Red Hat Security Advisory 2016-0352-01

Red Hat Security Advisory 2016-0352-01 – OpenStack Image Service provides discovery, registration, and delivery services for disk and server images. The service provides the ability to copy or snapshot a server image, and immediately store it away. Stored images can be used as a template to get new servers up and running quickly and more consistently than installing a server operating system and individually configuring additional services. An authorization vulnerability in OpenStack Image service was discovered, which allowed image-status manipulation using locations. By removing the last location of an image, an authenticated user could change the status from ‘active’ to ‘queue’. A malicious tenant could exploit this flaw to silently replace owned image data, regardless of its original creator or visibility settings. Only environments with show_multiple_locations set to true were affected.

Red Hat Security Advisory 2016-0354-01

Red Hat Security Advisory 2016-0354-01 – OpenStack Image Service provides discovery, registration, and delivery services for disk and server images. The service provides the ability to copy or snapshot a server image, and immediately store it away. Stored images can be used as a template to get new servers up and running quickly and more consistently than installing a server operating system and individually configuring additional services. An authorization vulnerability in OpenStack Image service was discovered, which allowed image-status manipulation using locations. By removing the last location of an image, an authenticated user could change the status from ‘active’ to ‘queue’. A malicious tenant could exploit this flaw to silently replace owned image data, regardless of its original creator or visibility settings. Only environments with show_multiple_locations set to true were affected.

Debian Security Advisory 3502-1

Debian Linux Security Advisory 3502-1 – Ralf Schlatterbeck discovered an information leak in roundup, a web-based issue tracking system. An authenticated attacker could use it to see sensitive details about other users, including their hashed password.

Debian Security Advisory 3426-2

Debian Linux Security Advisory 3426-2 – The update for linux issued as DSA-3426-1 and DSA-3434-1 to address CVE-2015-8543 uncovered a bug in ctdb, a clustered database to store temporary data, leading to broken clusters. Updated packages are now available to address this problem.

[CFP] EuskalHack (San Sebastian / Donostia) 2016

Posted by Ryan Dewhurst on Mar 03

Hi,

I am submitting this CFP on behalf of EuskalHack. Tables are shown in
Markdown format.

Thanks,
Ryan

**Introduction**

EuskalHack Security Congress is the first Ethical Hacking association in
Euskadi, with the aim of promoting the community and culture in digital
security to anyone who may be interested.

This exclusive conference is shaping up to be the most relevant in the
Basque Country, with an estimated 125 attendees for the first…

Vulnerabilities in Mobile Safari

Posted by MustLive on Mar 03

Hello list!

There are multiple Denial of Service vulnerabilities in Mobile Safari. After
conversation with Apple about all vulnerabilities in their browser during
December – February, I present the second advisory.

In the middle of December I checked all exploits for different browsers,
which I published and non-published since 2006, in Mobile Safari for iOS
6.0.1 and 8.4.1. This is the second part of vulnerabilities.

————————-…

[REVIVE-SA-2016-001] Revive Adserver – Multiple vulnerabilities

Posted by Matteo Beccati on Mar 03

========================================================================
Revive Adserver Security Advisory REVIVE-SA-2016-001
========================================================================
http://www.revive-adserver.com/security/revive-sa-2016-001
========================================================================
CVE-IDs: TBA
Date: 2016-03-02
Risk Level: Medium…

CVE Request: Fiyo CMS 2.0.6.1 – Multiple XSS Vulnerabilities

Posted by Himanshu Mehta on Mar 03

*1. Introduction*

Affected Product: Fiyo CMS 2.0.6.1
Fixed in: 2.0.6.2
Vendor Website: http://www.fiyo.org/
Vulnerability Type: XSS
Remote Exploitable: Yes

*2. Overview*

There are multiple XSS vulnerabilities in Fiyo CMS 2.0.6.1. The
vulnerabilities exist due to insufficient filtration of user-supplied data.
A remote attacker can execute arbitrary HTML and script code in browser in
context of the vulnerable…

WAGO IO PLC 758-870, 750-849, 750-849 vulnerabilities

Posted by Karn Ganeshen on Mar 03

*WAGO IO PLC 758-870, 750-849, 750-849 vulnerabilities*

*Background*
According to WAGO’s Web site, WAGO is an international company based in
Germany. They operate production facilities in Germany, Switzerland,
Poland, China, and India. WAGO maintains offices worldwide.

According to WAGO, its products are deployed across several sectors
including manufacturing, building automation, electric generation,
transportation, and others. WAGO…