[slackware-security] libpng (SSA:2015-337-01)
Monthly Archives: December 2015
Bugtraq: [slackware-security] mozilla-thunderbird (SSA:2015-337-02)
[slackware-security] mozilla-thunderbird (SSA:2015-337-02)
Bugtraq: ESA-2015-171 EMC NetWorker Denial-of-service Vulnerability
ESA-2015-171 EMC NetWorker Denial-of-service Vulnerability
Aethra SV2242E XXE Injection
Aethra SV2242E suffers from an XML external entity injection vulnerability.
Red Hat Security Advisory 2015-2544-01
Red Hat Security Advisory 2015-2544-01 – OpenShift Enterprise by Red Hat is the company’s cloud computing Platform-as-a-Service solution designed for on-premise or private cloud deployments. It was found that OpenShift’s API back end did not verify requests for pod log locations, allowing a pod on a Node to request logs for any other pod on that Node. A remote attacker could use this flaw to view sensitive information via pod logs that they would normally not have access to. This issue was discovered by Jordan Liggitt of Red Hat Atomic OpenShift.
Red Hat Security Advisory 2015-2545-01
Red Hat Security Advisory 2015-2545-01 – Chromium is an open-source web browser, powered by WebKit. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information when visited by the victim.
WordPress Cool Video Gallery 1.9 Command Injection
WordPress Cool Video Gallery plugin version 1.9 suffers from a remote command injection vulnerability.
ASUS RT-N15U Code Execution / XSS / Open Redirect
ASUS RT-N15U suffers from code execution, cross site request forgery, cross site scripting, and open redirection vulnerabilities.
RHSA-2015:2545-1: Critical: chromium-browser security update
Red Hat Enterprise Linux: Updated chromium-browser packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 6 Supplementary.
Red Hat Product Security has rated this update as having Critical security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2015-6764, CVE-2015-6765, CVE-2015-6766, CVE-2015-6767, CVE-2015-6768, CVE-2015-6769, CVE-2015-6770, CVE-2015-6771, CVE-2015-6772, CVE-2015-6773, CVE-2015-6774, CVE-2015-6775, CVE-2015-6776, CVE-2015-6777, CVE-2015-6778, CVE-2015-6779, CVE-2015-6780, CVE-2015-6781, CVE-2015-6782, CVE-2015-6784, CVE-2015-6785, CVE-2015-6786, CVE-2015-6787
RHBA-2015:2543-1: dracut bug fix update
Red Hat Enterprise Linux: Updated dracut packages that fix one bug are now available for Red Hat
Enterprise Linux 7.