Cookie Consent by Free Privacy Policy Generator ๐Ÿ“Œ Open-Xchange: A specifically designed sieve script can cause a DoS in lib-sieve during sieve script compilation via NULL pointer dereference

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Open-Xchange: A specifically designed sieve script can cause a DoS in lib-sieve during sieve script compilation via NULL pointer dereference


๐Ÿ’ก Newskategorie: Sicherheitslรผcken
๐Ÿ”— Quelle: vulners.com


image
Reproduction realcrash.sieve is the attached script 1. Build dovecot and pigeonhole 2. Run sievec realcrash.sieve Requirements include and variables extensions should be required. One of the global commands (global/export/import) without any arguments should be followed by the same command with valid (string or string list) arguments; Problem During vaildation of parsed script, lib-sieve tries to join arguments of consecutive global commands with the same name (export with export, global with global, import with import) in src/lib-sieve/sieve-ast.c:sieve_ast_stringlist_join. However, we can create a logically wrong export/import/global command with no arguments and during a lookup of this command's argument list lib-sieve will fault. Crash log with ASAN ``` ==19154==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x7f2a5d0d1564 bp 0x7ffc8e129150 sp 0x7ffc8e129130 T0) ==19154==The signal is caused by a READ memory access. ==19154==Hint: address points to the zero page. #0 0x7f2a5d0d1563 in sieve_ast_stringlist_join /home/rumata888/Documents/Collaboration/Fuzzing/OpenExchnage/pigeonhole/pigeonhole_clean/src/lib-sieve/sieve-ast.c:814 #1 0x7f2a5d17e869 in cmd_global_validate /home/rumata888/Documents/Collaboration/Fuzzing/OpenExchnage/pigeonhole/pigeonhole_clean/src/lib-sieve/plugins/include/cmd-global.c:181 #2 0x7f2a5d0edf9d in sieve_validate_command... ...



๐Ÿ“Œ GNU Libtasn1 3.0 up to 3.5 lib/element.c null pointer dereference


๐Ÿ“ˆ 39.17 Punkte

๐Ÿ“Œ GNU Libtasn1 3.0 up to 3.5 lib/decoding.c null pointer dereference


๐Ÿ“ˆ 39.17 Punkte

๐Ÿ“Œ CVE-2022-3606 | Linux Kernel BPF tools/lib/bpf/libbpf.c find_prog_by_sec_insn null pointer dereference


๐Ÿ“ˆ 39.17 Punkte

๐Ÿ“Œ CVE-2023-6915 | Linux Kernel up to 6.7-rc6 lib/idr.c ida_free null pointer dereference


๐Ÿ“ˆ 39.17 Punkte

๐Ÿ“Œ ZDI-CAN-12671: Windows Kernel DoS/Privilege Escalation via a NULL Pointer Deref


๐Ÿ“ˆ 36.63 Punkte

๐Ÿ“Œ GitHub Security Lab: [CATENACYBER]: [CPP] CWE-476 Null Pointer Dereference : Another query to either missing or redundant NULL check


๐Ÿ“ˆ 36.51 Punkte

๐Ÿ“Œ CVE-2020-9429 | Wireshark 3.2.0/3.2.1 WireGuard Dissector packet-wireguard.c Null Value null pointer dereference


๐Ÿ“ˆ 36.51 Punkte

๐Ÿ“Œ [dos] JavaScriptCore - GetterSetter Type Confusion During DFG Compilation


๐Ÿ“ˆ 36.06 Punkte

๐Ÿ“Œ [shellcode] - Windows x86 ShellExecuteA(NULL,NULL,"cmd.exe",NULL,NULL,1) Shellcode


๐Ÿ“ˆ 35.85 Punkte

๐Ÿ“Œ [shellcode] - Windows x86 ShellExecuteA(NULL,NULL,"cmd.exe",NULL,NULL,1) Shellcode


๐Ÿ“ˆ 35.85 Punkte

๐Ÿ“Œ [dos] - OS X Kernel - Exploitable NULL Pointer Dereference in AppleGraphicsDeviceControl


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] - OS X Kernel - Exploitable NULL Pointer Dereference in AppleMuxControl.kext


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] - OS X Kernel - Exploitable NULL Pointer Dereference in IOAudioEngine


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] - Microsoft Windows - LSASS SMB NTLM Exchange Null-Pointer Dereference (MS16-137)


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] - Linux Kernel - 'keyctl' Null Pointer Dereference


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] - OS X Kernel - Exploitable NULL Pointer Dereference in AppleGraphicsDeviceControl


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] - OS X Kernel - Exploitable NULL Pointer Dereference in AppleMuxControl.kext


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] - OS X Kernel - Exploitable NULL Pointer Dereference in IOAudioEngine


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] - Microsoft Windows - LSASS SMB NTLM Exchange Null-Pointer Dereference (MS16-137)


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] - Linux Kernel - 'keyctl' Null Pointer Dereference


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] Artifex MuPDF - Null Pointer Dereference


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] Artifex MuPDF mujstest 1.10a - Null Pointer Dereference


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] GStreamer gst-plugins-bad Plugin - NULL Pointer Dereference


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] Microsoft Edge Chakra - NULL Pointer Dereference


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] Watchdog Development Anti-Malware / Online Security Pro - NULL Pointer Dereference


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ Microsoft Windows NT 4.0/2000 Virtual DOS Machine NULL Pointer Dereference memory corruption


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ [dos] Windows Kernel - NULL Pointer Dereference in nt!MiOffsetToProtos While Parsing Malformed PE File


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ NVIDIA To Launch Graphics Cards Specifically Designed For Digital Currency Mining


๐Ÿ“ˆ 33.7 Punkte

๐Ÿ“Œ Apps/widgets/software specifically designed for KDE vs Gnome vs XFCE vs MATE vs LXDE & more - this is madness!


๐Ÿ“ˆ 33.7 Punkte

๐Ÿ“Œ iPadOS 14 introduces new features designed specifically for iPad


๐Ÿ“ˆ 33.7 Punkte

๐Ÿ“Œ Apple AI Research Releases MLX: An Efficient Machine Learning Framework Specifically Designed for Apple Silicon


๐Ÿ“ˆ 33.7 Punkte

๐Ÿ“Œ Adept AI Introduces Fuyu-Heavy: A New Multimodal Model Designed Specifically for Digital Agents


๐Ÿ“ˆ 33.7 Punkte

๐Ÿ“Œ Meta AI Introduces AudioSeal: The First Audio Watermarking Technique Designed Specifically for Localized Detection of AI-Generated Speech


๐Ÿ“ˆ 33.7 Punkte











matomo