Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

docs: update security bulletin #3598

Merged
merged 12 commits into from
Aug 16, 2024
43 changes: 43 additions & 0 deletions docs/docs-content/security-bulletins/reports/cve-2005-2541.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
---
sidebar_label: "CVE-2005-2541"
title: "CVE-2005-2541"
description: "Lifecycle of CVE-2005-2541"
hide_table_of_contents: true
sidebar_class_name: "hide-from-sidebar"
toc_max_heading_level: 2
tags: ["security", "cve"]
---

## CVE Details

[CVE-2005-2541](https://nvd.nist.gov/vuln/detail/CVE-2005-2541)

## Last Update

8/16/2024

## NIST CVE Summary

Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote
attackers to gain privileges.

## Our Official Summary

Waiting on a fix from third party mongodb vendor.

## CVE Severity

[10.0](https://nvd.nist.gov/vuln/detail/CVE-2005-2541)

## Status

Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.12

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added Palette VerteX 4.4.12 to Affected Products
44 changes: 44 additions & 0 deletions docs/docs-content/security-bulletins/reports/cve-2012-2663.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
---
sidebar_label: "CVE-2012-2663"
title: "CVE-2012-2663"
description: "Lifecycle of CVE-2012-2663"
hide_table_of_contents: true
sidebar_class_name: "hide-from-sidebar"
toc_max_heading_level: 2
tags: ["security", "cve"]
---

## CVE Details

[CVE-2012-2663](https://nvd.nist.gov/vuln/detail/CVE-2012-2663)

## Last Update

08/16/2024
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '08/16/2024'.


## NIST CVE Summary

extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Vale.Spelling] Did you really mean 'iptables'?

remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this
issue less relevant.

## Our Official Summary

Spectro Cloud Offical Summary Coming Soon
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Vale.Spelling] Did you really mean 'Offical'?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[spectrocloud-docs-internal.future] Avoid documenting features that are not available at present. You mentioned 'Coming Soon'.


## CVE Severity

[7.5](https://nvd.nist.gov/vuln/detail/CVE-2012-2663)

## Status

Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.12

## Revision History

- 1.0 08/16/2024 Initial Publication
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '08/16/2024'.

- 2.0 08/17/2024 Added palette VerteX 4.4.12 to Affected Products
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '08/17/2024'.

45 changes: 45 additions & 0 deletions docs/docs-content/security-bulletins/reports/cve-2015-20107.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
---
sidebar_label: "CVE-2015-20107"
title: "CVE-2015-20107"
description: "Lifecycle of CVE-2015-20107"
hide_table_of_contents: true
sidebar_class_name: "hide-from-sidebar"
toc_max_heading_level: 2
tags: ["security", "cve"]
---

## CVE Details

[CVE-2015-20107](https://nvd.nist.gov/vuln/detail/CVE-2015-20107)

## Last Update

08/16/2024

## NIST CVE Summary

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the
system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch
with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to
3.7, 3.8, 3.9

## Our Official Summary

Waiting on a fix from third party mongodb vendor

## CVE Severity

[7.6](https://nvd.nist.gov/vuln/detail/CVE-2015-20107)

## Status

Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.12

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added palette VerteX 4.4.12 to Affected Products
42 changes: 42 additions & 0 deletions docs/docs-content/security-bulletins/reports/cve-2016-1585.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
---
sidebar_label: "CVE-2016-1585"
title: "CVE-2016-1585"
description: "Lifecycle of CVE-2016-1585"
hide_table_of_contents: true
sidebar_class_name: "hide-from-sidebar"
toc_max_heading_level: 2
tags: ["security", "cve"]
---

## CVE Details

[CVE-2016-1585](https://nvd.nist.gov/vuln/detail/CVE-2016-1585)

## Last Update

8/16/2024
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '8/16/2024'.


## NIST CVE Summary

In all versions of AppArmor mount rules are accidentally widened when compiled.

## Our Official Summary

Spectro Cloud Official Summary coming soon.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[spectrocloud-docs-internal.future] Avoid documenting features that are not available at present. You mentioned 'coming soon'.


## CVE Severity

[9.8](https://nvd.nist.gov/vuln/detail/CVE-2016-1585)

## Status

Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.12

## Revision History

- 1.0 08/16/2024 Initial Publication
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '08/16/2024'.

- 2.0 08/17/2024 Added Palette VerteX 4.4.12 to Affected Products
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '08/17/2024'.

