CVE-2014-9510 – TP-Link TL-WR840N Configuration Import Cross-Site Request Forgery (CSRF)

Posted by Sean Wright on Jan 07

Classification: //Dell SecureWorks/Confidential – Limited External
Distribution:

############################################################################
# * Title: TP-Link TL-WR840N Configuration Import Cross-Site Request Forgery
(CSRF)
# * Advisory ID: SWRX-2015-001
# * Advisory URL:
http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2015-00
1/
# * Date published: Wednesday, January 7, 2015
# * CVE: CVE-2014-9510
# * CVSS…

Ubuntu Security Notice USN-2453-1

Ubuntu Security Notice 2453-1 – Timothy D. Morgan discovered that the run-mailcap tool incorrectly filtered certain shell metacharacters in filenames. If a user or automated system were tricked into opening a file with a specially-crafted filename, a remote attacker could possibly execute arbitrary code.

Ubuntu Security Notice USN-2454-1

Ubuntu Security Notice 2454-1 – It was discovered that Exiv2 incorrectly handled certain tag values in video files. If a user or automated system were tricked into opening a specially-crafted video file, a remote attacker could cause Exiv2 to crash, resulting in a denial of service.

Ubuntu Security Notice USN-2455-1

Ubuntu Security Notice 2455-1 – It was discovered that bsd-mailx contained a feature that allowed syntactically valid email addresses to be treated as shell commands. A remote attacker could possibly use this issue with a valid email address to execute arbitrary commands. This functionality has now been disabled by default, and can be re-enabled with the “expandaddr” configuration option. This update alone does not remove all possibilities of command execution. In environments where scripts use mailx to process arbitrary email addresses, it is recommended to modify them to use a “–” separator before the address to properly handle those that begin with “-“. Various other issues were also addressed.