Ubuntu Security Notice 2899-1 – It was discovered that LibreOffice incorrectly handled LWP document files. If a user were tricked into opening a specially crafted LWP document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code.
Monthly Archives: February 2016
Debian Security Advisory 3480-1
Debian Linux Security Advisory 3480-1 – Several vulnerabilities have been fixed in the GNU C Library, eglibc.
Red Hat Security Advisory 2016-0175-01
Red Hat Security Advisory 2016-0175-01 – The glibc packages provide the standard C libraries, POSIX thread libraries, standard math libraries, and the Name Server Caching Daemon used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. A stack-based buffer overflow was found in the way the libresolv library performed dual A/AAAA DNS queries. A remote attacker could create a specially crafted DNS response which could cause libresolv to crash or, potentially, execute code with the permissions of the user running the library. Note: this issue is only exposed when libresolv is called from the nss_dns NSS service module.
Red Hat Security Advisory 2016-0176-01
Red Hat Security Advisory 2016-0176-01 – The glibc packages provide the standard C libraries, POSIX thread libraries, standard math libraries, and the name service cache daemon used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. A stack-based buffer overflow was found in the way the libresolv library performed dual A/AAAA DNS queries. A remote attacker could create a specially crafted DNS response which could cause libresolv to crash or, potentially, execute code with the permissions of the user running the library. Note: this issue is only exposed when libresolv is called from the nss_dns NSS service module.
Red Hat Security Advisory 2016-0225-01
Red Hat Security Advisory 2016-0225-01 – The glibc packages provide the standard C libraries, POSIX thread libraries, standard math libraries, and the Name Server Caching Daemon used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. A stack-based buffer overflow was found in the way the libresolv library performed dual A/AAAA DNS queries. A remote attacker could create a specially crafted DNS response which could cause libresolv to crash or, potentially, execute code with the permissions of the user running the library. Note: this issue is only exposed when libresolv is called from the nss_dns NSS service module.
Redaxo CMS 5.0.0 Cross Site Scripting / SQL Injection
Redaxo CMS version 5.0.0 suffers from cross site scripting and remote SQL injection vulnerabilities.
TOTVS RM PORTAL Cross Site Scripting
TOTVS RM PORTAL suffers from multiple cross site scripting vulnerabilities. The vendor has not responded to reports.
phpMyBackupPro 2.5 CSRF / Remote Command Execution
phpMyBackupPro version 2.5 suffers from remote command execution and cross site request forgery vulnerabilities.
phpMyBackupPro 2.5 Shell Upload
phpMyBackupPro version 2.5 suffers from a remote shell upload vulnerability.
phpMyBackupPro 2.5 Cross Site Scripting
phpMyBackupPro version 2.5 suffers from multiple cross site scripting vulnerabilities.