Debian Linux Security Advisory 3493-1 – Gustavo Grieco discovered that xerces-c, a validating XML parser library for C++, mishandles certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. These flaws could lead to a denial of service in applications using the xerces-c library, or potentially, to the execution of arbitrary code.
Monthly Archives: February 2016
Red Hat Security Advisory 2016-0297-01
Red Hat Security Advisory 2016-0297-01 – In accordance with the Red Hat CloudForms Support Life Cycle Policy, support will end on February 28, 2017. Red Hat will not provide extended support for this product. Customers are requested to migrate to the newer Red Hat CloudForms product prior to the end of the life cycle for CloudForms 3.0.
Debian Security Advisory 3492-1
Debian Linux Security Advisory 3492-1 – Daniel Gultsch discovered in Gajim, an XMPP/jabber client. Gajim didn’t verify the origin of roster update, allowing an attacker to spoof them and potentially allowing her to intercept messages.
Pentagon To DoD: Give Us $580bn For Cyberwar And Spacewar
Net Neutrality Still Faces Attacks In Court And Congress
Baidu Apps Found To Be Leaking Personal Data
Two German Hospitals Hit With Ransomware
Zimbra 8.0.9 GA Cross Site Request Forgery
Zimbra versions 8.0.9 GA and below suffer from a cross site request forgery vulnerability.
Angler Exploit Kit Learns New Tricks, Finds Home On Popular Website
Angler Exploit evaded detection through new technique that bypasses Firefox and Chrome security protection.
Htcap Analysis Tool Beta 1.0
Htcap is a web application analysis tool for detecting communications between javascript and the server. It crawls the target application and maps ajax calls, dynamically inserted scripts, websockets calls, dynamically loaded resources and some interesting elements. The generated report is meant to be a good starting point for a manual web application security audit. Htcap is written in python and uses phantomjs to load pages injecting a probe that analyzes javascript behaviour. Once injected, the probe, overrides native javascript methods in order to intercept communications and DOM changes. It also simulates user interaction by firing all attached events and by filling html inputs.