Untrusted search path vulnerability in GNS3 before 1.2.3 allows local users to gain privileges via a Trojan horse uuid.dll in an unspecified directory.
Monthly Archives: May 2015
CVE-2015-2704
realmd allows remote attackers to inject arbitrary configurations in to sssd.conf and smb.conf via a newline character in an LDAP response.
CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
CVE-2015-3455
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, does not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.
CVE-2015-3627
Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.
CVE-2015-3629
Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization (“mount namespace breakout”) and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.
CVE-2015-3630
Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.
CVE-2015-3631
Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.
CESA-2015:1012 Important CentOS 6 thunderbirdSecurity Update
CentOS Errata and Security Advisory 2015:1012 Important Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1012.html The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) i386: bbfcda22cd70fbc5dfef4f55ae0805ec17600184187cb6772b84d2ac4488062a thunderbird-31.7.0-1.el6.centos.i686.rpm x86_64: 345eafa65b4ec7f43cbecd3b574eddaf68ec5c6e8dd6f36c7e5d86f5718b20f9 thunderbird-31.7.0-1.el6.centos.x86_64.rpm Source: c00e1249fd68b76040de3d1d55e5defd32aef185e64be05469ddc6b765f2ee36 thunderbird-31.7.0-1.el6.centos.src.rpm
Love hurts: Online dating scams are Australia’s top financial fraud
Australians were tricked out of around AUS$82 million (US$66 million) during 2014, with online dating scams accounting for the biggest losses.
The post Love hurts: Online dating scams are Australia’s top financial fraud appeared first on We Live Security.
![]()