Several recently discovered vulnerabilities:
- Three vulnerabilities in the open-source automated design system LibreCAD and the libdxfrw library that could trigger a controlled buffer overflow and potentially allow the execution of arbitrary code when opening specially crafted files in DWG and DXF formats. The issues have only been addressed in the form of patches (CVE-2021-21898, CVE-2021-21899, CVE-2021-21900).
- A vulnerability (CVE-2021-41817) in the Date.parse method provided in the standard library of the Ruby language. Flaws in the regular expressions used to parse dates in the Date.parse method can be exploited to perform DoS attacks, leading to significant CPU resource consumption and memory exhaustion when processing specially crafted data.
- A vulnerability in the TensorFlow machine learning platform (CVE-2021-41228) allows for arbitrary code execution when the saved_model_cli utility processes data from an attacker supplied via the '—input_examples' parameter. This issue arises from the use of external data when the 'eval' function is invoked. The problem has been resolved in TensorFlow releases 2.7.0, 2.6.1, 2.5.2, and 2.4.4.
- A vulnerability (CVE-2021-43331) in the GNU Mailman mailing list management system, caused by improper handling of certain types of URLs. This issue allows for the execution of JavaScript code by specifying a specially crafted URL on the settings page. Another problem has also been identified in Mailman (CVE-2021-43332), allowing a user with moderator privileges to guess the administrator password. These issues have been fixed in the Mailman 2.1.36 release.
- A series of vulnerabilities in the Vim text editor that can lead to buffer overflows and potentially allow for the execution of arbitrary code when opening specially crafted files using the '-S' option (CVE-2021-3903, CVE-2021-3872, CVE-2021-3927, CVE-2021-3928, fixes — 1, 2, 3, 4).
Source: opennet.ru
