This version of Mojolicious fixes an assumption in CGI’s parameter handling that can result in parameter injection attacks.
Monthly Archives: October 2014
Fedora 20 Security Update: perl-Mojolicious-5.49-1.fc20
This version of Mojolicious fixes an assumption in CGI’s parameter handling that can result in parameter injection attacks.
Fedora 20 Security Update: devscripts-2.14.8-1.fc20
Resolved Bugs
1059947 – CVE-2014-1833 devscripts: directory traversal flaw in uupdate
1059948 – devscripts: directory traversal flaw in uupdate [fedora-20]<br
Update to version 2.14.8, see http://metadata.ftp-master.debian.org/changelogs//main/d/devscripts/devscripts_2.14.8_changelog for details. Fixes CVE-2014-1833.
Samsung.com Open Redirect
Samsung.com suffers from an open redirect vulnerability.
Blackberry.com Open Redirect
Blackberry.com suffers from an open redirect vulnerability.
Fedora 20 Security Update: gnome-shell-3.10.4-9.fc20
Fedora 20 Security Update: facter-1.7.6-1.fc20
Resolved Bugs
1101346 – CVE-2014-3248 puppet: Ruby modules could be loaded from the current working directory
1114902 – CVE-2014-3248 facter: puppet: Ruby modules could be loaded from the current working directory [fedora-20]<br
Update to 1.7.6 for bz#1107891 and CVE-2014-3248
See http://puppetlabs.com/security/cve/cve-2014-3248 for more
information upstream.
Fedora 19 Security Update: facter-1.6.18-5.fc19
Resolved Bugs
1101346 – CVE-2014-3248 puppet: Ruby modules could be loaded from the current working directory
1107891 – CVE-2014-3248 facter: puppet: Ruby modules could be loaded from the current working directory [fedora-19]<br
Patch facter 1.6 series for Bug 1107891 – CVE-2014-3248
See http://puppetlabs.com/security/cve/cve-2014-3248 for more
information from upstream.
CSP Bypass on Android prior to 4.4
Posted by E Boogie on Oct 12
I’ve found a Content Security Policy bypass similar and related to the
same origin policy bypass in CVE-2014-6041.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6041
I’ve tested this on an Android 4.3 tablet running a bunch of different
browsers, including Inbrowser, Firefox, and the default Android
browser on an emulator for Android 4.3.1.
HTML PoC:
<input type=button value=”test” onclick=”…
CVE-2014-5327
Buffer overflow in the Webserver component on the Huawei E5332 router before 21.344.27.00.1080 allows remote authenticated users to cause a denial of service (reboot) via a long URI.