43 changes: 43 additions & 0 deletions docs/docs-content/security-bulletins/reports/cve-2016-20013.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
---
sidebar_label: "CVE-2016-20013"
title: "CVE-2016-20013"
description: "Lifecycle of CVE-2016-20013"
hide_table_of_contents: true
sidebar_class_name: "hide-from-sidebar"
toc_max_heading_level: 2
tags: ["security", "cve"]
---

## CVE Details

[CVE-2016-20013](https://nvd.nist.gov/vuln/detail/CVE-2016-20013)

## Last Update

08/16/2024

## NIST CVE Summary

sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the
algorithm's runtime is proportional to the square of the length of the password.

## Our Official Summary

Spectro Cloud Offical Summary Coming Soon

## CVE Severity

[7.5](https://nvd.nist.gov/vuln/detail/CVE-2016-20013)

## Status

Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.12

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added palette VerteX 4.4.12 to Affected Products
43 changes: 43 additions & 0 deletions docs/docs-content/security-bulletins/reports/cve-2017-11164.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
---
sidebar_label: "CVE-2017-11164"
title: "CVE-2017-11164"
description: "Lifecycle of CVE-2017-11164"
hide_table_of_contents: true
sidebar_class_name: "hide-from-sidebar"
toc_max_heading_level: 2
tags: ["security", "cve"]
---

## CVE Details

[CVE-2017-11164](https://nvd.nist.gov/vuln/detail/CVE-2017-11164)

## Last Update

08/16/2024

## NIST CVE Summary

In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion (uncontrolled
recursion) when processing a crafted regular expression.

## Our Official Summary

Spectro Cloud Offical Summary Coming Soon

## CVE Severity

[7.8](https://nvd.nist.gov/vuln/detail/CVE-2017-11164)

## Status

Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.12

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added palette VerteX 4.4.12 to Affected Products
46 changes: 46 additions & 0 deletions docs/docs-content/security-bulletins/reports/cve-2018-20225.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
---
sidebar_label: "CVE-2018-20225"
title: "CVE-2018-20225"
description: "Lifecycle of CVE-2018-20225"
hide_table_of_contents: true
sidebar_class_name: "hide-from-sidebar"
toc_max_heading_level: 2
tags: ["security", "cve"]
---

## CVE Details

[CVE-2018-20225](https://nvd.nist.gov/vuln/detail/CVE-2018-20225)

## Last Update

08/16/2024
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '08/16/2024'.


## NIST CVE Summary

An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if
the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url
option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can
put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality
and the user is responsible for using --extra-index-url securely

## Our Official Summary

Waiting on a fix from third party mongodb vendor
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Vale.Spelling] Did you really mean 'mongodb'?


## CVE Severity

[7.8](https://nvd.nist.gov/vuln/detail/CVE-2018-20225)

## Status

Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.12

## Revision History

- 1.0 08/16/2024 Initial Publication
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '08/16/2024'.

- 2.0 08/17/2024 Added palette VerteX 4.4.12 to Affected Products
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '08/17/2024'.

44 changes: 44 additions & 0 deletions docs/docs-content/security-bulletins/reports/cve-2018-20657.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
---
sidebar_label: "CVE-2018-20657"
title: "CVE-2018-20657"
description: "Lifecycle of CVE-2018-20657"
hide_table_of_contents: true
sidebar_class_name: "hide-from-sidebar"
toc_max_heading_level: 2
tags: ["security", "cve"]
---

## CVE Details

[CVE-2018-20657](https://nvd.nist.gov/vuln/detail/CVE-2018-20657)

## Last Update

08/16/2024
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '08/16/2024'.


## NIST CVE Summary

The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Vale.Spelling] Did you really mean 'demangle_template'?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Vale.Spelling] Did you really mean 'libiberty'?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Vale.Spelling] Did you really mean 'Binutils'?

via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Vale.Spelling] Did you really mean 'cxxfilt'?

to CVE-2018-12698.

## Our Official Summary

Waiting on a fix from third party mongodb & calico vendors
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Vale.Spelling] Did you really mean 'mongodb'?


## CVE Severity

[7.5](https://nvd.nist.gov/vuln/detail/CVE-2018-20657)

## Status

Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.12

## Revision History

- 1.0 08/16/2024 Initial Publication
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '08/16/2024'.

- 2.0 08/17/2024 Added palette VerteX 4.4.12 to Affected Products
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '08/17/2024'.

Loading