The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destination attribute in a Response element in a SAML assertion matches the location from which the message was received, which allows remote attackers to have unspecified impact via unknown vectors. NOTE: this identifier was SPLIT from CVE-2015-0277 per ADT2 due to different vulnerability types.
Monthly Archives: August 2015
Risky Schneider Electric SCADA Vulnerabilities Remain Unpatched
Vulnerabilities in Schneider Electric SCADA gear remain unpatched close to two weeks after they were disclosed during DEF CON.
Bugtraq: [ERPSCAN-15-012] SAP Afaria 7 XComms â?? Buffer Overflow
[ERPSCAN-15-012] SAP Afaria 7 XComms â?? Buffer Overflow
Bugtraq: [ERPSCAN-15-013] SAP NetWeaver AS Java CIM UPLOAD â?? XXE
[ERPSCAN-15-013] SAP NetWeaver AS Java CIM UPLOAD â?? XXE
Bugtraq: Insufficient certificate validation in EMC Secure Remote Services Virtual Edition
Insufficient certificate validation in EMC Secure Remote Services Virtual Edition
Bugtraq: Weak authentication in EMC Secure Remote Services Virtual Edition Web Portal
Weak authentication in EMC Secure Remote Services Virtual Edition Web Portal
Using BitTorrent Vulnerabilities to Launch Distributed Reflective DoS Attacks
Researchers warn several BitTorrent protocols can be leveraged to carry out distributed reflective denial of service (DRoS) attacks.
CESA-2015:1635 Moderate CentOS 7 sqlite SecurityUpdate
CentOS Errata and Security Advisory 2015:1635 Moderate Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1635.html The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 172f48aba58c71b0a3c41bd8c0a459ec91a8b01f619cf118c4e64549b7e6776b lemon-3.7.17-6.el7_1.1.x86_64.rpm d7dd647b74a2c66f1d783c49dbd15e87afab7ea6e99d44650e2eac25fb54582a sqlite-3.7.17-6.el7_1.1.i686.rpm 6265a0f89a60789ae98b96dab9326dfa637181bb19792c23d87dcc3551a455b4 sqlite-3.7.17-6.el7_1.1.x86_64.rpm a9b2e28016678005089686ae541c45e02dd478be922eb55fb2ee252e93ca9d52 sqlite-devel-3.7.17-6.el7_1.1.i686.rpm 8f5549812a7db3779d07234213afc80d40bfdd2b6df2fef48a6d6b73e477aaec sqlite-devel-3.7.17-6.el7_1.1.x86_64.rpm 8ab5d99ff1519abf6a32871c9cc806fd87b5ce4aa0dede1d4470bb5cd141b1f6 sqlite-doc-3.7.17-6.el7_1.1.noarch.rpm 87b97d5f0a28917419972fda17f6dec2f6cce100f5ef230d515d0aab8aa8c19e sqlite-tcl-3.7.17-6.el7_1.1.x86_64.rpm Source: 510a7da912831e9994fb1c6bc6aa850f428cc461bde8ecc16e1bd2d790f575bf sqlite-3.7.17-6.el7_1.1.src.rpm
CESA-2015:1636 Moderate CentOS 7 net-snmpSecurity Update
CentOS Errata and Security Advisory 2015:1636 Moderate Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1636.html The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 5684807da810a67791c508e2c91772034135a5fab60d9af714b3023ea81eeffe net-snmp-5.7.2-20.el7_1.1.x86_64.rpm 19e91a03c5ff4184e1bce196c1d39fb7a9ca53991df1cb068d37fc1b4589d654 net-snmp-agent-libs-5.7.2-20.el7_1.1.i686.rpm 639e7376cff59e704c6761ecd8e1913e11ead459b458cebd3fc55f7caa89410b net-snmp-agent-libs-5.7.2-20.el7_1.1.x86_64.rpm 