Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ IPv4 Parsing Flaw In NPM Netmask Could Affect 270,000 Apps

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š IPv4 Parsing Flaw In NPM Netmask Could Affect 270,000 Apps


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: it.slashdot.org

chicksdaddy shares a report from The Security Ledger: Independent security researchers analyzing the widely used open source component netmask have discovered security vulnerabilities that could leave more than a quarter million open source applications vulnerable to attack, according to a report released Monday, The Security Ledger reports. According to a report by the site Sick Codes, the flaws open applications that rely on netmask to a wide range of malicious attacks including Server Side Request Forgeries (SSRF) and Remote- and Local File Includes (RFI, LFI) that could enable attackers to ferry malicious code into a protected network, or siphon sensitive data out of one. Even worse, the flaws appear to stretch far beyond a single open source module, affecting a wide range of open source development languages, researchers say. Netmask is a widely used package that allows developers to evaluate whether a IP address attempting to access an application was inside or outside of a given IPv4 range. Based on an IP address submitted to netmask, the module will return true or false about whether or not the submitted IP address is in the defined "block." According to the researcher using the handle "Sick Codes," the researchers discovered that netmask had a big blind spot. Specifically: it evaluates certain IP addresses incorrectly: improperly validating so-called "octal strings" rendering IPv4 addresses that contain certain octal strings as integers. For example, the IP4 address 0177.0.0.1 should be evaluated by netmask as the private IP address 127.0.0.1, as the octal string "0177" translates to the integer "127." However, netmask evaluates it as a public IPv4 address: 177.0.0.1, simply stripping off the leading zero and reading the remaining parts of the octal string as an integer. The implications for modules that are using the vulnerable version of netmask are serious. According to Sick Codes, remote attackers can use SSRF attacks to upload malicious files from the public Internet without setting off alarms, because applications relying on netmask would treat a properly configured external IP address as an internal address. Similarly, attackers could also disguise remote IP addresses local addresses, enabling remote file inclusion (RFI) attacks that could permit web shells or malicious programs to be placed on target networks. But researchers say much more is to come. The problems identified in netmask are not unique to that module. Researchers have noted previously that textual representation of IPv4 addresses were never standardized, leading to disparities in how different but equivalent versions of IPv4 addresses (for example: octal strings) are rendered and interpreted by different applications and platforms.

Read more of this story at Slashdot.

...



๐Ÿ“Œ IPv4 Parsing Flaw In NPM Netmask Could Affect 270,000 Apps


๐Ÿ“ˆ 120.34 Punkte

๐Ÿ“Œ Medium CVE-2021-28918: Netmask project Netmask


๐Ÿ“ˆ 49.26 Punkte

๐Ÿ“Œ Critical โ€œNetmaskโ€ npm Package Flaw Affects Hundreds of Thousands of Applications


๐Ÿ“ˆ 44.33 Punkte

๐Ÿ“Œ Sitting comfortably? Then it's probably time to patch, as critical flaw uncovered in npm's netmask package


๐Ÿ“ˆ 44.33 Punkte

๐Ÿ“Œ Hundreds of thousands of projects affected by a flaw in netmask npm package


๐Ÿ“ˆ 44.33 Punkte

๐Ÿ“Œ Vulnerability in 'netmask' npm Package Affects 280,000 Projects


๐Ÿ“ˆ 41.99 Punkte

๐Ÿ“Œ Unscheinbar aber gefรคhrlich: netmask รผbersetzt IPv4-Adressen falsch


๐Ÿ“ˆ 40.03 Punkte

๐Ÿ“Œ Sicherheitslรผcke: npm-Paket Netmask ignoriert das Oktalsystem in IP-Adressen


๐Ÿ“ˆ 37.07 Punkte

๐Ÿ“Œ Sicherheitslรผcke: npm-Paket Netmask ignoriert das Oktalsystem in IP-Adressen


๐Ÿ“ˆ 37.07 Punkte

๐Ÿ“Œ Serious Vulnerability In Netmask npm Package Risked 270K+ Projects


๐Ÿ“ˆ 37.07 Punkte

๐Ÿ“Œ netmask Package up to 1.0.6 on npm input validation [CVE-2021-28918]


๐Ÿ“ˆ 37.07 Punkte

๐Ÿ“Œ Code Execution Flaw in Electron Framework Could Affect Many Apps


๐Ÿ“ˆ 32.03 Punkte

๐Ÿ“Œ Linux Kernel up to 3.15.1 IPv4 UDP Socket net/ipv4/datagram.c ip4_datagram_release_cb memory corruption


๐Ÿ“ˆ 30.79 Punkte

๐Ÿ“Œ Cisco Wireless LAN Controller Software 8.4 IPv4 Fragment IPv4 Packet denial of service


๐Ÿ“ˆ 30.79 Punkte

๐Ÿ“Œ Wind River VxWorks 6.9/7 IPv4 IPv4 Packet Stack-based memory corruption


๐Ÿ“ˆ 30.79 Punkte

๐Ÿ“Œ Suricata 4.1.4 Options decode-ipv4.c IPV4OptValidateTimestamp IPv4 Packet memory corruption


๐Ÿ“ˆ 30.79 Punkte

๐Ÿ“Œ Linux Kernel bis 3.15.1 IPv4 UDP Socket net/ipv4/datagram.c ip4_datagram_release_cb Pufferรผberlauf


๐Ÿ“ˆ 30.79 Punkte

๐Ÿ“Œ CVE-2022-3435 | Linux Kernel IPv4 net/ipv4/fib_semantics.c fib_nh_match out-of-bounds


๐Ÿ“ˆ 30.79 Punkte

๐Ÿ“Œ CVE-2023-6932 | Linux Kernel up to 6.6.x IPv4 net/ipv4/igmp.c igmp_start_timer use after free


๐Ÿ“ˆ 30.79 Punkte

๐Ÿ“Œ CVE-2023-42754 | Linux Kernel 6.2.16 IPv4 net/ipv4/route.c ipv4_send_dest_unreach null pointer dereference (FEDORA-2023-50bd7c9c12)


๐Ÿ“ˆ 30.79 Punkte

๐Ÿ“Œ Critical Flaw in GoAhead Web Server Could Affect Wide Range of IoT Devices


๐Ÿ“ˆ 27.86 Punkte

๐Ÿ“Œ Critical Flaw in GoAhead Web Server Could Affect Wide Range of IoT Devices


๐Ÿ“ˆ 27.86 Punkte

๐Ÿ“Œ Design Flaw Could Affect Microsoft Surface Duoโ€™s Most Innovative Feature


๐Ÿ“ˆ 27.86 Punkte

๐Ÿ“Œ New Spectre-Like 'PACMAN' Flaw Could Affect ARM-Based Chips (including Apple's M1)


๐Ÿ“ˆ 27.86 Punkte

๐Ÿ“Œ The New Spectre-Like 'PACMAN' Flaw Could Affect ARM-Based Chips (including Apple's M1)


๐Ÿ“ˆ 27.86 Punkte

๐Ÿ“Œ Fuzzing npm/nodejs WebAssembly parsing library with jsfuzz


๐Ÿ“ˆ 27.6 Punkte

๐Ÿ“Œ Fuzzing npm/nodejs WebAssembly parsing library with jsfuzz


๐Ÿ“ˆ 27.6 Punkte

๐Ÿ“Œ Medium CVE-2020-7614: Npm-programmatic project Npm-programmatic


๐Ÿ“ˆ 24.88 Punkte

๐Ÿ“Œ The ZipperDown Vulnerability could affect roughly 10% of iOS Apps


๐Ÿ“ˆ 24.77 Punkte

๐Ÿ“Œ CVE-1999-0524: ICMP information such as (1) netmask and...


๐Ÿ“ˆ 24.63 Punkte

๐Ÿ“Œ Critical netmask networking bug impacts thousands of applications


๐Ÿ“ˆ 24.63 Punkte

๐Ÿ“Œ Netmask: Node- und Perl-Pakete parsen IP-Adressen falsch


๐Ÿ“ˆ 24.63 Punkte

๐Ÿ“Œ Security: Mangelnde Eingabeprรผfung in perl-Net-Netmask (Fedora)


๐Ÿ“ˆ 24.63 Punkte

๐Ÿ“Œ Mangelnde Eingabeprรผfung in perl-Net-Netmask (Fedora)


๐Ÿ“ˆ 24.63 Punkte











matomo