Debian Linux Security Advisory 3254-1 – Kostya Kortchinsky of the Google Security Team discovered a flaw in the DER parser used to decode SSL/TLS certificates in suricata. A remote attacker can take advantage of this flaw to cause suricata to crash.
Monthly Archives: May 2015
Debian Security Advisory 3255-1
Debian Linux Security Advisory 3255-1 – It was discovered that libzmq, a lightweight messaging kernel, is susceptible to a protocol downgrade attack on sockets using the ZMTP v3 protocol. This could allow remote attackers to bypass ZMTP v3 security mechanisms by sending ZMTP v2 or earlier headers.
Debian Security Advisory 3256-1
Debian Linux Security Advisory 3256-1 – Hanno Boeck discovered a heap-based buffer overflow flaw in the way Libtasn1, a library to manage ASN.1 structures, decoded certain DER-encoded input. A specially crafted DER-encoded input could cause an application using the Libtasn1 library to crash, or potentially to execute arbitrary code.
Red Hat Security Advisory 2015-0957-01
Red Hat Security Advisory 2015-0957-01 – Red Hat Satellite is a system management tool for Linux-based infrastructures. It allows for provisioning, monitoring, and remote management of multiple Linux deployments with a single, centralized tool. It was found that the RPC interface in Satellite would resolve external entities, allowing an attacker to conduct XML External Entity attacks. A remote attacker could use this flaw to read files accessible to the user running the Satellite server, and potentially perform other more advanced XXE attacks.
HP Security Bulletin HPSBGN03328 1
HP Security Bulletin HPSBGN03328 1 – A potential security vulnerability has been identified with Network Virtualization for HP LoadRunner and Performance Center. The vulnerability could be exploited remotely to allow disclosure of information. Revision 1 of this advisory.
Ubuntu Security Notice USN-2605-1
Ubuntu Security Notice 2605-1 – Pedro Ribeiro discovered that ICU incorrectly handled certain memory operations when processing data. If an application using ICU processed crafted data, an attacker could cause it to crash or potentially execute arbitrary code with the privileges of the user invoking the program.
Call for Papers: RAID 2015
Posted by Skander Iversen on May 11
Dear colleagues,
I would like to announce the following CFP.
Please kindly consider submitting to this conference.
This year’s RAID will take in marvelous Kyoto, Japan.
—————————————–
RAID 2015
Kyoto, Japan, November 2-4, 2015
http://www.raid2015.org/
Call for Papers
—————
The 18th International Symposium on Research in Attacks, Intrusions and
Defenses
(RAID 2015) aims at bringing together leading…
G-Homa WLan Power Plug Multiple Problems
Posted by honeypot on May 11
G-Homa WLan Power Plug Multiple Problems
i found multiple problems with the g-home ower plug.
1) Default User/Password in the Admin WebServer (admin/admin).
2) Communication with controlling server without authentication.
TCP-Binary without encryption.
3) App (Android adn IPhone) communicate with the controll server
via http.
4) Non configurable chinese ntp server contacted.
5) According to the documentation i found it would be possible…
Ed Felten Joins White House as Deputy CTO
Ed Felten, a professor at Princeton University and a well-respected voice on security and privacy issues, is joining the White House as the deputy CTO. In his new role, Felten will be working under Megan Smith, the CTO of the United States and a former Google vice president. Felten has been at Princeton in various […]
Fedora 22 Security Update: libssh-0.7.0-1.fc22
Resolved Bugs
1213775 – CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets
1218076 – CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets [fedora-all]<br
Update to version 0.7.0
Security fix for CVE-2015-3146