Tags › Security Advisory
Asterisk Skinny: memory exhaustion denial of service
Published on May 23, 2017 in asterisk, denial of service, security advisory
- Authors:
- Alfred Farrugia alfred@enablesecurity.com
- Sandro Gauci sandro@enablesecurity.com
- Vulnerable version: Asterisk 14.4.0 with
chan_skinnyenabled - References: AST-2017-004
- Enable Security Advisory: https://www.enablesecurity.com/advisories/ES2017-03-asterisk-chan-skinny-crash/
- Vendor Advisory: http://downloads.asterisk.org/pub/security/AST-2017-004.html
- Timeline:
- Report date: 2017-04-13
- Digium confirmed issue: 2017-04-13
- Digium patch and advisory: 2017-05-19
- Enable Security advisory: 2017-05-23
Description
Sending one malformed Skinny message to port 2000 will exhaust Asterisk’s memory resulting in a crash.
Impact
Abuse of this issue allows attackers to crash Asterisk when Skinny is exposed to attackers.
How to reproduce the issue
Start Asterisk and make sure the chan_skinny module is loaded. Then execute:
Asterisk PJSIP: out-of-bound memory access in multipart parser
Published on May 23, 2017 in asterisk, pjsip, denial of service, security advisory
- Authors:
- Alfred Farrugia alfred@enablesecurity.com
- Sandro Gauci sandro@enablesecurity.com
- Vulnerable version: Asterisk 14.4.0 running
chan_pjsip, PJSIP 2.6 - References: AST-2017-003
- Enable Security Advisory: https://www.enablesecurity.com/advisories/ES2017-02-asterisk-pjsip-multi-part-crash/
- Vendor Advisory: http://downloads.asterisk.org/pub/security/AST-2017-003.html
- Timeline:
- Report date: 2017-04-13
- Digium confirmed issue: 2017-04-13
- Digium patch and advisory: 2017-05-19
- PJSIP added patch by Digium: 2017-05-21
- Enable Security advisory: 2017-05-23
Description
A specially crafted SIP message with a malformed multipart body was found to cause a segmentation fault.
Impact
Abuse of this vulnerability leads to denial of service (DoS), and potentially remote code execution (RCE), in Asterisk when chan_pjsip is in use. This vulnerability is likely to affect other code that makes use of PJSIP.
Liferay: XML External Entity vulnerability in OpenID component
Published on Jan 1, 2016 in liferay, xxe, security advisory
- Vulnerable version: Liferay 6.2.3 CE GA4 and earlier
- Liferay reference: LPS-58014
- Enable Security Advisory: https://www.enablesecurity.com/advisories/ES2016-01-liferay-xxe/
- Timeline:
- Report date: March 16 2015
- Liferay patch: August 26 2015
- Liferay advisory: January 18 2016
- Enable Security advisory: June 1 2016
Description
Liferay supports OpenID login which was found to make use of a version of openid4java that is vulnerable to XML External Entity (XXE) attacks.
Impact
Abuse of the XXE vulnerability can (at least) lead to local file disclosure, server-side request forgery (SSRF) and denial of service. This vulnerability was abused to read local files on the web server that the web application had access to.
…Juniper VPN SSL: client-side cross-site scripting
Published on Sep 12, 2013 in CVE-2013-5649, juniper, cross-site scripting, security advisory
- Vendor advisory: http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10589
- Vulnerable product that was tested: MAG-2600, Version 7.2R3 (build 21397)
- CVE: CVE-2013-5649
- Enable Security Advisory: https://www.enablesecurity.com/advisories/ES2013-01-juniper-junos-dom-xss/
Description
The Juniper VPN SSL system was found to be vulnerable to a client-side cross site scripting vulnerability.
Impact
Exploitation of this vulnerability may allow hijack of VPN SSL sessions. This usually involves a social engineering attack in order to convince a logged in victim to click on an attacker-supplied URL. Therefore such an attack would typically be the result of a targeted attack rather than an opportunistic one.
…Applicure dotDefender: stored cross-site scripting in admin interface
Published on Jun 1, 2010 in dotdefender, cross-site scripting, security advisory
An advisory by EnableSecurity.
- ID: ES-20100601
- Affected Versions: version 4.0
- Fixed versions: 4.01-3 and later
- Enable Security Advisory: https://www.enablesecurity.com/advisories/ES2010-01-applicure-dotDefender-stored-xss/
Description
Applicure dotDefender is a Web Application Firewall that can be installed on Windows and Linux servers.
From their website (applicure.com):
“dotDefender is the market-leading software Web Application Firewall (WAF). dotDefender boasts enterprise-class security, advanced integration capabilities, easy maintenance and low total cost of ownership (TCO). dotDefender is the perfect choice for protecting your website and web applications today.”
…
Armorlogic Profense WAF: multiple vulnerabilities
Published on May 13, 2009 in CVE-2009-1594, CVE-2009-1593, profense, cross-site scripting, security advisory
An advisory by EnableSecurity. Trustwave published a joint advisory named TWSL2009-001.
- ID: ES-20090500
- Affected Versions: versions prior to 2.4.4 and 2.2.22
- Fixed versions: 2.4.4, 2.2.22 and later
- Enable Security Advisory: https://www.enablesecurity.com/advisories/ES2009-02-armorlogic-profense-multiple-vulnerabilities/
Description
Armorlogic Profense is a Web Application Firewall and load balancing solution.
From their website (armorlogic.com):
“Protecting and securing websites and web applications can be a complicated business. Profense web application firewall simplifies protection with an affordable and easy to use, feature rich, solution that gives you full PCI DSS 1.1 and 1.2 section 6.6 compliance.”
…
OpenX: multiple vulnerabilities
Published on Apr 1, 2009 in openx, cross-site scripting, sql injection, security advisory
An advisory by EnableSecurity in collaboration with Acunetix.
- Affected versions: OpenX 2.6.4 and older versions
- Enable Security Advisory: https://www.enablesecurity.com/advisories/ES2009-01-openx-multiple-vulnerabilities/
Description
OpenX is an online advertising web application written in PHP that supports popular sites such as TechCrunch, SUN Microsystems and Metacafe.
From their website (openx.org):
“OpenX is a free, open source ad server that manages the selling and delivery of your online advertising inventory. You can get OpenX as a hosted service or as downloaded software.”
…
Apple Mail.app: S/MIME encrypted emails stored in clear text
Published on Oct 3, 2008 in apple, security advisory
- Affected version: 3.5 (929.4/929.2)
- Unaffected version: Unknown
Summary
Apple Mail.app does not store S/MIME encrypted emails securely in the Drafts directory on server.
Impact
The assumption that the server does not have access to the email content is violated.
Description
Apple’s Mail.app is the default email application that comes with Mac OS X machines. It supports S/MIME as standard for encryption and authentication of emails. However by default Mail.app also has an option called “Store draft messages on the server” when you are making use of an IMAP or Exchange server.
…