Recently I discovered some vulnerabilities in
GNU Readline. These bugs
have been
fixed
in GNU Readline version 8.1.
The case of identifying the vulnerabilities was rather interesting. I wanted to
fuzz another program and wrote a quick harness to test if my setup works. This
test harness used GNU Readline to read input from stdin and passed the data
along to the function under test. I left the fuzzer running while I started to
improve the harness (which would also mean getting rid of GNU Readline as it is
relatively slow for the use-case at hand). However, AFL showed the first crashes
and upon inspection, the vulnerabilities where not in the code I actually wanted
to fuzz but in my systems GNU Readline.
Last week I had the pleasure to attend
Offensivecon 2019 in Berlin. The conference was
organized very well, and I liked the familial atmosphere which allowed to meet
lots of different people. Thanks to the organizers, speakers and everyone else
involved for this conference! Andreas posted a
one tweet tldr of
the first day; fuzzing is still the way to go to find bugs, and mitigations make
exploitation harder. Here are some short summaries of the talks I enjoyed.
Recently, we identified security issues in the Nexus Repository Manager software
developed by Sonatype. The tested versions were OSS 3.12.1-01 and OSS 3.13.1-01.
We identified a Java Expression Language Injection in the role and user creation
function. In order to exploit this issue, the attacker needs to be authenticated
with high privileges, the standard anonymous user is not sufficient.
We recently identified security issues in the UNIFY OpenScape Desk Phone CP600
HFA software. We disclosed the vulnerabilities to Unify, as a fix is now
provided we want to give a brief overview of the vulnerability affecting the web
interface.
We were able to identify the following vulnerabilities in the Web interface of
the telephone:
Command Injection in Picture Delete function of OpenScape Desk Phone Webportal
Unauthenticated Arbitrary File Access in the OpenScape Desk Phone Webportal
Memory Corruption in the OpenScape Desk Phone Webservice
Missing Hardening of the OpenScape Desk Phone Webservice Binary
Cross Site Request Forgery Missing in the OpenScape Desk Phone Webservice