ManageEngine Desktop Central 9 suffers from a cross site request forgery vulnerability.
Monthly Archives: February 2015
HP Security Bulletin HPSBMU03232 3
HP Security Bulletin HPSBMU03232 3 – A potential security vulnerability has been identified with HP SiteScope. The vulnerability could be exploited remotely to allow elevation of privilege. Revision 3 of this advisory.
Debian Security Advisory 3151-1
Debian Linux Security Advisory 3151-1 – Several vulnerabilities were discovered in Django, a high-level Python web development framework.
Debian Security Advisory 3152-1
Debian Linux Security Advisory 3152-1 – A flaw was found in the test_compr_eb() function allowing out-of-bounds read and write access to memory locations. By carefully crafting a corrupt ZIP archive an attacker can trigger a heap overflow, resulting in application crash or possibly having other unspecified impact.
HP Security Bulletin HPSBGN03247 1
HP Security Bulletin HPSBGN03247 1 – A potential security vulnerability has been identified with HP IceWall SSO Dfw using glibc. This vulnerability could be used to remotely execute arbitrary code. Revision 1 of this advisory.
HP Security Bulletin HPSBGN03237 1
HP Security Bulletin HPSBGN03237 1 – A potential security vulnerability has been identified with HP Insight Remote Support v7 Clients running SSLv3 which may affect WBEM, WS-MAN and WMI connections from monitored devices to an HP Insight Remote Support Hosting Device, such as an HP Insight Remote Support Central Management Server (CMS). This is the SSLv3 vulnerability known as “Padding Oracle on Downgraded Legacy Encryption” also known as “Poodle”, which could be exploited remotely to allow disclosure of information. HP Insight Remote Support 7.2 allows the Hosting Device administrator to disable SSLv3 ciphers. Some monitored devices may require an update to support TLS encryption, while others may not support TLS encryption at all. Disabling SSLv3 on the hosting device can result in loss of communication with such monitored devices. HP has provided the ability to address POODLE in the Insight Remote Support 7.2 release, but disabling SSLv3 requires the Hosting Device administrator to take specific actions to address this vulnerability. Revision 1 of this advisory.