SB2025021236 - Multiple vulnerabilities in IBM Dynamic System Analysis (DSA) Preboot
Published: February 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 secuirty vulnerabilities.
1) Heap-based buffer overflow (CVE-ID: CVE-2015-9262)
The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in _XcursorThemeInherits in library.c. A remote attacker can trigger a one-byte heap overflow and cause the service to crash or execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
2) Privilege escalation (CVE-ID: CVE-2018-14665)
The vulnerability allows a local user to gain elevated privileges on the target system.
The vulnerability exists due to improper handling of two command-line options, namely -logfile and -modulepath. A local user can specify a '-modulepath' argument with an insecure path to create, overwrite or delete any files with root privileges.
3) Out-of-bounds write (CVE-ID: CVE-2018-14600)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to out-of-bounds write when handling malicious input. A remote unauthenticated attacker can trick the victim into opening a specially crafted data, trigger memory corruption and execute arbitrary code on the target X client.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
4) Off-by-one error (CVE-ID: CVE-2018-14599)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to an off-by-one memory write error in the XGetFontPath(), XListExtensions(), and XListFonts() functions. A remote unauthenticated attacker can cause a remote X server to return a specially crafted response to trigger memory corruption and execute arbitrary code on the target X client.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
5) Improper input validation (CVE-ID: CVE-2018-14598)
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to an error when handling malicious input. A remote unauthenticated attacker can cause a remote server to return a specially crafted reply to cause the target X client to crash.
Remediation
Install update from vendor's website.