DarkReading |TI

Cartoon Caption Winner: Road Trip

Enterprise Vulnerabilities
From DHS/US-CERT’s National Vulnerability Database CVE-2021-23394
PUBLISHED: 2021-06-13

The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.

CVE-2021-34682
PUBLISHED: 2021-06-12

Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.

CVE-2021-31811
PUBLISHED: 2021-06-12

In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.

CVE-2021-31812
PUBLISHED: 2021-06-12

In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.

CVE-2021-32552
PUBLISHED: 2021-06-12

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.

Read More HERE

Leave a Reply