SB2012110401 - Multiple vulnerabilities in cockroachdb pebble
Published: November 4, 2012 Updated: August 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2012-4022)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.
Pebble before 2.6.4 allows remote attackers to trigger loss of blog-entry viewability via a crafted comment.
2) Input validation error (CVE-ID: CVE-2012-4023)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote non-authenticated attacker to manipulate data.
CRLF injection vulnerability in Pebble before 2.6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
3) Input validation error (CVE-ID: CVE-2012-5170)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Remediation
Install update from vendor's website.
References
- http://jvn.jp/en/jp/JVN75492883/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2012-000098
- http://secunia.com/advisories/51102
- http://jvn.jp/en/jp/JVN39563771/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2012-000099
- http://jvn.jp/en/jp/JVN55398821/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2012-000100
- http://osvdb.org/86890
- http://www.securityfocus.com/bid/56370
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79757