FreeBSD Security Advisory – An integer overflow in computing the size of IGMPv3 data buffer can result in a buffer which is too small for the requested operation. An attacker who can send specifically crafted IGMP packets could cause a denial of service situation by causing the kernel to crash.
Monthly Archives: February 2015
TangoBB 1.5.0-A3 Cross Site Scripting
TangoBB version 1.5.0-A3 suffers from a cross site scripting vulnerability.
Enano CMS 1.1.8pl1 Cross Site Scripting
Enano CMS version 1.1.8pl1 suffers from a cross site scripting vulnerability.
Ubuntu Security Notice USN-2512-1
Ubuntu Security Notice 2512-1 – A race condition was discovered in the Linux kernel’s key ring. A local user could cause a denial of service (memory corruption or panic) or possibly have unspecified impact via the keyctl commands. A memory leak was discovered in the ISO 9660 CDROM file system when parsing rock ridge ER records. A local user could exploit this flaw to obtain sensitive information from kernel memory via a crafted iso9660 image. Various other issues were also addressed.
Slackware Security Advisory – mozilla-thunderbird Updates
Slackware Security Advisory – New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues.
Slackware Security Advisory – mozilla-firefox Updates
Slackware Security Advisory – New mozilla-firefox packages are available for Slackware 14.1 and -current to fix security issues.
Ubuntu Security Notice USN-2520-1
Ubuntu Security Notice 2520-1 – Peter De Wachter discovered that CUPS incorrectly handled certain malformed compressed raster files. A remote attacker could use this issue to cause CUPS to crash, resulting in a denial of service, or possibly execute arbitrary code.
Ubuntu Security Notice USN-2519-1
Ubuntu Security Notice 2519-1 – Arnaud Le Blanc discovered that the GNU C Library incorrectly handled file descriptors when resolving DNS queries under high load. This may cause a denial of service in other applications, or an information leak. This issue only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. It was discovered that the GNU C Library incorrectly handled receiving a positive answer while processing the network name when performing DNS resolution. A remote attacker could use this issue to cause the GNU C Library to hang, resulting in a denial of service. Various other issues were also addressed.
HP Security Bulletin HPSBUX03162 SSRT101885 1
HP Security Bulletin HPSBUX03162 SSRT101885 1 – Potential security vulnerabilities have been identified with HP-UX running OpenSSL. These vulnerabilities could be exploited remotely to create a remote Denial of Service (DoS) and other vulnerabilities. Revision 1 of this advisory.
Gentoo Linux Security Advisory 201502-15
Gentoo Linux Security Advisory 201502-15 – Multiple vulnerabilities have been found in Samba, the worst of which allowing a context-dependent attacker to bypass intended file restrictions, cause a Denial of Service or execute arbitrary code. Versions less than 3.6.25 are affected.