Resolved Bugs
1210677 – CVE-2015-1860 CVE-2015-1859 CVE-2015-1858 qt: various flaws [fedora-all]
1210673 – CVE-2015-1858 qt: segmentation fault in qbmphandler.cpp
1210674 – CVE-2015-1859 qt: segmentation fault in qicohandler.cpp
1210675 – CVE-2015-1860 qt: segmentation fault in qgifhandler.cpp<br
Security fix for CVE-2015-1859, CVE-2015-1858, CVE-2015-1860
Monthly Archives: April 2015
Nodes Studio CMS XSS / Path Disclosure / SQL Injection
Nodes Studio CMS suffers from cross site scripting, path disclosure, and remote SQL injection vulnerabilities.
ProFTPd 1.3.5 File Copy
ProFTPd installations that use the mod_copy module’s SITE CPFR/SITE CPTO commands allows these commands to be used by unauthenticated clients.
WordPress WP-Mon Arbitrary File Download
WordPress WP-Mon plugin suffers from an arbitrary file disclosure vulnerability.
CVE-2015-0967
Multiple cross-site scripting (XSS) vulnerabilities in SearchBlox before 8.2 allow remote attackers to inject arbitrary web script or HTML via (1) the search field in plugin/index.html or (2) the title field in the Create Featured Result form in admin/main.jsp.
CVE-2015-0968
Unrestricted file upload vulnerability in admin/uploadImage.html in SearchBlox before 8.2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension and the image/jpeg content type, a different vulnerability than CVE-2013-3590.
CVE-2015-0969
SearchBlox before 8.2 allows remote attackers to obtain sensitive information via a pretty=true action to the _cluster/health URI.
CVE-2015-0970
Cross-site request forgery (CSRF) vulnerability in SearchBlox before 8.2 allows remote attackers to hijack the authentication of arbitrary users.
TGIF: Avast news wrap-up for April 3 – 17
The Avast bi-weekly wrap-up is a quick summary of what was on the Avast blog for the last two weeks.
Spring has sprung and it’s time to clean the dust and grime away after a long winter. In a departure from our regular security-oriented blog posts, we share 10 spring cleaning tips to combat grime. Don’t forget you can also clean your mobile devices! But you barely have to lift a finger because Avast GrimeFighter Safe Clean will remove the grime from your Android mobile devices with the touch of a button. If only window washing were so easy!
Independent testing lab AV-TEST gave their coveted certification to our popular mobile security application, Avast Mobile Security. If you are still on the fence regarding protecting your Android smartphone then read How to find the best protection for your Android phone? Independent tests.
Many smartphone owners are more worried about losing their device then they are about becoming infected with malware. That’s why we created Avast Anti-Theft. Make sure you have the latest version of our free app so if your phone gets lost, you can track it via your My Avast account or using SMS notifications from your friend’s phone. Turned Android auto-updates off? Manually update Anti-Theft to stay protected. explains how you can use Avast Anti -Theft to recover your lost Android device.
The mobile development team released a handy little app called Avast Battery Saver. This free app from Google Play helps you save some battery power. But not just any app can do it. The blog post Fear and loathing on Google Play: An in-depth look at today’s battery saving and cleaning apps gives us the scoop on apps that promise to save battery life with task cleaning.
How to extend the life of your phone’s battery is a question that we all have when the juice starts running out. The Avast Battery Saver app can help save about 20% but there are other ways to save battery life. We give you the tips and also share the future of smartphone batteries.
The unsecured Wi-Fi hotspot at the local cafe can be bad news if thieves capture your login credentials. Android users with Avast Mobile Security have a built-in feature called Wi-Fi Security that warns them if any issues are detected. We are now seeking iOS beta testers for an app called Avast SecureMe that will include the same type of feature for iPhone users. Check our blog Wi-Fi Security feature foolproofs your network connections both in public and at home and scroll down to the bottom for the beta test sign up link.
Cybercrooks use a variety of attack vectors to reach their victims. Targeted spearphishing attacks use email messages to trick people into providing sensitive information while malicious apps for Android disguise themselves as innocent games. The scary ransomware locks up all your files and demands ransom for the key to unlock it – on both PCs and and mobile devices! Avast keeps you aware of cybercrooks latest tricks in Don’t take the bait: Beware of web attack techniques.
CVE-2014-7954 MTP path traversal vulnerability in Android
Posted by Imre RAD on Apr 17
MTP path traversal vulnerability in Android 4.4
———————————————–
doSendObjectInfo() method of the MtpServer class implemented in
frameworks/av/media/mtp/MtpServer.cpp does not validate the name
parameter of the incoming MTP packet at all.
It is possible to upload files outside of the sdcard using a specially
crafted MTP request:
root () testpc:~/mtp-test# ./mtp-mysend sdf.txt …