259906dd53d82fcd7c3bec4eb6a5704a4d1eae20afbe201b7e16828b65e28b96 net-snmp-devel-5.7.2-20.el7_1.1.i686.rpm 8918b6cb06d2092040cc497571b9ee520bdaf5dbc717ab8c52fed18f6cd1d45c net-snmp-devel-5.7.2-20.el7_1.1.x86_64.rpm f305b33384efcbda7b214b5bec517fa1dde60d3452f8a3322c173d7aa438fc0b net-snmp-gui-5.7.2-20.el7_1.1.x86_64.rpm a5067c828035ff4697995e2226a450434c49a99d4eb2c199a5b1d2e43416f6ff net-snmp-libs-5.7.2-20.el7_1.1.i686.rpm d07ad6d3c4e2a4b35ef897051ba7ce63c48dcbfe6daef896f78e8589e81f5ca6 net-snmp-libs-5.7.2-20.el7_1.1.x86_64.rpm 5644fb28c2006c89058864c9cf4dbd706ca7d6d36b6db5870047471939b82b37 net-snmp-perl-5.7.2-20.el7_1.1.x86_64.rpm 66730e834b4a44e5aae61ad28c0b944481f937b8baf6cd7cd113815339017bcf net-snmp-python-5.7.2-20.el7_1.1.x86_64.rpm 42c11fe5067cb712a3d531a7fbc35f64fc792be40e34dd097bf476e8f96b673d net-snmp-sysvinit-5.7.2-20.el7_1.1.x86_64.rpm 681d8ab7b5e274d554665648c921a8594775af0c04ee93b9c273fc882d1e9255 net-snmp-utils-5.7.2-20.el7_1.1.x86_64.rpm Source: c5ac5b9f29069245cd05a42004137e4741feab3bf9b8b784e2da0df786bdb9b7 net-snmp-5.7.2-20.el7_1.1.src.rpm
CESA-2015:1627 Moderate CentOS 5 glibc SecurityUpdate
CentOS Errata and Security Advisory 2015:1627 Moderate Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1627.html The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) i386: 18290a10228b5f60f1c0ddb097d3b00ad72347bd88b936faaa7bdef1e22421ba glibc-2.5-123.el5_11.3.i386.rpm ebba6ec48aa2f6cf9c770bbe86e33e9f35aadb2f12b7a4d5afb5d6617d53ab30 glibc-2.5-123.el5_11.3.i686.rpm 77759982e4459c691af65449b5355126ce47af0152bbdf075d51af0ae6cc023b glibc-common-2.5-123.el5_11.3.i386.rpm a1050a5ce1470b821eb0e638dbabea53bd66c81c1d3ded7a91962904453a3da0 glibc-devel-2.5-123.el5_11.3.i386.rpm 25fcd032d6996e521b7b94b1802092cce06ce9fb8c7fe67ec043938802377be5 glibc-headers-2.5-123.el5_11.3.i386.rpm 6ccb9a38c8450f7173e93aecab6a99de4fd40bf153ef5863d0f6a2b8152c08a5 glibc-utils-2.5-123.el5_11.3.i386.rpm 3dfeed4123deed66234c78481d27d7c89b57476629c0f8dce5662fe7ecca1afa nscd-2.5-123.el5_11.3.i386.rpm x86_64: ebba6ec48aa2f6cf9c770bbe86e33e9f35aadb2f12b7a4d5afb5d6617d53ab30 glibc-2.5-123.el5_11.3.i686.rpm 3f0a2eaf3e9380552f4e321fef19510af35cda3ed67e3e8492f3ed0887d0fca5 glibc-2.5-123.el5_11.3.x86_64.rpm 3d767f90a1f5b7ad6de52fd11c539b5067ec3cad12315ab8764f468c9e66bea0 glibc-common-2.5-123.el5_11.3.x86_64.rpm a1050a5ce1470b821eb0e638dbabea53bd66c81c1d3ded7a91962904453a3da0 glibc-devel-2.5-123.el5_11.3.i386.rpm b650ce43cfdd851a8a8570a38522363c67c87ec68dd1e3a9f93a0d732f6d8746 glibc-devel-2.5-123.el5_11.3.x86_64.rpm 72db66b5d6f76e217e11d59844917bc058739818106d3f54c0349f545a3d003b glibc-headers-2.5-123.el5_11.3.x86_64.rpm 9f0c7a5c51c6e665988299279bc54140ee8f6d2b78080fdcde11ad39a847af89 glibc-utils-2.5-123.el5_11.3.x86_64.rpm 44c53971f7828e28396a056a1bee641c7741621240a10d3510c7749141aa83d4 nscd-2.5-123.el5_11.3.x86_64.rpm Source: 4c85b7e2c35e9099ff3e52c1b9407e276961f7b6b5bd3a110ede7bc778cbddde glibc-2.5-123.el5_11.3.src.rpm