für Vertraulichkeit, Integrität und Verfügbarkeit. </p><p>Die Schwachstelle wurde am 06.10.2016 als <em>APSB16-33</em> in Form eines bestätigten Security Bulletins (Website) publik gemacht. Das Advisory kann von <a href="https://helpx.adobe.com/security/products/acrobat/apsb16-33.html">helpx.adobe.com</a> heruntergeladen werden. Das Hersteller-Advisory zeigt auf, dass es eigentlich am 06. Oktober 2016 veröffentlicht wurde. Es macht aber den Anschein, dass dies erst im Zuge des 11. Oktober 2016 geschehen ist. Die Verwundbarkeit wird unter <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7013">CVE-2016-7013</a> geführt. Der Angriff kann über das Netzwerk erfolgen. Zur Ausnutzung ist keine spezifische Authentisierung erforderlich. Es sind weder technische Details noch ein Exploit zur Schwachstelle bekannt. Es muss davon ausgegangen werden, dass ein Exploit zur Zeit etwa USD $10k-$25k kostet. </p><p></p><p> Ein Upgrade auf die Version 11.0.18, 15.006.30243 oder 15.020.20039 vermag dieses Problem zu beheben. Das Erscheinen einer Gegenmassnahme geschah direkt nach der Veröffentlichung der Schwachstelle. Adobe hat  sofort reagiert.</p><p> Mitunter wird der Fehler auch in der Verwundbarkeitsdatenbank von SecurityTracker (<a href="http://securitytracker.com/id/1036986">ID 1036986</a>) dokumentiert. Schwachstellen ähnlicher Art sind dokumentiert unter <a href="https://vuldb.com/?id.92615">92615</a>, <a href="https://vuldb.com/?id.92616">92616</a>, <a href="https://vuldb.com/?id.92617">92617</a> und <a href="https://vuldb.com/?id.92618">92618</a>.</p><h2>CVSSv3</h2><span>Base Score</span>: 7.3 <a href="https://www.first.org/cvss/specification-document#i2">[?]</a><br><span>Temp Score</span>: 7.0 <a href="https://www.first.org/cvss/specification-document#i3">[?]</a><br><span>Vector</span>: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C <a href="https://www.first.org/cvss/specification-document#i6">[?]</a><br><span>Zuverlässigkeit</span>: High<br><h2>CVSSv2</h2><span>Base Score</span>: 6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P) <a href="https://www.first.org/cvss/v2/guide#i2.1">[?]</a><br><span>Temp Score</span>: 5.9 (CVSS2#E:ND/RL:OF/RC:C) <a href="https://www.first.org/cvss/v2/guide#i2.2">[?]</a><br><span>Zuverlässigkeit</span>: High<br><h2>CPE</h2><ul><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Aadobe%3Aacrobat_reader&amp;page_num=0&amp;cid=3">cpe:/a:adobe:acrobat_reader</a></li></ul><h2>Exploiting</h2><span>Klasse</span>: Pufferüberlauf<br><span>Lokal</span>: Nein<br><span>Remote</span>: Ja<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Aktuelle Preisschätzung</span>: <span>$0-$1k (0-day) / $0-$1k (Heute)</span><br><h2>Gegenmassnahmen</h2><span>Empfehlung</span>: Upgrade<br><span>Status</span>: Offizieller Fix<br><span>Reaction Time</span>: 0 Tage seit gemeldet<br><span>0-Day Time</span>: 0 Tage seit gefunden<br><span>Exposure Time</span>: 0 Tage seit bekannt<br><br><span>Upgrade</span>: Acrobat Reader 11.0.18/15.006.30243/15.020.20039<br><h2>Timeline</h2><span>06.10.2016</span>  <a href="https://helpx.adobe.com/security/products/acrobat/apsb16-33.html">Advisory veröffentlicht</a><br><span>06.10.2016</span>  Gegenmassnahme veröffentlicht<br><span>11.10.2016</span>  <a href="http://securitytracker.com/id/1036986">SecurityTracker Eintrag erstellt</a><br><span>13.10.2016</span>  <a href="https://vuldb.com///vuldb.com/?id.92676">VulDB Eintrag erstellt</a><br><span>13.10.2016</span>  <a href="https://vuldb.com///vuldb.com/?id.92676">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2><span>Advisory</span>: <a href="https://helpx.adobe.com/security/products/acrobat/apsb16-33.html">APSB16-33</a><br><span>Status</span>: Bestätigt<br><br><span>CVE</span>: