Debian Linux Security Advisory 3046-1 – It was reported that MediaWiki, a website engine for collaborative work, allowed to load user-created CSS on pages where user-created JavaScript is not allowed. A wiki user could be tricked into performing actions by manipulating the interface from CSS, or JavaScript code being executed from CSS, on security-wise sensitive pages like Special:Preferences and Special:UserLogin. This update removes the separation of CSS and JavaScript module allowance.
Monthly Archives: October 2014
Gentoo Linux Security Advisory 201410-01
Gentoo Linux Security Advisory 201410-1 – Multiple parsing flaws in Bash could allow remote attackers to inject code or cause a Denial of Service condition. Versions less than 4.2_p52 are affected.
Debian Security Advisory 3042-1
Debian Linux Security Advisory 3042-1 – Stefano Zacchiroli discovered a vulnerability in exuberant-ctags, a tool files cause ctags to enter an infinite loop until it runs out of disk space, resulting in denial of service.
Debian Security Advisory 3044-1
Debian Linux Security Advisory 3044-1 – Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution on x86 hardware.
Debian Security Advisory 3045-1
Debian Linux Security Advisory 3045-1 – Several vulnerabilities were discovered in qemu, a fast processor emulator.
WatchGuard Warns IT Pros: If You're Still Applying 'One Security Policy to All,' You're Not Getting the Benefit Out of Your Network Segmentation Work
‘Unpatchable’ USB exploit posted to GitHub
Techspot reports that a another USB exploit has been discovered by a pair of researchers who have “thrown caution to the wind by posting code for a similar attack on GitHub.”
The post ‘Unpatchable’ USB exploit posted to GitHub appeared first on We Live Security.
![]()
Bing: no plans to offer search boost for encrypted websites
Over the summer, Google introduced plans to start giving preference to websites that use HTTPS encryption to try and incentivize good online security practices. PC World reports that Microsoft’s search rival, Bing, has no plans to follow suit with its own search algorithm.
The post Bing: no plans to offer search boost for encrypted websites appeared first on We Live Security.
![]()





