what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 19 of 19 RSS Feed

Files Date: 2015-07-10

FreeBSD Security Advisory - OpenSSL Certificate Forgery
Posted Jul 10, 2015
Authored by Adam Langley, David Benjamin | Site security.freebsd.org

FreeBSD Security Advisory - During certificate verification, OpenSSL will attempt to find an alternative certificate chain if the first attempt to build such a chain fails, unless the application explicitly specifies X509_V_FLAG_NO_ALT_CHAINS. An error in the implementation of this logic could erroneously mark certificate as trusted when they should not. An attacker could cause certain checks on untrusted certificates, such as the CA (certificate authority) flag, to be bypassed, which would enable them to use a valid leaf certificate to act as a CA and issue an invalid certificate.

tags | advisory
systems | freebsd
advisories | CVE-2015-1793
SHA-256 | 7506aba3461e8c1915436a9531f38abc96e09fee2b93caefa87da64dce1a32d3
VMware Security Advisory 2015-0005
Posted Jul 10, 2015
Authored by VMware | Site vmware.com

VMware Security Advisory 2015-0005 - VMware Workstation, Player, and Horizon View Client for Windows updates address a host privilege escalation vulnerability.

tags | advisory
systems | windows
advisories | CVE-2015-3650
SHA-256 | 59a3124a6a1edf44fcbd19fea4a8569a864b53e76d75f7d23cf7672bccf89777
Gentoo Linux Security Advisory 201507-15
Posted Jul 10, 2015
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201507-15 - Certain checks on untrusted certificates can be bypassed. Versions less than 1.0.1p are affected.

tags | advisory
systems | linux, gentoo
advisories | CVE-2015-1793
SHA-256 | a2cdd3e13ff08aecad86dae1e1117c6751bff280917deb2d2154138c8a75ffa1
Gentoo Linux Security Advisory 201507-14
Posted Jul 10, 2015
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201507-14 - Multiple vulnerabilities have been found in Oracle JRE/JDK, allowing both local and remote attackers to compromise various Java components. Versions less than 1.8.0.31 are affected.

tags | advisory, java, remote, local, vulnerability
systems | linux, gentoo
advisories | CVE-2014-3566, CVE-2014-6549, CVE-2014-6585, CVE-2014-6587, CVE-2014-6591, CVE-2014-6593, CVE-2014-6601, CVE-2015-0383, CVE-2015-0395, CVE-2015-0400, CVE-2015-0403, CVE-2015-0406, CVE-2015-0407, CVE-2015-0408, CVE-2015-0410, CVE-2015-0412, CVE-2015-0413, CVE-2015-0421
SHA-256 | 68f7370a0bb86460a4c7ad46df242b19a472738fa3278d4a412b9ef00ea75454
Gentoo Linux Security Advisory 201507-13
Posted Jul 10, 2015
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201507-13 - Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code. Versions less than 11.2.202.481 are affected.

tags | advisory, remote, arbitrary, vulnerability
systems | linux, gentoo
advisories | CVE-2014-0578, CVE-2015-3113, CVE-2015-3114, CVE-2015-3115, CVE-2015-3116, CVE-2015-3117, CVE-2015-3118, CVE-2015-3119, CVE-2015-3120, CVE-2015-3121, CVE-2015-3122, CVE-2015-3123, CVE-2015-3124, CVE-2015-3125, CVE-2015-3126, CVE-2015-3127, CVE-2015-3128, CVE-2015-3129, CVE-2015-3130, CVE-2015-3131, CVE-2015-3132, CVE-2015-3133, CVE-2015-3134, CVE-2015-3135, CVE-2015-3136, CVE-2015-3137, CVE-2015-4428, CVE-2015-4429
SHA-256 | 9e22b6b377c344d3976d867790d2fd90102944fdef8f98bff06a9f65c5188c39
Gentoo Linux Security Advisory 201507-11
Posted Jul 10, 2015
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201507-11 - A vulnerability in Perl allows a remote attacker to cause Denial of Service. Versions less than 5.20.1-r4 are affected.

tags | advisory, remote, denial of service, perl
systems | linux, gentoo
advisories | CVE-2013-7422
SHA-256 | 92515b5641c1e04669a5ea77ae2c669b3dd743bbd5792ebb1240d321f4dd6d41
Gentoo Linux Security Advisory 201507-10
Posted Jul 10, 2015
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201507-10 - A buffer overflow in t1utils could result in execution of arbitrary code or Denial of Service. Versions less than 1.39 are affected.

tags | advisory, denial of service, overflow, arbitrary
systems | linux, gentoo
advisories | CVE-2015-3905
SHA-256 | 05ca903eeb3ce5acf7366fd02c94a11d61f4a7197aae58a48cf9641a3345cb86
HP Security Bulletin HPSBGN03371 1
Posted Jul 10, 2015
Authored by HP | Site hp.com

HP Security Bulletin HPSBGN03371 1 - Potential security vulnerabilities have been identified with HP IceWall Products running OpenSSL. The vulnerabilities could be exploited remotely resulting in Denial of Service (DoS). Revision 1 of this advisory.

tags | advisory, denial of service, vulnerability
advisories | CVE-2015-1789, CVE-2015-1790, CVE-2015-1792
SHA-256 | 3b3270a97d3384fea9dbdef49cee0353bed3e10a622c74e5224fabc91b870a86
Debian Security Advisory 3307-1
Posted Jul 10, 2015
Authored by Debian | Site debian.org

Debian Linux Security Advisory 3307-1 - Toshifumi Sakaguchi discovered that the patch applied to pdns-recursor, a recursive DNS server, fixing CVE-2015-1868, was insufficient in some cases, allowing remote attackers to cause a denial of service (service-affecting CPU spikes and in some cases a crash).

tags | advisory, remote, denial of service
systems | linux, debian
advisories | CVE-2015-1868
SHA-256 | 52c2f6866da2d72e1111af168275c5446d2db324e865b7f2e7e95a1eff611b4f
Debian Security Advisory 3306-1
Posted Jul 10, 2015
Authored by Debian | Site debian.org

Debian Linux Security Advisory 3306-1 - Toshifumi Sakaguchi discovered that the patch applied to pdns, an authoritative DNS server, fixing CVE-2015-1868, was insufficient in some cases, allowing remote attackers to cause a denial of service (service-affecting CPU spikes and in some cases a crash).

tags | advisory, remote, denial of service
systems | linux, debian
advisories | CVE-2015-1868
SHA-256 | 1a215fcb65099e37092b0721efe6f44ea5c98f4af9701285916a1353d36f6778
Slackware Security Advisory - openssl Updates
Posted Jul 10, 2015
Authored by Slackware Security Team | Site slackware.com

Slackware Security Advisory - New openssl packages are available for Slackware 14.0, 14.1, and -current to fix a security issue.

tags | advisory
systems | linux, slackware
advisories | CVE-2015-1793
SHA-256 | fab3a5f845a8a609a8f716281160940dde18a47c55720da981a19fa511dce1a8
Gentoo Linux Security Advisory 201507-19
Posted Jul 10, 2015
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201507-19 - Multiple vulnerabilities have been found in MySQL, allowing attackers to execute arbitrary code or cause Denial of Service. Versions less than 5.6.24 are affected.

tags | advisory, denial of service, arbitrary, vulnerability
systems | linux, gentoo
advisories | CVE-2015-0405, CVE-2015-0423, CVE-2015-0433, CVE-2015-0438, CVE-2015-0439, CVE-2015-0441, CVE-2015-0498, CVE-2015-0499, CVE-2015-0500, CVE-2015-0501, CVE-2015-0503, CVE-2015-0505, CVE-2015-0506, CVE-2015-0507, CVE-2015-0508, CVE-2015-0511, CVE-2015-2566, CVE-2015-2567, CVE-2015-2568, CVE-2015-2571, CVE-2015-2573
SHA-256 | d15e7fb0c0ce49127e5f6e5f934fc256af2e2cf5d16264d6097fe29a7c5bacd4
Gentoo Linux Security Advisory 201507-18
Posted Jul 10, 2015
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201507-18 - Multiple vulnerabilities have been found in Chromium allowing remote attackers to bypass security restrictions. Versions less than 43.0.2357.130 are affected.

tags | advisory, remote, vulnerability
systems | linux, gentoo
advisories | CVE-2015-1266, CVE-2015-1267, CVE-2015-1268, CVE-2015-1269
SHA-256 | e6d136f83c61862e30d3b807e3cb9fe2bf4c55d0ee24c892a5afc033585067af
Gentoo Linux Security Advisory 201507-17
Posted Jul 10, 2015
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201507-17 - A vulnerability in SNMP could lead to Denial of Service condition. Versions less than 5.7.3_pre5-r1 are affected.

tags | advisory, denial of service
systems | linux, gentoo
advisories | CVE-2014-3565
SHA-256 | da1a650a530e7660f2ea01e920dd40a172c53f238e9bfd938a922c6384fe8ee8
Gentoo Linux Security Advisory 201507-16
Posted Jul 10, 2015
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201507-16 - A vulnerability in Portage's urlopen function could allow a remote attacker to conduct a man-in-the-middle attack. Versions less than 2.1.12.2 are affected.

tags | advisory, remote
systems | linux, gentoo
advisories | CVE-2013-2100
SHA-256 | ffde84fd8885d942bee352410952274e352dc9000f2dd14faa0ddc1a239ce71a
ADB Backup APK Injection
Posted Jul 10, 2015
Authored by Imre Rad

The Android ABD utility backup manager, which invokes the custom BackupAgent, does not filter the data stream returned by the applications. While a BackupAgent is being executed during the backup process, it is able to inject additional applications (APKs) into the backup archive without the user's consent. The BackupAgent needs no Android permissions. Upon restoration of the backup archive, the system installs the injected, additional application (since it is part of the backup archive and the system believes it is authentic) with escalated privileges. Proof of concept code included.

tags | exploit, proof of concept
systems | linux
advisories | CVE-2014-7952
SHA-256 | d376ef512eaaa814a39535b0eb8c3bd952e0156ea5d7dc7981001d630f3697b5
EMC RecoverPoint For Virtual Machines Restriction Bypass
Posted Jul 10, 2015
Site emc.com

EMC RecoverPoint for VMs 4.3 contains fixes for a restriction bypass vulnerability that could potentially be exploited by malicious users to compromise the affected system.

tags | advisory, bypass
advisories | CVE-2015-4526
SHA-256 | b791da096acfb920bf6e25f91e7a691a93a2573bb230ba63e8fc5e12bce911f3
Arab Portal 3 SQL Injection
Posted Jul 10, 2015
Authored by ali ahmady

Arab Portal version 3 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | ef75d0dfb6f860bfb269b4aff5abc5565e76f6afd91f5ab2e7a00aa9c155bdbc
UPNPD M-SEARCH ssdp:discover Reflection Denial Of Service
Posted Jul 10, 2015
Authored by Todor Donev

UPNPD M-Search ssdp:discover reflection denial of service exploit.

tags | exploit, denial of service
SHA-256 | f367c58f0ffd545e2d90772fec10aeb953a0bcdc97164f66bdb1c8a16e3d98a9
Page 1 of 1
Back1Next

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    0 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close