The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Computer vulnerabilities of Red Hat Fedora

computer vulnerability CVE-2017-1000255

Linux kernel: memory corruption via PowerPC TM Bad Thing

Synthesis of the vulnerability

An attacker can generate a memory corruption via PowerPC TM Bad Thing of the Linux kernel, in order to trigger a denial of service, and possibly to run code.
Impacted products: Fedora, Linux, RHEL, Ubuntu.
Severity: 2/4.
Consequences: administrator access/rights, denial of service on server.
Provenance: user shell.
Creation date: 10/10/2017.
Identifiers: CERTFR-2017-AVI-339, CERTFR-2017-AVI-424, CERTFR-2017-AVI-426, CERTFR-2018-AVI-175, CVE-2017-1000255, FEDORA-2017-c110ac0eb1, FEDORA-2017-cafcdbdde5, FEDORA-2018-884a105c04, RHSA-2018:0654-01, USN-3443-1, USN-3443-2, USN-3443-3, USN-3487-1, VIGILANCE-VUL-24065.

Description of the vulnerability

An attacker can generate a memory corruption via PowerPC TM Bad Thing of the Linux kernel, in order to trigger a denial of service, and possibly to run code.
Full Vigil@nce bulletin... (Free trial)

vulnerability announce CVE-2017-10841

WebCalendar: directory traversal

Synthesis of the vulnerability

An attacker can traverse directories of WebCalendar, in order to read a file outside the service root path.
Impacted products: Fedora.
Severity: 2/4.
Consequences: data reading.
Provenance: internet client.
Creation date: 10/10/2017.
Identifiers: CVE-2017-10841, FEDORA-2017-26a53ccbdf, FEDORA-2017-c9abeb3158, VIGILANCE-VUL-24062.

Description of the vulnerability

An attacker can traverse directories of WebCalendar, in order to read a file outside the service root path.
Full Vigil@nce bulletin... (Free trial)

vulnerability alert CVE-2017-10840

WebCalendar: Cross Site Scripting

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting of WebCalendar, in order to run JavaScript code in the context of the web site.
Impacted products: Fedora.
Severity: 2/4.
Consequences: client access/rights.
Provenance: document.
Creation date: 10/10/2017.
Identifiers: CVE-2017-10840, FEDORA-2017-26a53ccbdf, FEDORA-2017-c9abeb3158, VIGILANCE-VUL-24061.

Description of the vulnerability

The WebCalendar product offers a web service.

However, it does not filter received data before inserting them in generated HTML documents.

An attacker can therefore trigger a Cross Site Scripting of WebCalendar, in order to run JavaScript code in the context of the web site.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability alert CVE-2017-14977

Poppler: NULL pointer dereference via FoFiTrueType-getCFFBlock

Synthesis of the vulnerability

An attacker can force a NULL pointer to be dereferenced via FoFiTrueType::getCFFBlock() of Poppler, in order to trigger a denial of service.
Impacted products: Debian, Fedora, openSUSE Leap, Solaris, SUSE Linux Enterprise Desktop, SLES, Ubuntu.
Severity: 1/4.
Consequences: denial of service on service, denial of service on client.
Provenance: document.
Creation date: 09/10/2017.
Identifiers: bulletinjan2019, CVE-2017-14977, DLA-1177-1, DSA-4079-1, DSA-4079-2, FEDORA-2017-6127ddb036, FEDORA-2017-a0ffdf1fbd, openSUSE-SU-2018:1721-1, SUSE-SU-2018:1662-1, SUSE-SU-2018:1691-1, USN-3440-1, VIGILANCE-VUL-24056.

Description of the vulnerability

An attacker can force a NULL pointer to be dereferenced via FoFiTrueType::getCFFBlock() of Poppler, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability CVE-2017-14975

Poppler: NULL pointer dereference via FoFiType1C-convertToType0

Synthesis of the vulnerability

An attacker can force a NULL pointer to be dereferenced via FoFiType1C::convertToType0() of Poppler, in order to trigger a denial of service.
Impacted products: Debian, Fedora, openSUSE Leap, Solaris, SUSE Linux Enterprise Desktop, SLES, Ubuntu.
Severity: 1/4.
Consequences: denial of service on service, denial of service on client.
Provenance: document.
Creation date: 09/10/2017.
Identifiers: bulletinjan2019, CVE-2017-14975, DLA-1177-1, DSA-4079-1, DSA-4079-2, FEDORA-2017-6127ddb036, FEDORA-2017-a0ffdf1fbd, openSUSE-SU-2018:1721-1, SUSE-SU-2018:1662-1, USN-3440-1, VIGILANCE-VUL-24055.

