Weekly Vulnerabilities Reports > November 30 to December 6, 2015

Overview

12 new vulnerabilities reported during this period, including 7 critical vulnerabilities and 4 high severity vulnerabilities. This weekly summary report vulnerabilities in 31 products from 13 vendors including PHP, Fedoraproject, Pcre, Debian, and Oracle. Vulnerabilities are notably categorized as "Improper Restriction of Operations within the Bounds of a Memory Buffer", "Information Exposure", "Integer Overflow or Wraparound", "Use of Uninitialized Resource", and "NULL Pointer Dereference".

  • 12 reported vulnerabilities are remotely exploitables.
  • 12 reported vulnerabilities are exploitable by an anonymous user.
  • PHP has the most reported vulnerabilities, with 8 reported vulnerabilities.
  • PHP has the most reported critical vulnerabilities, with 6 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

7 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2015-12-06 CVE-2015-6764 Google
Nodejs
Debian
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products

The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

9.8
2015-12-02 CVE-2015-8394 Pcre
PHP
Integer Overflow or Wraparound vulnerability in multiple products

PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

9.8
2015-12-02 CVE-2015-8391 Pcre
Oracle
Fedoraproject
Redhat
PHP
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products

The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

9.8
2015-12-02 CVE-2015-8390 Pcre
Fedoraproject
PHP
Use of Uninitialized Resource vulnerability in multiple products

PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

9.8
2015-12-02 CVE-2015-8389 Pcre
Fedoraproject
PHP
Incorrect Regular Expression vulnerability in multiple products

PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite recursion) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

9.8
2015-12-02 CVE-2015-8386 Pcre
Fedoraproject
Oracle
PHP
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products

PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

9.8
2015-12-02 CVE-2015-8383 Pcre
Fedoraproject
PHP
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products

PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

9.8

4 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2015-12-06 CVE-2015-3194 Openssl
Canonical
Debian
Nodejs
NULL Pointer Dereference vulnerability in multiple products

crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parameter.

7.5
2015-12-06 CVE-2015-3193 Openssl
Nodejs
Canonical
Information Exposure vulnerability in multiple products

The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for remote attackers to obtain sensitive private-key information via an attack against use of a (1) Diffie-Hellman (DH) or (2) Diffie-Hellman Ephemeral (DHE) ciphersuite.

7.5
2015-12-02 CVE-2015-8393 Pcre
Fedoraproject
PHP
Information Exposure vulnerability in multiple products

pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client.

7.5
2015-12-02 CVE-2015-8387 Pcre
Fedoraproject
PHP
Integer Overflow or Wraparound vulnerability in multiple products

PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

7.3

1 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2015-12-06 CVE-2015-3195 Apple
Oracle
Openssl
Redhat
Canonical
Debian
Opensuse
Suse
Fedoraproject
Information Exposure vulnerability in multiple products

The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.

5.3

0 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS