Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.
Monthly Archives: February 2015
CVE-2015-0831 (firefox, firefox_esr, thunderbird)
Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.
CVE-2015-0832 (firefox)
Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.
CVE-2015-0833 (firefox, firefox_esr, thunderbird)
Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 on Windows, when the Maintenance Service is not used, allow local users to gain privileges via a Trojan horse DLL in (1) the current working directory or (2) a temporary directory, as demonstrated by bcrypt.dll.
CVE-2015-0834 (firefox)
The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.
CVE-2015-0835 (firefox)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
CVE-2015-0836 (firefox, firefox_esr, thunderbird)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Anthem hack puts at least 8.8 million NON-customers at risk
Even if you’re not a customer of health insurer Anthem, your data could have been put at risk. Be on your guard.
The post Anthem hack puts at least 8.8 million NON-customers at risk appeared first on We Live Security.
Fedora 21 Security Update: bind-9.9.6-8.P1.fc21
Resolved Bugs
1193820 – CVE-2015-1349 bind: issue in trust anchor management can cause named to crash<br
CVE-2015-1349
Fedora 20 Security Update: bind-9.9.4-18.P2.fc20
Resolved Bugs
1193820 – CVE-2015-1349 bind: issue in trust anchor management can cause named to crash<br
CVE-2015-1349