Dangerous vulnerabilities in QEMU, Node.js, Grafana, and Android.

Several recently discovered vulnerabilities:

  • The vulnerability (CVE-2020-13765) in QEMU, which may potentially allow for code execution with QEMU process privileges on the host system when booting a specially crafted kernel image in the guest system. The issue is caused by a buffer overflow in the code that copies contents from ROM during the system boot phase and manifests when loading a 32-bit kernel image into memory. The fix is currently available only in the form of a patch.
  • Four vulnerabilities in Node.js. The vulnerabilities four vulnerabilities have been fixed in releases 14.4.0, 10.21.0, and 12.18.0.
    • CVE-2020-8172 — allows bypassing the host certificate check when reusing a TLS session.
    • CVE-2020-8174 — potentially allows code execution in the system due to a buffer overflow in the functions napi_get_value_string_(), occurring with certain calls to N-API (C API for writing native addons).
    • CVE-2020-10531 — integer overflow in ICU (International Components for Unicode) for C/C++, which may lead to a buffer overflow when using the UnicodeString::doAppend() function.
    • CVE-2020-11080 — allows for a denial of service (100% CPU load) via transmission of large 'SETTINGS' frames when connecting over HTTP/2.
  • The vulnerability in the Grafana metrics visualization platform used for creating visual monitoring graphs based on various data sources. A flaw in the code handling avatars allows initiating an HTTP request from Grafana to any URL without authentication and viewing the result of that request. This feature can be exploited, for example, to explore the internal network of companies using Grafana. The issue has been closed in releases
    Grafana 6.7.4 and 7.0.2. As a workaround, it is recommended to restrict access to the URL '/avatar/*' on the server with Grafana.
  • Published the June security patch set for Android, which fixes 34 vulnerabilities. Four issues have been assigned a critical severity level: two vulnerabilities (CVE-2019-14073, CVE-2019-14080) in proprietary Qualcomm components and two vulnerabilities in the system that allow code execution when processing specially crafted external data (CVE-2020-0117 — integer overflow in the Bluetooth stack, CVE-2020-8597 — EAP overflow in pppd).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster