CVE-2008-0322


Published: 13-05-2008

Product:
Microsoft: windows-nt XP

Severity: High (7.2)

CVSS vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C)

Attack`s vector: Localy exploitable

Potential loss type: Gain administrative access, Integrity, Confidentiality, Availability

Vulnerability description:
The I2O Utility Filter driver (i2omgmt.sys) 5.1.2600.2180 for Microsoft Windows XP sets Everyone/Write permissions for the"\\.\I2OExc"device interface, which allows local users to gain privileges.  NOTE: this issue can be leveraged to overwrite arbitrary memory and execute code via an IOCTL call with a crafted DeviceObject pointer.

Patch available: Yes

References:
IDEFENSE: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=6 ...
BID: http://www.securityfocus.com/bid/29171
FRSIRT: http://www.frsirt.com/english/advisories/2008/1476/references
SECUNIA: http://secunia.com/advisories/30203

Cisco Security Advisory: Multiple Vulnerabilities in Cisco PIX and Cisco ASA

Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive
Security Appliances and Cisc ...

23 october, 2008

Cisco Security Advisory: Authentication Bypass in Cisco Unity

A vulnerability exists in Cisco Unity that could allow an unauthenticated user to view or modify som ...

08 october, 2008

Cisco Security Advisory: Cisco 10000, uBR10012, uBR7200 Series Devices IPC Vulnerability

Cisco 10000, uBR10012 and uBR7200 series devices use a User Datagram Protocol (UDP) based Inter-Pro ...

25 september, 2008

(MS08-069) Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218)

This security update resolves several vulnerabilities in Microsoft XML Core Services.

12 november, 2008

(MS08-068) Vulnerability in SMB Could Allow Remote Code Execution (957097)

This security update resolves a publicly disclosed vulnerability in Microsoft Server Message Block & ...

12 november, 2008

(MS08-067) Vulnerability in Server Service Could Allow Remote Code Execution (958644)

The vulnerability could allow remote code execution if an affected system received a specially craft ...

23 october, 2008

CVE-2008-5284

The web server in IEA Software RadiusNT and RadiusX 5.1.38 and other versions before 5.1.44, Emerald 5.0.49 and other versions before 5.0.52, Air Marshal 2.0.4 and other versions before 2.0.8, and Radius test client (aka Radlogin) 4.0.20 and earlier, allows remote attackers to cause a denial of service (crash) via an HTTP Content-Length header with a negative value, which triggers a single byte overwrite of memory using a NULL terminator.  NOTE: some of these details are obtained from third party information.

CVE-2008-5283

Google Hack Honeypot (GHH) File Upload Manager 1.3 allows remote attackers to delete uploaded files via unknown vectors related to the delall action to index.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. CVE analysis suggests that the most recent version as of 20081128 is 1.2, and the File Upload Manager does not have a "delall" action.

CVE-2008-5282

Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF attribute, and (2) a DIV tag with a long id attribute.

CVE-2008-5281

Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a long DELE command.

CVE-2008-5280

The Local ZIM Server in Zilab Chat and Instant Messaging (ZIM) Server 2.0 and 2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted requests without required parameters.

CVE-2008-5279

The Local ZIM Server (zcs.exe) in Zilab Chat and Instant Messaging (ZIM) Server 2.1 and earlier allow remote attackers to execute arbitrary code via (1) heap-based buffer overflows involving multiple vectors including a long room name and a long source account, and (2) a stack-based buffer overflow with a long username in an information request.  NOTE: some of these details are obtained from third party information.

CVE-2008-5278

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

CVE-2008-5275

Multiple directory traversal vulnerabilities in the (a) "Unzip archive" and (b) "Upload files and archives" functionality in net2ftp 0.96 stable and 0.97 beta allow remote attackers to create, read, or delete arbitrary files via a .. (dot dot) in a filename within a (1) TAR or (2) ZIP archive.  NOTE: this can be leveraged for code execution by creating a .php file.

CVE-2008-5274

Todd Woolums ASP News Management 2.2 allows remote attackers to obtain news items via a direct request to (1) rss.asp, (2) viewheadings.asp, or (3) viewnews.asp.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2008-5273

SQL injection vulnerability in viewnews.asp in Todd Woolums ASP News Management 2.2 allows remote attackers to execute arbitrary SQL commands via the newsID parameter.

CVE-2008-5272

Multiple directory traversal vulnerabilities in Fred Stuurman SyndeoCMS 2.6.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the template parameter to (1) starnet/editors/fckeditor/studenteditor.php; (2) starnet/modules/sn_news/edit_content.php, reached through starnet/index.php; and (3) starnet/modules/sn_newsletter/edit_content.php, reached through starnet/index.php.

CVE-2008-5271

Cross-site scripting (XSS) vulnerability in index.php in Fred Stuurman SyndeoCMS 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

CVE-2008-5270

SQL injection vulnerability in view.topics.php in Yuhhu Superstar 2008 allows remote attackers to execute arbitrary SQL commands via the board parameter.

CVE-2008-5269

SQL injection vulnerability in index.php in pSys 0.7.0 alpha allows remote attackers to execute arbitrary SQL commands via the shownews parameter.

CVE-2008-5268

SQL injection vulnerability in content/forums/reply.asp in ASPPortal allows remote attackers to execute arbitrary SQL commands via the Topic_Id parameter.

A Buffer Overflow Security Vulnerability in the Solaris sadmind(1M) Daemon May Lead to Execution of Arbitrary Code

A Buffer Overflow Security Vulnerability in the Solaris sadmind(1M) Daemon May Lead to Execu ...

17 november, 2008

A Security Vulnerability in the Solaris i915 DRM Driver May Cause a Kernel Panic

An insufficient resource management security vulnerability in the Solaris i915 Direct Rendering Mana ...

17 november, 2008

Security Vulnerability in StarOffice/StarSuite Related to EMF Files May Lead to Heap Overflows and Arbitrary Code Execution

A security vulnerability with the way StarOffice/StarSuite 7 and 8 process EMF files may allow a rem ...

17 november, 2008

[RHSA-2008:1001-01] Important: tog-pegasus security update

Red Hat Security Advisory - Important: tog-pegasus security update

25 november, 2008

[RHSA-2008:0955-01] Critical: java-1.4.2-ibm security update

Red Hat Security Advisory - Critical: java-1.4.2-ibm security update

25 november, 2008

[RHSA-2008:0618-01] Moderate: vim security update

Red Hat Security Advisory - Moderate: vim security update

25 november, 2008

Electronics Workbench (EWB File) Local Stack Overflow PoC

Target: Electronics Workbench
Impact: Denial of service

KTP Computer Customer Database CMS Local File Inclusion Exploit

Target: KTP Computer Customer Database
Impact: Ðàñêðûòèå âàæíûõ äàííûõ

Lito Lite CMS (cate.php cid) Remote SQL Injection Exploit

Target: Lito Lite CMS
Impact: SQL injection