Log

ASA-201808-8 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker is able to execute arbitrary code or gain information about the Spectre mitigations.
ASA-201809-1 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker is able to crash the bitcoin-daemon or the bitcoin-qt application. This vulnerability could allow a miner to inflate the supply of Bitcoin as they would then be able to claim value being spent twice.
ASA-201809-2 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker is able to crash the bitcoin-daemon or the bitcoin-qt application. This vulnerability could allow a miner to inflate the supply of Bitcoin as they would then be able to claim value being spent twice.
ASA-201809-3 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A local attacker is able to execute arbitrary commands via a specially crafted shell script.
ASA-201809-4 created at 25 Sep 2019 19:32:14
Workaround
+ If the gmp plugin is loaded, make sure that none of the employed keys
+ and certificates (including those of CAs) use keys with e = 3.
+ Strongswan's tool to generate keys (pki --gen) always used e = 65537
+ (0x10001), which is not vulnerable, so certificates and keys generated
+ with this tool are fine for use even with an unpatched gmp plugin.
Impact
+ An attacker is able to use non-validated fields on a maliciously- crafted file to forge a signature or a CA certificate.
ASA-201809-5 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker is able to bypass access restrictions put in place by the site administrator and/or gain access to restricted content.
ASA-201810-1 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker is able to cause a denial of service by sending a specially crafted mqtt message.
ASA-201810-10 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker is able to successfully authenticate without any credentials, resulting in unauthorized access.
ASA-201810-11 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote unauthenticated attacker is able to crash snmpd or potentially execute arbitrary code on the system by sending specially crafted packets.
ASA-201810-12 created at 25 Sep 2019 19:32:14
Workaround
Impact
+ A remote attacker can spoof the URL or the security status of a page, access sensitive information, crash the browser or execute arbitrary code on the affected host.