A coordinated operation between international police and private technology companies shuts down the Simda botnet.
Monthly Archives: April 2015
Fedora 20 Security Update: icu-50.1.2-12.fc20
Resolved Bugs
1190131 – CVE-2014-7926 CVE-2014-9654 CVE-2014-7923 icu: various flaws [fedora-all]
1185202 – CVE-2014-7923 ICU: regexp engine missing look-behind expression range check
1185205 – CVE-2014-7926 ICU: regexp engine incorrect handling of a zero length quantifier
1190129 – CVE-2014-9654 icu: insufficient size limit checks in regular expression compiler<br
Security fix for CVE-2014-9654, CVE-2014-7923, CVE-2014-7926
Fedora 21 Security Update: icu-52.1-6.fc21
Resolved Bugs
1190131 – CVE-2014-7926 CVE-2014-9654 CVE-2014-7923 icu: various flaws [fedora-all]
1185202 – CVE-2014-7923 ICU: regexp engine missing look-behind expression range check
1185205 – CVE-2014-7926 ICU: regexp engine incorrect handling of a zero length quantifier
1190129 – CVE-2014-9654 icu: insufficient size limit checks in regular expression compiler<br
Security fix for CVE-2014-9654, CVE-2014-7923, CVE-2014-7926
CVE-2015-0675
The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(6), 9.2 before 9.2(3.3), and 9.3 before 9.3(3) does not properly validate failover communication messages, which allows remote attackers to reconfigure an ASA device, and consequently obtain administrative control, by sending crafted UDP packets over the local network to the failover interface, aka Bug ID CSCur21069.
CVE-2015-0676
The DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2 before 8.2(5.57), 8.3 before 8.3(2.44), 8.4 before 8.4(7.28), 8.5 before 8.5(1.24), 8.6 before 8.6(1.17), 8.7 before 8.7(1.16), 9.0 before 9.0(4.33), 9.1 before 9.1(6.1), 9.2 before 9.2(3.4), and 9.3 before 9.3(3) allows man-in-the-middle attackers to cause a denial of service (memory consumption or device outage) by triggering outbound DNS queries and then sending crafted responses to these queries, aka Bug ID CSCuq77655.
CVE-2015-0677
The XML parser in Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.28), 8.6 before 8.6(1.17), 9.0 before 9.0(4.33), 9.1 before 9.1(6), 9.2 before 9.2(3.4), and 9.3 before 9.3(3), when Clientless SSL VPN, AnyConnect SSL VPN, or AnyConnect IKEv2 VPN is used, allows remote attackers to cause a denial of service (VPN outage or device reload) via a crafted XML document, aka Bug ID CSCus95290.
Vuln: CrystalPlayer Playlist File Buffer Overflow Vulnerability
CrystalPlayer Playlist File Buffer Overflow Vulnerability
Vuln: Clever Internet ActiveX Suite CLINetSuiteX6.OCX Arbitrary File Download Or Overwrite Vulnerability
Clever Internet ActiveX Suite CLINetSuiteX6.OCX Arbitrary File Download Or Overwrite Vulnerability
Vuln: gnome-shell '_gdk_x11_display_error_event()' Function Local Security Bypass Vulnerability
gnome-shell ‘_gdk_x11_display_error_event()’ Function Local Security Bypass Vulnerability
Vuln: IBM Java CVE-2013-4002 Denial of Service Vulnerability
IBM Java CVE-2013-4002 Denial of Service Vulnerability