SB2023120117 - Multiple vulnerabilities in IBM QRadar WinCollect Agent
Published: December 1, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 secuirty vulnerabilities.
1) Incorrect Regular Expression (CVE-ID: CVE-2022-25883)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing regular expressions. A remote attacker can pass specially crafted data to the application via the new Range function and perform regular expression denial of service (ReDos) attack.
2) Out-of-bounds read (CVE-ID: CVE-2023-1255)
The vulnerability allows an attacker to perform a denial of service (DoS) attack.
3) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2023-32001)
The vulnerability allows a local users to escalate privileges on the system.
The vulnerability exists due to a race condition when calling fopen() on STS and/or alt-svc data to files. A local user can create or rename directory entries in the directory the victim saves their files and abuse the symbolic link behavior to overwrite arbitrary files on the system.
4) Resource exhaustion (CVE-ID: CVE-2023-38039)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not limit the size of received headers from a single request that are stored for future reference. A remote attacker can send overly large HTTP responses to the application and consume all memory resources.
5) Information disclosure (CVE-ID: CVE-2021-39008)
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote privileged user can gain unauthorized access to sensitive information on the system.
6) Input validation error (CVE-ID: CVE-2023-26279)
The vulnerability allows a local user to perform unauthorized actions on the system.
The vulnerability exists due to insufficient validation of encoding. A local user can perform unauthorized actions on the system.
Remediation
Install update from vendor's website.