Posts by Arch (old posts, page 4)

[ASA-202505-10] python-django: denial of service

A remote attacker can exploit inefficient HTML tag parsing in Django’s strip_tags() function to cause excessive CPU usage, leading to a denial of service. This may affect applications that use the striptags template filter to sanitize user-controlled input, making them vulnerable to slowdown or unresponsiveness when handling specially crafted HTML content.

[ASA-202505-8] nodejs-lts-iron: multiple issues

A remote attacker can exploit multiple vulnerabilities in Node.js to cause a denial of service or bypass access restrictions. Improper error handling and memory management flaws may crash the process or lead to unbounded memory usage, while an HTTP parsing inconsistency in Node.js 20.x can enable request smuggling, allowing attackers to evade proxy-based access controls and submit unauthorized requests.

[ASA-202505-7] nodejs-lts-jod: denial of service

A remote attacker can exploit improper error handling and memory management flaws in Node.js to crash the process or exhaust system resources, leading to a denial of service. Specifically, malformed input may trigger a crash in asynchronous cryptographic operations, while repeated use of file system APIs with crafted input may cause unbounded memory growth.

[ASA-202505-5] webkitgtk-6.0: arbitrary code execution

A remote attacker could craft malicious web content that exploits use-after-free vulnerabilities in WPE WebKit, potentially leading to arbitrary code execution. This can compromise the confidentiality, integrity, and availability of affected systems, especially those rendering untrusted web content through WPE WebKit.

[ASA-202505-4] webkit2gtk-4.1: arbitrary code execution

A remote attacker could craft malicious web content that exploits use-after-free vulnerabilities in WPE WebKit, potentially leading to arbitrary code execution. This can compromise the confidentiality, integrity, and availability of affected systems, especially those rendering untrusted web content through WPE WebKit.

[ASA-202505-3] webkit2gtk: arbitrary code execution

A remote attacker could craft malicious web content that exploits use-after-free vulnerabilities in WPE WebKit, potentially leading to arbitrary code execution. This can compromise the confidentiality, integrity, and availability of affected systems, especially those rendering untrusted web content through WPE WebKit.