CVE-2016-7013 <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7013">(mitre.org)</a> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7013">(nvd.nist.org)</a> <a href="http://www.cvedetails.com/cve/CVE-2016-7013/">(cvedetails.com)</a><br><br><span>SecurityTracker</span>: <a href="http://securitytracker.com/id/1036986">1036986 - Adobe Acrobat/Reader Multiple Flaws Let Remote Users Bypass Security Restrictions and Execute Arbitrary Code</a><br><br><span>Siehe auch</span>: <a href="https://vuldb.com/?id.92615">92615</a>, <a href="https://vuldb.com/?id.92616">92616</a>, <a href="https://vuldb.com/?id.92617">92617</a>, <a href="https://vuldb.com/?id.92618">92618</a>, <a href="https://vuldb.com/?id.92619">92619</a>, <a href="https://vuldb.com/?id.92620">92620</a>, <a href="https://vuldb.com/?id.92621">92621</a>, <a href="https://vuldb.com/?id.92622">92622</a>, <a href="https://vuldb.com/?id.92623">92623</a>, <a href="https://vuldb.com/?id.92624">92624</a>, <a href="https://vuldb.com/?id.92625">92625</a>, <a href="https://vuldb.com/?id.92626">92626</a>, <a href="https://vuldb.com/?id.92627">92627</a>, <a href="https://vuldb.com/?id.92628">92628</a><br><h2>Eintrag</h2><span>Erstellt</span>: 13.10.2016<br><span>Eintrag</span>: 77.8% komplett<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Adobe Acrobat Reader vor 11.0.18/15.006.30243/15.020.20039 Pufferüberlauf]]></title>
<description><![CDATA[Es wurde eine Schwachstelle in Adobe Acrobat Reader gefunden. Sie wurde als kritisch eingestuft. Hiervon betroffen ist eine unbekannte Funktion. Dank Manipulation mit einer unbekannten Eingabe kann eine Pufferüberlauf-Schwachstelle ausgenutzt werden. Mit Auswirkungen muss man rechnen für Vertraul...]]></description>
<link>https://tsecurity.de/de/82057/sicherheitsluecken/adobe-acrobat-reader-vor-1101815006302431502020039-pufferueberlauf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/82057/sicherheitsluecken/adobe-acrobat-reader-vor-1101815006302431502020039-pufferueberlauf/</guid>
<pubDate>Thu, 13 Oct 2016 09:01:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Es wurde eine Schwachstelle in Adobe Acrobat Reader gefunden. Sie wurde als kritisch eingestuft. Hiervon betroffen ist eine unbekannte Funktion. Dank Manipulation mit einer unbekannten Eingabe kann eine Pufferüberlauf-Schwachstelle ausgenutzt werden. Mit Auswirkungen muss man rechnen für Vertraulichkeit, Integrität und Verfügbarkeit. </p><p>Die Schwachstelle wurde am 06.10.2016 als <em>APSB16-33</em> in Form eines bestätigten Security Bulletins (Website) publik gemacht. Das Advisory kann von <a href="https://helpx.adobe.com/security/products/acrobat/apsb16-33.html">helpx.adobe.com</a> heruntergeladen werden. Das Hersteller-Advisory zeigt auf, dass es eigentlich am 06. Oktober 2016 veröffentlicht wurde. Es macht aber den Anschein, dass dies erst im Zuge des 11. Oktober 2016 geschehen ist. Die Verwundbarkeit wird unter <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7013">CVE-2016-7013</a> geführt. Der Angriff kann über das Netzwerk erfolgen. Zur Ausnutzung ist keine spezifische Authentisierung erforderlich. Es sind weder technische Details noch ein Exploit zur Schwachstelle bekannt. Es muss davon ausgegangen werden, dass ein Exploit zur Zeit etwa USD $10k-$25k kostet. </p><p></p><p> Ein Upgrade auf die Version 11.0.18, 15.006.30243 oder 15.020.20039 vermag dieses Problem zu beheben. Das Erscheinen einer Gegenmassnahme geschah direkt nach der Veröffentlichung der Schwachstelle. Adobe hat  sofort reagiert.