Red Hat Security Advisory 2015-0074-01 – JasPer is an implementation of Part 1 of the JPEG 2000 image compression standard. An off-by-one flaw, leading to a heap-based buffer overflow, was found in the way JasPer decoded JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code. An unrestricted stack memory use flaw was found in the way JasPer decoded JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code.
Monthly Archives: January 2015
Red Hat Security Advisory 2015-0079-01
Red Hat Security Advisory 2015-0079-01 – Oracle Java SE version 7 includes the Oracle Java Runtime Environment and the Oracle Java Software Development Kit. This update fixes several vulnerabilities in the Oracle Java Runtime Environment and the Oracle Java Software Development Kit.
Ubuntu Security Notice USN-2482-1
Ubuntu Security Notice 2482-1 – Alexander Cherepanov discovered that libelf1 incorrectly handled certain filesystem paths while extracting ar archives. An attacker could use this flaw to perform a directory traversal attack on the root directory if the process extracting the ar archive has write access to the root directory.
Red Hat Security Advisory 2015-0080-01
Red Hat Security Advisory 2015-0080-01 – Oracle Java SE version 8 includes the Oracle Java Runtime Environment and the Oracle Java Software Development Kit. This update fixes several vulnerabilities in the Oracle Java Runtime Environment and the Oracle Java Software Development Kit.
Program-O 2.4.6 XSS / LFI / HTTP Response Splitting
Program-O version 2.4.6 suffers from http response splitting, cross site scripting, and local file inclusion vulnerabilities.
USAA Mobile App Information Disclosure
The USAA Mobile app for Android versions prior to 7.10.1 suffer from an information disclosure vulnerability.
articleFR CMS 3.0.5 Cross Site Scripting
articleFR CMS version 3.0.5 suffers from a cross site scripting vulnerability.
Alibaba Cross Site Scripting / Open Redirect
Various Alibaba sites suffer from cross site scripting and open redirect vulnerabilities.
ecommerceMajor SQL Injection
ecommerceMajor suffers from remote SQL injection vulnerabilities.
Adobe Releases Security Updates for Flash Player
Original release date: January 22, 2015
Adobe has released security updates to address a vulnerability in Flash Player, which could potentially allow a remote attacker to take control of an affected system.
Users and administrators are encouraged to review Adobe Security Bulletin APSB15-02 and apply the necessary updates.
This product is provided subject to this Notification and this Privacy & Use policy.