Posted by David Coomber on Sep 07
Avira Mobile Security iOS Application – Cleartext Credentials Vulnerability
Posted by David Coomber on Sep 07
Avira Mobile Security iOS Application – Cleartext Credentials Vulnerability
Posted by David Coomber on Sep 07
Webroot SecureAnywhere Mobile Protection – MITM SSL Certificate Vulnerability
Posted by Elliott Lewis on Sep 07
NETGEAR Wireless Management System – Authentication Bypass and Privilege
Escalation.
WMS5316 ProSafe 16AP Wireless Management System – Firmware 2.1.4.15 (Build
1236).
[-] Vulnerability Information:
==============================
Title: NETGEAR Wireless Management System – Authentication Bypass and
Privilege Escalation
CVE: Not assigned
Vendor: NETGEAR
Product: WMS5316 ProSafe 16AP Wireless Management System
Affected Version: Firmware 2.1.4.15…
Red Hat Enterprise Linux: Updated qemu-kvm-rhev packages that fix one security issue and one bug are
now available for Red Hat Enterprise Virtualization.
Red Hat Product Security has rated this update as having Moderate security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-5165
Red Hat Enterprise Linux: Updated git19 packages that fix one bug are now available for Red Hat Software
Collections.
This Metasploit module exploits an OS command injection vulnerability in a web-accessible CGI script used to change passwords for locally-defined proxy user accounts. Valid credentials for such an account are required. Command execution will be in the context of the “nobody” account, but this account had broad sudo permissions, including to run the script /usr/local/bin/chrootpasswd (which changes the password for the Linux root account on the system to the value specified by console input once it is executed). The password for the proxy user account specified will *not* be changed by the use of this module, as long as the target system is vulnerable to the exploit. Very early versions of Endian Firewall (e.g. 1.1 RC5) require HTTP basic auth credentials as well to exploit this vulnerability. Use the USERNAME and PASSWORD advanced options to specify these values if required. Versions >= 3.0.0 still contain the vulnerable code, but it appears to never be executed due to a bug in the vulnerable CGI script which also prevents normal use (http://jira.endian.com/browse/UTM-1002). Versions 2.3.x and 2.4.0 are not vulnerable because of a similar bug (http://bugs.endian.com/print_bug_page.php?bug_id=3083). Tested successfully against the following versions of EFW Community: 1.1 RC5, 2.0, 2.1, 2.2, 2.5.1, 2.5.2. Should function against any version from 1.1 RC5 to 2.2.x, as well as 2.4.1 and 2.5.x.
Be on the lookout for copycat social media accounts which may be attempting to lead your customers astray.
The post Customers of UK’s Metro Bank targeted by Twitter fraudsters appeared first on We Live Security.
![]()
FireEye appliances suffer from an arbitrary file disclosure vulnerability.
NETGEAR WMS5316 ProSafe 16AP Wireless Management System suffers from authentication bypass and privilege escalation vulnerabilities.
Debian Linux Security Advisory 3353-1 – Qinghao Tang of QIHU 360 discovered a double free flaw in OpenSLP, an implementation of the IETF Service Location Protocol. This could allow remote attackers to cause a denial of service (crash).