FreeBSD Security Advisory - During certificate verification, OpenSSL will attempt to find an alternative certificate chain if the first attempt to build such a chain fails, unless the application explicitly specifies X509_V_FLAG_NO_ALT_CHAINS. An error in the implementation of this logic could erroneously mark certificate as trusted when they should not. An attacker could cause certain checks on untrusted certificates, such as the CA (certificate authority) flag, to be bypassed, which would enable them to use a valid leaf certificate to act as a CA and issue an invalid certificate.
7506aba3461e8c1915436a9531f38abc96e09fee2b93caefa87da64dce1a32d3
VMware Security Advisory 2015-0005 - VMware Workstation, Player, and Horizon View Client for Windows updates address a host privilege escalation vulnerability.
59a3124a6a1edf44fcbd19fea4a8569a864b53e76d75f7d23cf7672bccf89777
Gentoo Linux Security Advisory 201507-15 - Certain checks on untrusted certificates can be bypassed. Versions less than 1.0.1p are affected.
a2cdd3e13ff08aecad86dae1e1117c6751bff280917deb2d2154138c8a75ffa1
Gentoo Linux Security Advisory 201507-14 - Multiple vulnerabilities have been found in Oracle JRE/JDK, allowing both local and remote attackers to compromise various Java components. Versions less than 1.8.0.31 are affected.
68f7370a0bb86460a4c7ad46df242b19a472738fa3278d4a412b9ef00ea75454
Gentoo Linux Security Advisory 201507-13 - Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code. Versions less than 11.2.202.481 are affected.
9e22b6b377c344d3976d867790d2fd90102944fdef8f98bff06a9f65c5188c39
Gentoo Linux Security Advisory 201507-11 - A vulnerability in Perl allows a remote attacker to cause Denial of Service. Versions less than 5.20.1-r4 are affected.
92515b5641c1e04669a5ea77ae2c669b3dd743bbd5792ebb1240d321f4dd6d41
Gentoo Linux Security Advisory 201507-10 - A buffer overflow in t1utils could result in execution of arbitrary code or Denial of Service. Versions less than 1.39 are affected.
05ca903eeb3ce5acf7366fd02c94a11d61f4a7197aae58a48cf9641a3345cb86
HP Security Bulletin HPSBGN03371 1 - Potential security vulnerabilities have been identified with HP IceWall Products running OpenSSL. The vulnerabilities could be exploited remotely resulting in Denial of Service (DoS). Revision 1 of this advisory.
3b3270a97d3384fea9dbdef49cee0353bed3e10a622c74e5224fabc91b870a86
Debian Linux Security Advisory 3307-1 - Toshifumi Sakaguchi discovered that the patch applied to pdns-recursor, a recursive DNS server, fixing CVE-2015-1868, was insufficient in some cases, allowing remote attackers to cause a denial of service (service-affecting CPU spikes and in some cases a crash).
52c2f6866da2d72e1111af168275c5446d2db324e865b7f2e7e95a1eff611b4f
Debian Linux Security Advisory 3306-1 - Toshifumi Sakaguchi discovered that the patch applied to pdns, an authoritative DNS server, fixing CVE-2015-1868, was insufficient in some cases, allowing remote attackers to cause a denial of service (service-affecting CPU spikes and in some cases a crash).
1a215fcb65099e37092b0721efe6f44ea5c98f4af9701285916a1353d36f6778
Slackware Security Advisory - New openssl packages are available for Slackware 14.0, 14.1, and -current to fix a security issue.
fab3a5f845a8a609a8f716281160940dde18a47c55720da981a19fa511dce1a8
Gentoo Linux Security Advisory 201507-19 - Multiple vulnerabilities have been found in MySQL, allowing attackers to execute arbitrary code or cause Denial of Service. Versions less than 5.6.24 are affected.
d15e7fb0c0ce49127e5f6e5f934fc256af2e2cf5d16264d6097fe29a7c5bacd4
Gentoo Linux Security Advisory 201507-18 - Multiple vulnerabilities have been found in Chromium allowing remote attackers to bypass security restrictions. Versions less than 43.0.2357.130 are affected.
e6d136f83c61862e30d3b807e3cb9fe2bf4c55d0ee24c892a5afc033585067af
Gentoo Linux Security Advisory 201507-17 - A vulnerability in SNMP could lead to Denial of Service condition. Versions less than 5.7.3_pre5-r1 are affected.
da1a650a530e7660f2ea01e920dd40a172c53f238e9bfd938a922c6384fe8ee8
Gentoo Linux Security Advisory 201507-16 - A vulnerability in Portage's urlopen function could allow a remote attacker to conduct a man-in-the-middle attack. Versions less than 2.1.12.2 are affected.
ffde84fd8885d942bee352410952274e352dc9000f2dd14faa0ddc1a239ce71a
The Android ABD utility backup manager, which invokes the custom BackupAgent, does not filter the data stream returned by the applications. While a BackupAgent is being executed during the backup process, it is able to inject additional applications (APKs) into the backup archive without the user's consent. The BackupAgent needs no Android permissions. Upon restoration of the backup archive, the system installs the injected, additional application (since it is part of the backup archive and the system believes it is authentic) with escalated privileges. Proof of concept code included.
d376ef512eaaa814a39535b0eb8c3bd952e0156ea5d7dc7981001d630f3697b5
EMC RecoverPoint for VMs 4.3 contains fixes for a restriction bypass vulnerability that could potentially be exploited by malicious users to compromise the affected system.
b791da096acfb920bf6e25f91e7a691a93a2573bb230ba63e8fc5e12bce911f3
Arab Portal version 3 suffers from a remote SQL injection vulnerability.
ef75d0dfb6f860bfb269b4aff5abc5565e76f6afd91f5ab2e7a00aa9c155bdbc
UPNPD M-Search ssdp:discover reflection denial of service exploit.
f367c58f0ffd545e2d90772fec10aeb953a0bcdc97164f66bdb1c8a16e3d98a9