HP Security Bulletin HPSBGN03569 2 – Potential security vulnerabilities have been identified in the server running HP OneView for VMware vCenter (OV4VC) version 7.8.1 or earlier. The vulnerabilities may lead to remote disclosure of information. Revision 2 of this advisory.
Monthly Archives: April 2016
HP Security Bulletin HPSBST03568 1
HP Security Bulletin HPSBST03568 1 – A potential security vulnerability has been identified with HP XP7 Command View Advanced Edition Suite and HP XP P9000 Command View Advanced Edition Software including Device Manager and Hitachi Automation Director (HAD). The vulnerability could be remotely exploited resulting in Server-Side Request Forgery (SSRF). Revision 1 of this advisory.
OSVDB Shuts Down For Good
Panda Security URL Filtering Privilege Escalation
Panda Security URL Filtering versions prior to 4.3.1.9 suffer from a privilege escalation vulnerability.
Panda Endpoint Administration Agent Privilege Escalation
Panda Endpoint Administration Agent versions prior to 7.50.00 suffer from a privilege escalation vulnerability.
SIDU 5.3 Cross Site Scripting
SIDU version 5.3 database web gui suffers from multiple cross site scripting vulnerabilities.
SIDU 5.2 Cross Site Scripting
SIDU version 5.2 database web gui suffers from multiple cross site scripting vulnerabilities.
Linux ASLR Weakness Addressed
A weakness in the Linux ASLR implementation has been addressed.
Microsoft Windows 8.1 Console Driver Job Object Process Limit Bypass
One change in Windows 8.1 from Windows 7 is the introduction of the console driver (condrv.sys) which is responsible for handling the management of consoles. It contains a method, CdpLaunchServerProcess which creates an instance of conhost.exe. This method calls ZwCreateUserProcess which means that the system call runs with kernel permissions, it also passes a flag (0x400) to the system call which indicates that the new process should not be assigned to the parent job. This allows for the conhost process to bypass the job restrictions.
DSA-3546 optipng – security update
Hans Jerry Illikainen discovered that missing input sanitising in the
BMP processing code of the optipng PNG optimiser may result in denial of
service or the execution of arbitrary code if a malformed file is
processed.