Monthly Archives: May 2015
Prank Texts Clobber iPhones
Ubuntu Security Notice USN-2617-3
Ubuntu Security Notice 2617-3 – USN-2617-1 fixed a vulnerability in NTFS-3G. The original patch did not completely address the issue. This update fixes the problem. Tavis Ormandy discovered that FUSE incorrectly filtered environment variables. A local attacker could use this issue to gain administrative privileges. Various other issues were also addressed.
Red Hat Security Advisory 2015-1031-01
Red Hat Security Advisory 2015-1031-01 – KVM is a full virtualization solution for Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the user-space component for running virtual machines using KVM. An out-of-bounds memory access flaw was found in the way QEMU’s virtual Floppy Disk Controller handled FIFO buffer access while processing certain FDC commands. A privileged guest user could use this flaw to crash the guest or, potentially, execute arbitrary code on the host with the privileges of the host’s QEMU process corresponding to the guest.
Red Hat Security Advisory 2015-1030-01
Red Hat Security Advisory 2015-1030-01 – The kernel packages contain the Linux kernel, the core of any Linux operating system. A use-after-free flaw was found in the way the Linux kernel’s SCTP implementation handled authentication key reference counting during INIT collisions. A remote attacker could use this flaw to crash the system or, potentially, escalate their privileges on the system. This issue was discovered by Sun Baoliang of Red Hat.
Ubuntu Security Notice USN-2617-3
Ubuntu Security Notice 2617-3 – USN-2617-1 fixed a vulnerability in NTFS-3G. The original patch did not completely address the issue. This update fixes the problem. Tavis Ormandy discovered that FUSE incorrectly filtered environment variables. A local attacker could use this issue to gain administrative privileges. Various other issues were also addressed.
APPLE-SA-2015-05-27-1 OS X: Flash Player plug-in blocked
From: Apple Product Security
Reply to list
APPLE-SA-2015-05-27-1 OS X: Flash Player plug-in blocked Due to security issues in older versions, Apple has updated the web plug-in blocking mechanism to disable all versions prior to Flash Player 17.0.0.188 and 13.0.0.289. Information on blocked web plug-ins will be posted to: http://support. [...]
Bugtraq: CVE-2015-4084 – WordPress Free Counter Plugin [Stored XSS]
CVE-2015-4084 – WordPress Free Counter Plugin [Stored XSS]
Bugtraq: Thycotic Password Manager Secret Server iOS Application – MITM SSL Certificate Vulnerability
Thycotic Password Manager Secret Server iOS Application – MITM SSL Certificate Vulnerability
Bugtraq: [Onapsis Security Advisory 2015-006] SAP HANA Information Disclosure via SQL IMPORT FROM statement
[Onapsis Security Advisory 2015-006] SAP HANA Information Disclosure via SQL IMPORT FROM statement