</p><p> Mitunter wird der Fehler auch in der Verwundbarkeitsdatenbank von SecurityTracker (<a href="http://securitytracker.com/id/1036986">ID 1036986</a>) dokumentiert. Schwachstellen ähnlicher Art sind dokumentiert unter <a href="https://vuldb.com/?id.92615">92615</a>, <a href="https://vuldb.com/?id.92616">92616</a>, <a href="https://vuldb.com/?id.92617">92617</a> und <a href="https://vuldb.com/?id.92618">92618</a>.</p><h2>CVSSv3</h2><span>Base Score</span>: 7.3 <a href="https://www.first.org/cvss/specification-document#i2">[?]</a><br><span>Temp Score</span>: 7.0 <a href="https://www.first.org/cvss/specification-document#i3">[?]</a><br><span>Vector</span>: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C <a href="https://www.first.org/cvss/specification-document#i6">[?]</a><br><span>Zuverlässigkeit</span>: High<br><h2>CVSSv2</h2><span>Base Score</span>: 6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P) <a href="https://www.first.org/cvss/v2/guide#i2.1">[?]</a><br><span>Temp Score</span>: 5.9 (CVSS2#E:ND/RL:OF/RC:C) <a href="https://www.first.org/cvss/v2/guide#i2.2">[?]</a><br><span>Zuverlässigkeit</span>: High<br><h2>CPE</h2><ul><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Aadobe%3Aacrobat_reader&amp;page_num=0&amp;cid=3">cpe:/a:adobe:acrobat_reader</a></li></ul><h2>Exploiting</h2><span>Klasse</span>: Pufferüberlauf<br><span>Lokal</span>: Nein<br><span>Remote</span>: Ja<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Aktuelle Preisschätzung</span>: <span>$0-$1k (0-day) / $0-$1k (Heute)</span><br><h2>Gegenmassnahmen</h2><span>Empfehlung</span>: Upgrade<br><span>Status</span>: Offizieller Fix<br><span>Reaction Time</span>: 0 Tage seit gemeldet<br><span>0-Day Time</span>: 0 Tage seit gefunden<br><span>Exposure Time</span>: 0 Tage seit bekannt<br><br><span>Upgrade</span>: Acrobat Reader 11.0.18/15.006.30243/15.020.20039<br><h2>Timeline</h2><span>06.10.2016</span>  <a href="https://helpx.adobe.com/security/products/acrobat/apsb16-33.html">Advisory veröffentlicht</a><br><span>06.10.2016</span>  Gegenmassnahme veröffentlicht<br><span>11.10.2016</span>  <a href="http://securitytracker.com/id/1036986">SecurityTracker Eintrag erstellt</a><br><span>13.10.2016</span>  <a href="https://vuldb.com///vuldb.com/?id.92676">VulDB Eintrag erstellt</a><br><span>13.10.2016</span>  <a href="https://vuldb.com///vuldb.com/?id.92676">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2><span>Advisory</span>: <a href="https://helpx.adobe.com/security/products/acrobat/apsb16-33.html">APSB16-33</a><br><span>Status</span>: Bestätigt<br><br><span>CVE</span>: CVE-2016-7013 <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7013">(mitre.org)</a> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7013">(nvd.nist.org)</a> <a href="http://www.cvedetails.com/cve/CVE-2016-7013/">(cvedetails.com)</a><br><br><span>SecurityTracker</span>: <a href="http://securitytracker.com/id/1036986">1036986 - Adobe Acrobat/Reader Multiple Flaws Let Remote Users Bypass Security Restrictions and Execute Arbitrary Code</a><br><br><span>Siehe auch</span>: <a href="https://vuldb.com/?id.92615">92615</a>, <a href="https://vuldb.com/?id.92616">92616</a>, <a href="https://vuldb.com/?id.92617">92617</a>, <a href="https://vuldb.com/?id.92618">92618</a>, <a href="https://vuldb.com/?id.92619">92619</a>, <a href="https://vuldb.com/?id.92620">92620</a>, <a href="https://vuldb.com/?id.92621">92621</a>, <a href="https://vuldb.com/?id.92622">92622</a>, <a href="https://vuldb.com/?id.92623">92623</a>, <a href="https://vuldb.com/?id.92624">92624</a>, <a href="https://vuldb.com/?id.92625">92625</a>, <a href="https://vuldb.com/?id.92626">92626</a>, <a href="https://vuldb.com/?id.92627">92627</a>, <a href="https://vuldb.com/?id.92628">92628</a><br><h2>Eintrag</h2><span>Erstellt</span>: 13.10.2016<br><span>Eintrag</span>: 77.8% komplett<br>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,01ms -->