This update backports an upstream patch to fix multiple integer overflows (CVE-2016-9085).
Monthly Archives: October 2016
libwebp-0.5.1-2.fc24
This update backports an upstream patch to fix multiple integer overflows (CVE-2016-9085).
NVIDIA NvStreamKms PsSetCreateProcessNotifyRoutineEx Stack Buffer Overflow
The NvStreamKms.sys driver calls PsSetCreateProcessNotifyRoutineEx to set up a process creation notification routine. wcscpy_s is used incorrectly here, as the second argument is not the size of |Dst|, but rather the calculated size of the filename. |Dst| is a stack buffer that is at least 255 characters long. The the maximum component paths of most filesystems on Windows have a limit that is <= 255 though, so this shouldn’t be an issue on normal filesystems. However, one can pass UNC paths to CreateProcessW containing forward slashes as the path delimiter, which means that the extracted filename here can be “a/b/c/…”, leading to a buffer overflow. Additionally, this function has no stack cookie.
NVIDIA 0x5000027 DxgkDdiEscape Handler Write
The DxgkDdiEscape handler for 0x5000027 accepts a user provided pointer, but does no checks on it before using it.
Mirai Botnet Itself is Flawed; Hacking Back IoTs Could Mitigate DDoS Attacks
The infamous botnet that was used in the recent massive distributed denial of service (DDoS) attacks against the popular DNS provider Dyn, causing vast internet outage on last Friday, itself is flawed.
Yes, Mirai malware, which has already enslaved millions of Internet of Things (IoT) devices across 164 countries, contains several vulnerabilities that might be used against it in order to
![]()
NVIDIA 0x100010b Missing Bounds Check
NVIDIA suffers from a missing bounds check in escape 0x100010b.
NVIDIA 0x70001b2 DxgkDdiEscape Handler Bounds Checking
The DxgkDdiEscape handler for 0x70001b2 doesn’t do proper bounds checks for its variable size input.
Bugtraq: [security bulletin] HPSBHF3549 ThinkPwn UEFI BIOS SmmRuntime Escalation of Privilege
[security bulletin] HPSBHF3549 ThinkPwn UEFI BIOS SmmRuntime Escalation of Privilege
Bugtraq: [security bulletin] HPSBMU03653 rev.1 – HPE System Management Homepage (SMH), Remote Arbitrary Code Execution, Cross-Site Scripting (XSS), Denial of Service (DoS), Unauthorized Disclosure of Information
[security bulletin] HPSBMU03653 rev.1 – HPE System Management Homepage (SMH), Remote Arbitrary Code Execution, Cross-Site Scripting (XSS), Denial of Service (DoS), Unauthorized Disclosure of Information
Bugtraq: APPLE-SA-2016-10-27-3 iTunes 12.5.2 for Windows
APPLE-SA-2016-10-27-3 iTunes 12.5.2 for Windows
