DSA-3298 jackrabbit – security update

It was discovered that the Jackrabbit WebDAV bundle was susceptible to a
XXE/XEE attack. When processing a WebDAV request body containing XML,
the XML parser could be instructed to read content from network
resources accessible to the host, identified by URI schemes such as
http(s) or file. Depending on the WebDAV request, this could not
only be used to trigger internal network requests, but might also be
used to insert said content into the request, potentially exposing it to
the attacker and others.

DAVOSET v.1.2.5

Posted by MustLive on Jun 30

Hello participants of Mailing List.

After making public release of DAVOSET
(http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2013-June/008850.html),
I’ve made next update of the software. DAVOSET v.1.2.5 was released – DDoS
attacks via other sites execution tool (http://websecurity.com.ua/davoset/).

Video demonstration of DAVOSET: http://www.youtube.com/watch?v=RKi35-f346I

GitHub: https://github.com/MustLive/DAVOSET

OPM Identity-Protection Phishing Campaigns

Original release date: June 30, 2015

US-CERT is aware of phishing campaigns masquerading as emails from the Office of Personnel Management (OPM) or the identity protection firm CSID. For those affected by the recent data breach, the legitimate domain used for accessing identity protection services is https://opm.csid.com.

US-CERT recommends that users visit the OPM website for more information. Users are also encouraged to report suspicious email to US-CERT.


This product is provided subject to this Notification and this Privacy & Use policy.

Fedora 22 Security Update: libssh-0.7.1-1.fc22

Resolved Bugs
1223964 – libssh 0.7.0 regression breaks cockpit and cockpit test suite
1221310 – undefined symbol: ssh_forward_listen
1218076 – CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets [fedora-all]
1213775 – CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets<br
Update to version 0.7.1
Add patch to fix undefined symbol: ssh_forward_listen (bug #1221310)
Update to version 0.7.0
Security fix for CVE-2015-3146