Description of the vulnerability

An attacker can force a NULL pointer to be dereferenced via FoFiType1C::convertToType0() of Poppler, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

vulnerability note CVE-2017-14929

Poppler: memory corruption via Object-dictLookup

Synthesis of the vulnerability

An attacker can generate a memory corruption via Object::dictLookup() of Poppler, in order to trigger a denial of service, and possibly to run code.
Impacted products: Debian, Fedora, Ubuntu.
Severity: 2/4.
Consequences: user access/rights, denial of service on service, denial of service on client.
Provenance: document.
Creation date: 09/10/2017.
Identifiers: CVE-2017-14929, DSA-4097-1, FEDORA-2017-51ff8fe326, FEDORA-2017-6127ddb036, FEDORA-2017-805d9423f8, FEDORA-2017-a0ffdf1fbd, USN-3440-1, VIGILANCE-VUL-24054.

Description of the vulnerability

An attacker can generate a memory corruption via Object::dictLookup() of Poppler, in order to trigger a denial of service, and possibly to run code.
Full Vigil@nce bulletin... (Free trial)

vulnerability bulletin CVE-2017-14928

Poppler: NULL pointer dereference via AnnotRichMedia-Configuration-Configuration

Synthesis of the vulnerability

An attacker can force a NULL pointer to be dereferenced via AnnotRichMedia::Configuration::Configuration of Poppler, in order to trigger a denial of service.
Impacted products: Fedora, openSUSE Leap, SUSE Linux Enterprise Desktop, SLES, Ubuntu.
Severity: 1/4.
Consequences: denial of service on service, denial of service on client.
Provenance: document.
Creation date: 09/10/2017.
Identifiers: CVE-2017-14928, FEDORA-2017-51ff8fe326, FEDORA-2017-6127ddb036, FEDORA-2017-805d9423f8, FEDORA-2017-a0ffdf1fbd, openSUSE-SU-2018:1721-1, SUSE-SU-2018:1662-1, USN-3440-1, VIGILANCE-VUL-24053.

Description of the vulnerability

An attacker can force a NULL pointer to be dereferenced via AnnotRichMedia::Configuration::Configuration of Poppler, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

vulnerability announce CVE-2017-14926

Poppler: NULL pointer dereference via AnnotRichMedia-Content-Content

Synthesis of the vulnerability

An attacker can force a NULL pointer to be dereferenced via AnnotRichMedia::Content::Content of Poppler, in order to trigger a denial of service.
Impacted products: Fedora, Ubuntu.
Severity: 1/4.
Consequences: denial of service on service, denial of service on client.
Provenance: document.
Creation date: 09/10/2017.
Identifiers: CVE-2017-14926, FEDORA-2017-51ff8fe326, FEDORA-2017-6127ddb036, FEDORA-2017-805d9423f8, FEDORA-2017-a0ffdf1fbd, USN-3440-1, VIGILANCE-VUL-24052.

Description of the vulnerability

An attacker can force a NULL pointer to be dereferenced via AnnotRichMedia::Content::Content of Poppler, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

vulnerability alert CVE-2017-14518

Poppler: denial of service via isImageInterpolationRequired

Synthesis of the vulnerability

An attacker can generate a fatal error via isImageInterpolationRequired() of Poppler, in order to trigger a denial of service.
Impacted products: Debian, Fedora, openSUSE Leap, Solaris, SUSE Linux Enterprise Desktop, SLES, Ubuntu, WindRiver Linux.
Severity: 1/4.
Consequences: denial of service on service, denial of service on client.
Provenance: document.
Creation date: 09/10/2017.
Identifiers: bulletinjan2019, CVE-2017-14518, DSA-4079-1, DSA-4079-2, FEDORA-2017-51ff8fe326, FEDORA-2017-6127ddb036, FEDORA-2017-805d9423f8, FEDORA-2017-a0ffdf1fbd, openSUSE-SU-2018:1721-1, SUSE-SU-2018:1662-1, USN-3440-1, VIGILANCE-VUL-24051.

Description of the vulnerability

An attacker can generate a fatal error via isImageInterpolationRequired() of Poppler, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability announce CVE-2017-13722

libxfont: out-of-bounds memory reading via PCF

Synthesis of the vulnerability

An attacker can force a read at an invalid address via PCF of libxfont, in order to trigger a denial of service, or to obtain sensitive information.
Impacted products: Debian, Fedora, NetBSD, openSUSE Leap, Ubuntu, Unix (platform) ~ not comprehensive, XOrg Bundle ~ not comprehensive.
Severity: 2/4.
Consequences: data reading, denial of service on service, denial of service on client.
Provenance: document.
Creation date: 09/10/2017.
Identifiers: CVE-2017-13722, DLA-1126-1, DSA-3995-1, FEDORA-2017-2783ef2c63, FEDORA-2017-b7c4334524, FEDORA-2017-f44afd1f34, openSUSE-SU-2017:3256-1, openSUSE-SU-2018:0343-1, USN-3442-1, VIGILANCE-VUL-24047.

Description of the vulnerability

An attacker can force a read at an invalid address via PCF of libxfont, in order to trigger a denial of service, or to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)
Our database contains other pages. You can request a free trial to read them.

Display information about Red Hat Fedora: