[FD] SEC Consult SA-20230117-2 :: Multiple post-authentication vulnerabilities including RCE in @OpenText Content Server component of OpenText Extended ECM

2023-01-19 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20230117-2 > === title: Multiple post-authentication vulnerabilities including RCE product: OpenText™ Content Server component of OpenText™ Extended ECM

[FD] SEC Consult SA-20230117-1 :: Pre-authenticated Remote Code Execution via Java frontend and QDS endpoint in @OpenText Content Server component of OpenText Extended ECM

2023-01-19 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20230117-1 > === title: Pre-authenticated Remote Code Execution via Java frontend and QDS endpoint product: OpenText™ Content Serve

[FD] SEC Consult SA-20230117-0 :: Pre-authenticated Remote Code Execution in cs.exe (@OpenText Content Server component of OpenText Extended ECM)

2023-01-19 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20230117-0 > === title: Pre-authenticated Remote Code Execution in cs.exe product: OpenText™ Content Server component of OpenText™ Extended ECM vulner

[FD] HNS-2022-01 - HN Security Advisory - Multiple vulnerabilities in Solaris dtprintinfo and libXm/libXpm

2023-01-19 Thread Marco Ivaldi
Dear Full Disclosure, Find attached a security advisory that details multiple vulnerabilities we discovered in Oracle Solaris CDE dtprintinfo, Motif libXm, and X.Org libXpm. * Title: Multiple vulnerabilities in Solaris dtprintinfo and libXm/libXpm * Products: Common Desktop Environment 1.6, Motif

[FD] wolfSSL before 5.5.2: Heap-buffer over-read with WOLFSSL_CALLBACKS

2023-01-19 Thread Maximilian Ammann via Fulldisclosure
# wolfSSL before 5.5.2: Heap-buffer over-read with WOLFSSL_CALLBACKS ## INFO === The CVE project has assigned the id CVE-2022-42905 to this issue. Severity: 9.1 CRITICAL Affected version: before 5.5.2 End of embargo: Ended

[FD] wolfSSL before 5.5.0: Denial-of-service with session resumption

2023-01-19 Thread Maximilian Ammann via Fulldisclosure
# wolfSSL before 5.5.0: Denial-of-service with session resumption = ## INFO === The CVE project has assigned the id CVE-2022-38152 to this issue. Severity: 7.5 HIGH Affected version: before 5.5.0 End of embargo: Ended August 30,

[FD] wolfSSL 5.3.0: Denial-of-service

2023-01-19 Thread Maximilian Ammann via Fulldisclosure
# wolfSSL 5.3.0: Denial-of-service == ## INFO === The CVE project has assigned the id CVE-2022-38153 to this issue. Severity: 5.9 MEDIUM Affected version: 5.3.0 End of embargo: Ended August 30, 2022 Blog Post: https://blog.trailofbits.com/2023/01/12/wolfssl-v

[FD] wolfSSL before 5.5.0: Denial-of-service with session resumption

2023-01-19 Thread Maximilian Ammann via Fulldisclosure
# wolfSSL before 5.5.0: Denial-of-service with session resumption = ## INFO === The CVE project has assigned the id CVE-2022-38152 to this issue. Severity: 7.5 HIGH Affected version: before 5.5.0 End of embargo: Ended August 30,