RSS   Vulnerabilities for
'Linux enterprise server for raspberry pi'
   RSS

2017-12-20
 
CVE-2017-17806

CWE-787
 

 
The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executing a crafted sequence of system calls that encounter a missing SHA-3 initialization.

 
 
CVE-2017-17805

CWE-20
 

 
The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYPTO_USER_API_SKCIPHER) to cause a denial of service (uninitialized-memory free and kernel crash) or have unspecified other impact by executing a crafted sequence of system calls that use the blkcipher_walk API. Both the generic implementation (crypto/salsa20_generic.c) and x86 implementation (arch/x86/crypto/salsa20_glue.c) of Salsa20 were vulnerable.

 
2017-06-19
 
CVE-2017-1000366

CWE-119
 

 
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.

 
2017-03-23
 
CVE-2016-9398

CWE-Other
 

 
The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.

 

 >>> Vendor: SUSE 76 Products
Suse linux
Suse linux imap server
Suse linux openexchange server
Office server
Suse email server
Suse linux admin-cd for firewall
Suse linux connectivity server
Suse linux database server
Suse linux firewall cd
Suse linux office server
Suse office server
Suse linux firewall
Suse linux firewall live-cd
Suse iptables
Suse cvsup
Suse linux school server
Suse linux standard server
Suse sled beagle
Suse open enterprise server
Linux enterprise desktop
Opensuse
Open suse
Yast2-backup
Shadow
Suse linux enterprise server
KIWI
VPNC
Webyast
Openstack
Suse linux enterprise desktop
Studio onsite
Studio extension for system z
Suse linux enterprise software development kit
GCAB
Opensuse osc
Linux enterprise server
Linux enterprise debuginfo
Manager
Linux enterprise software development kit
Linux enterprise workstation extension
Openstack cloud
Yast2
Manager proxy
Suse openstack cloud
Linux enterprise
Suse linux enterprise live patching
Suse linux enterprise module for public cloud
Suse linux enterprise workstation extension
Suse linux enterprise real time extension
Linux enterprise real time extension
Opensuse leap
Suse linux workstation extension
Linux enterprise server for sap
Linux enterprise server for raspberry pi
Linux enterprise high availability
Rancher
Linux enterprise module for web scripting
Linux enterprise for sap
Portus
Linux enterprise point of sale
Susefirewall2
Open build service
Linux enterprise module for public cloud
Subscription management tool
Suse enterprise storage
Backports
Package hub
Caas platform
Repository mirroring tool
Openqa
Susestudio-ui-server
Yast2-security
Keystone json assignment
Openstack cloud crowbar
Linux enterprise high performance computing
Manager server


Copyright 2024, cxsecurity.com

 

Back to Top