Red Hat Enterprise Linux: Updated OpenStack Compute packages that resolve various issues are now
available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse)
for RHEL 7.
Monthly Archives: April 2016
RHBA-2016:0689-1: openstack-nova bug fix advisory
Red Hat Enterprise Linux: Updated OpenStack Compute packages that resolve various issues are now
available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse)
for RHEL 6.
Remote Code Execution in Shopware <5.1.5 (CVE-2016-3109)
Posted by David Vieira-Kurz on Apr 26
CREDITS
========
This issue has been identified by David Vieira-Kurz of Immobilien Scout GmbH.
CVE
====
CVE-2016-3109
AFFECTED PRODUCT
==================
Shopware < 5.1.5 : https://en.shopware.com/
IMPACT
=======
This issue has been triaged with the highest severity (CRITICAL) by the Shopware maintainer because it allows
unauthenticated remote code execution by any attacker! This means that an attacker is able to read ANY files on…
[CFP] GreHack 2016
Posted by Paget Philippe on Apr 26
[cid:[email protected]]
# GreHack 2016 – Call For Paper
* website: http://grehack.fr
* online version: http://grehack.fr/data/cfp.txt
## What’s GreHack?
GreHack is an international security conference which takes place in Grenoble (France). It aims to bring together
academics, industry, governments, students and hackers to discuss new advances in computer and information security
research. This year will be the fourth…
Request For Comment: Possible Flaw of Bypassing CAPTCHA in AWS Login?
Posted by David Leo on Apr 26
The process of AWS login has a feature: if you use “fresh” browser(no cookie, no cache, etc) to sign in, put correct
email and correct password there, CAPTCHA is required(“To better protect your account, please re-enter your password
and then enter the characters as they are shown in the image below”).
And I accidentally noticed this feature can be easily bypassed:
MY SYSTEM
Knoppix 7.6.0 on Read-Only USB Stick – always…
Multiple Vulnerabilities in Voo branded Netgear CG3700b
Posted by dev on Apr 26
CVEs pending, screenshots and further examples available soon on my site.
Cross-Site Request Forgery (CSRF) on all form POSTs
———————————————————————————
The Voo branded Netgear CG3700b custom firmware (newest version, V2.02.03)
allows a (context-dependent) attacker to perform a Cross-Site Request
Forgery (CSRF) attack on all configuration setting
(/goform/<settingspage>) page POST…
Mozilla Releases Security Updates
Original release date: April 26, 2016
Mozilla has released security updates to address multiple vulnerabilities in Firefox and Firefox ESR. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Available updates include:
- Firefox 46
- FireFox ESR 38.8
- FireFox ESR 45.1
Users and administrators are encouraged to review the Mozilla Security Advisories for Firefox and Firefox ESR and apply the necessary updates.
This product is provided subject to this Notification and this Privacy & Use policy.
Empty DDoS Threats Still Net Attackers $100,000
A group posing as the Armada Collective is threatening businesses with large-scale DDoS attacks without carrying out the attacks. So far, they’ve been paid more than $100,000.
Pro-ISIS Hackers release 'Kill List' Of 43 United States Officials
In Brief
A group of pro-ISIS hackers calling themselves the United Cyber Caliphate (UCC) has issued a “Kill List” containing the names of dozens of U.S. government personnel at the Pentagon, Department of Homeland Security, State Department, and several other federal agencies.
Meanwhile, the US military’s Cyber Command has announced to launch its first attack against ISIS’ digital
![]()
BeautifulPeople.com experiences data breach: 1m affected
The personal data of around 1.1 million people could be sold off on the black market after BeautifulPeople.com experiences data breach.
The post BeautifulPeople.com experiences data breach: 1m affected appeared first on We Live Security.
![]()
