Log

ASA-201805-7 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker is able to crash the application or execute arbitrary code via a specially crafted PDF file.
ASA-201805-8 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker is able to crash the application or execute arbitrary code via a specially crafted PDF file.
ASA-201805-9 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker can execute arbitrary code on the affected host via a specially crafted web content.
ASA-201806-1 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker can execute arbitrary code on the affected host by placing a crafted .gitmodules file in a repository cloned by a local user, or access sensitive information via a crafted path in such a repository.
ASA-201806-10 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ An unprivileged user might be able to retrieve private keys on the affected host.
ASA-201806-11 created at 25 Sep 2019 19:32:14
Workaround
+ You can make sure arbitrary code execution is not possible by disabling
+ pass's extension facility:
+
+ export PASSWORD_STORE_ENABLE_EXTENSIONS=false
Impact
+ A remote attacker is able to bypass signature verification and register arbitrary keys for an account or execute arbitrary code on the host by providing the application a crafted pgp signature packet.
ASA-201806-12 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ An unprivileged user is able to mount remote samba shares, enabling arbitrary filesystem access and privileged escalation.
ASA-201806-13 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker is able to steal the browser history with a specially crafted web page title.
ASA-201806-14 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker can access sensitive information, bypass various security mechanisms and execute arbitrary code on the affected host.
ASA-201806-2 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker is able to execute arbitrary code or crash the application via a specially crafted file.