Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted length field in a packet.
Monthly Archives: March 2015
CVE-2015-2192
Integer overflow in the dissect_osd2_cdb_continuation function in epan/dissectors/packet-scsi-osd.c in the SCSI OSD dissector in Wireshark 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted length field in a packet.
GLSA 201503-03: PHP: Multiple vulnerabilities
GLSA 201503-04: GNU C Library: Multiple vulnerabilities
GLSA 201503-05: FreeType: Multiple vulnerabilities
Vuln: OpenSSL CVE-2014-3572 Security Bypass Vulnerability
OpenSSL CVE-2014-3572 Security Bypass Vulnerability
Vuln: Linux Kernel 'fs/isofs/rock.c' Local Information Disclosure Vulnerability
Linux Kernel ‘fs/isofs/rock.c’ Local Information Disclosure Vulnerability
Re: Java 8u40 released: why?
Posted by Nick FitzGerald on Mar 07
James Hodgkinson wrote:
Indeed!
So you did not notice the explanation that this would happen, right
there on the “continue the install” permission dialog?
The one we can see a screenshot of at, say:
https://grahamcluley.com/2015/03/oracle-java-mac/
Your description rather strongly implies that you have no choice in
getting the Ask toolbar, which is untrue.
I understand that Mac users will likely not be _accustomed_ to such…
Re: Partial pointer leaks
Posted by Christophe Hauser on Mar 07
Hi Robert,
thank you, this is very interesting and seems to be one potential
occurrence of what I am looking for.
Nice tool by the way !
Re: Java 8u40 released: why?
Posted by Alan Coopersmith on Mar 07
There are Java updates associated with security fixes on the quarterly
CPU cycle, but those aren’t the only Java updates – it is software under
active development after all, and releases new features too, not just
security patches.
http://www.oracle.com/technetwork/java/javase/overview/jdk-version-number-scheme-1918258.html
https://www.java.com/en/download/faq/release_dates.xml
http://openjdk.java.net/projects/jdk8u/