Log

AVG-2116 edited at 01 Jul 2021 09:24:47
Severity
- Unknown
+ Medium
CVE-2020-36401 edited at 01 Jul 2021 09:24:47
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Arbitrary code execution
Description
+ mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).
References
+ https://github.com/google/oss-fuzz-vulns/blob/main/vulns/mruby/OSV-2020-744.yaml
+ https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=23801
+ https://github.com/mruby/mruby/commit/97319697c8f9f6ff27b32589947e1918e3015503
Notes
AVG-2116 created at 01 Jul 2021 09:23:41
Packages
+ mruby
Issues
+ CVE-2020-36401
Status
+ Fixed
Severity
+ Unknown
Affected
+ 2.1.2-1
Fixed
+ 3.0.0-1
Ticket
Advisory qualified
+ Yes
References
Notes
CVE-2020-36401 created at 01 Jul 2021 09:23:41
AVG-2115 edited at 01 Jul 2021 09:19:54
Severity
- Unknown
+ Medium
CVE-2021-36081 edited at 01 Jul 2021 09:19:54
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
Description
+ Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.
References
+ https://github.com/google/oss-fuzz-vulns/blob/main/vulns/tesseract-ocr/OSV-2021-211.yaml
+ https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=29698
+ https://github.com/tesseract-ocr/tesseract/commit/e6f15621c2ab2ecbfabf656942d8ef66f03b2d55
Notes
AVG-2115 created at 01 Jul 2021 09:19:06
Packages
+ tesseract
Issues
+ CVE-2021-36081
Status
+ Not affected
Severity
+ Unknown
Affected
+ 4.1.1-7
Fixed
Ticket
Advisory qualified
+ No
References
Notes
CVE-2021-36081 created at 01 Jul 2021 09:19:06
AVG-1847 edited at 30 Jun 2021 08:34:19
Advisory qualified
- Yes
+ No
CVE-2021-29657 edited at 30 Jun 2021 08:33:37
References
+ https://googleprojectzero.blogspot.com/2021/06/an-epyc-escape-case-study-of-kvm.html
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.11.12&id=c90804920978faba6b5fa91e82edc58e5ffd7d30
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.28&id=5f6625f5cd5c593fae05a6ce22b406166bc796b8
AVG-2114 edited at 30 Jun 2021 08:30:25
Severity
- Unknown
+ Medium
CVE-2021-35958 edited at 30 Jun 2021 08:30:25
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Arbitrary file overwrite
Description
+ ** DISPUTED ** TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives.
References
+ https://vuln.ryotak.me/advisories/52
+ https://docs.python.org/3/library/tarfile.html#tarfile.TarFile.extractall
Notes
AVG-2114 created at 30 Jun 2021 08:28:41
Packages
+ tensorflow
Issues
+ CVE-2021-35958
Status
+ Vulnerable
Severity
+ Unknown
Affected
+ 2.5.0-4
Fixed
Ticket
Advisory qualified
+ Yes
References
Notes
CVE-2021-35958 created at 30 Jun 2021 08:28:41
AVG-2113 edited at 29 Jun 2021 18:30:04
Severity
- Unknown
+ Critical
CVE-2021-34824 edited at 29 Jun 2021 18:30:04
Severity
- Unknown
+ Critical
Remote
- Unknown
+ Remote
Type
- Unknown
+ Information disclosure
Description
+ Istio before version 1.10.2 contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.
+
+ The Istio Gateway and DestinationRule can load private keys and certificates from Kubernetes secrets via the credentialName configuration. For Istio 1.8 and above, the secrets are conveyed from Istiod to gateways or workloads via the XDS API.
+
+ In the above approach, a gateway or workload deployment should only be able to access credentials (TLS certificates and private keys) stored in the Kubernetes secrets within its namespace. However, a bug in Istiod permits an authorized client the ability to access and retrieve any TLS certificate and private key cached in Istiod.
References
+ https://istio.io/latest/news/security/istio-security-2021-007/
+ https://github.com/istio/istio/commit/10674c9a86ece93dcd40efd8e4b9147bc8604460
+ https://github.com/istio/istio/commit/f58f789f8e0d1580d00b68b76b1132163939b9ef
Notes
+ Workaround
+ ==========
+
+ This vulnerability can be mitigated by disabling Istiod caching. Caching is disabled by setting an Istiod environment variable PILOT_ENABLE_XDS_CACHE=false. System and Istiod performance may be impacted as this disables XDS caching.
AVG-2113 created at 29 Jun 2021 18:24:14
Packages
+ istio
Issues
+ CVE-2021-34824
Status
+ Fixed
Severity
+ Unknown
Affected
+ 1.10.1-1
Fixed
+ 1.10.2-1
Ticket
Advisory qualified
+ Yes
References
Notes
CVE-2021-34824 created at 29 Jun 2021 18:24:14