CVE-2019-5672

CVE-2019-5672

NVIDIA Linux for Tegra (L4T) contains a vulnerability where the Secure Shell (SSH) keys provided in the sample rootfs are not replaced by unique host keys after sample rootsfs generation and flashing, which may lead to information disclosure. The updates apply to all versions prior to and including R28.3.

Source: CVE-2019-5672

CVE-2018-19300

CVE-2018-19300

On D-Link DAP-1530 (All A revisions) before firmware version 1.06b01, DAP-1610 (All A revisions) before firmware version 1.06b01, DWR-111 (All A revisions) before firmware version 1.02v02, DWR-116 (All A revisions) before firmware version 1.06b03, DWR-512 (All B revisions) before firmware version 2.02b01, DWR-711 (All A revisions) through firmware version 1.11, DWR-712 (All B revisions) before firmware version 2.04b01, DWR-921 (All A revisions) before firmware version 1.02b01, and DWR-921 (All B revisions) before firmware version 2.03b01, there exists an EXCU_SHELL file in the web directory. By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. Other devices might be affected as well.

Source: CVE-2018-19300

CVE-2019-3837

CVE-2019-3837

It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unprivileged multi-threaded userspace application calling recvmsg() for the same network socket in parallel executed on ioatdma-enabled hardware with net_dma enabled can leak the memory, crash the host leading to a denial-of-service or cause a random memory corruption.

Source: CVE-2019-3837

CVE-2019-3845

CVE-2019-3845

A lack of access control was found in the message queues maintained by Satellite’s QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.

Source: CVE-2019-3845