Mandriva Linux Security Advisory 2015-021 – When libcurl sends a request to a server via a HTTP proxy, it copies the entire URL into the request and sends if off. If the given URL contains line feeds and carriage returns those will be sent along to the proxy too, which allows the program to for example send a separate HTTP request injected embedded in the URL.
Monthly Archives: January 2015
Debian Security Advisory 3125-1
Debian Linux Security Advisory 3125-1 – Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit.
Debian Security Advisory 3124-1
Debian Linux Security Advisory 3124-1 – Thorsten Eckel of Znuny GMBH and Remo Staeuble of InfoGuard discovered a privilege escalation vulnerability in otrs2, the Open Ticket Request System. An attacker with valid OTRS credentials could access and manipulate ticket data of other users via the GenericInterface, if a ticket webservice is configured and not additionally secured.
Anonymous hackers ‘declare war’ on al Qaeda and Islamic State
The Anonymous hacking collective has “declared war” against the terrorists said to be responsible for the shootings of staff at France’s satyrical Charlie Hebdo magazine, reports The Telegraph.
The post Anonymous hackers ‘declare war’ on al Qaeda and Islamic State appeared first on We Live Security.
HP Security Bulletin HPSBOV03227
HP Security Bulletin HPSBOV03227 – Potential security vulnerabilities have been identified with HP SSL for OpenVMS. These vulnerabilities could be remotely exploited to create a remote disclosure of information, Denial of Service, and other vulnerabilities. Revision 1 of this advisory.
Maligno 1.5
Maligno is an open source penetration testing tool written in python, that serves Metasploit payloads. It generates shellcode with msfvenom and transmits it over HTTP or HTTPS. The shellcode is encrypted with AES and encoded with Base64 prior to transmission.
‘Critical Security Updates’ cancelled for 939 million Android users
Google has revealed that Android smartphones and tablets running versions of the software released before 4.3 (Jellybean) will no longer be given official updates to an important part of the software
The post ‘Critical Security Updates’ cancelled for 939 million Android users appeared first on We Live Security.