By michele654 on Friday, 05 July 2024
Category: Vulnerabilities

New Vulnerabilities Friday 05 July


New Alerts for Exim, CODESYS, IBM, and Linux.

Exim 

Exim misparses a multiline RFC 2231 header filename, allowing remote attackers to bypass a $mime_filename extension-blocking protection mechanism, and deliver executable attachments to the mailboxes of end users.
More info.

CODESYS 

CODESYS Control runtime system uses the OPC UA stack, which is vulnerable to a DoS. CVSSv3 score of 7.5
More info.

IBM 

IBM Instana Observability is vulnerable to Improper Input Validation due to Apache Avro Java SDK. CVSSv3 score of 9.8
More info.

Linux 

A vulnerability in IPv6 can lead to a DoS.
More info.

There are several other linux vulnerabilities reported, worth a look. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details