Monthly Archives: May 2016
Panama Papers Now Searchable
Ubuntu Security Notice USN-2965-1
Ubuntu Security Notice 2965-1 – Jann Horn discovered that the extended Berkeley Packet Filter (eBPF) implementation in the Linux kernel did not properly reference count file descriptors, leading to a use-after-free. A local unprivileged attacker could use this to gain administrative privileges. Ralf Spenneberg discovered that the USB sound subsystem in the Linux kernel did not properly validate USB device descriptors. An attacker with physical access could use this to cause a denial of service (system crash). Various other issues were also addressed.
Ubuntu Security Notice USN-2965-3
Ubuntu Security Notice 2965-3 – Jann Horn discovered that the extended Berkeley Packet Filter (eBPF) implementation in the Linux kernel did not properly reference count file descriptors, leading to a use-after-free. A local unprivileged attacker could use this to gain administrative privileges. Ralf Spenneberg discovered that the USB sound subsystem in the Linux kernel did not properly validate USB device descriptors. An attacker with physical access could use this to cause a denial of service (system crash). Various other issues were also addressed.
Ubuntu Security Notice USN-2965-4
Ubuntu Security Notice 2965-4 – Jann Horn discovered that the extended Berkeley Packet Filter (eBPF) implementation in the Linux kernel did not properly reference count file descriptors, leading to a use-after-free. A local unprivileged attacker could use this to gain administrative privileges. Ralf Spenneberg discovered that the USB sound subsystem in the Linux kernel did not properly validate USB device descriptors. An attacker with physical access could use this to cause a denial of service (system crash). Various other issues were also addressed.
Debian Security Advisory 3571-1
Debian Linux Security Advisory 3571-1 – Simon McVittie discovered a cross-site scripting vulnerability in the error reporting of Ikiwiki, a wiki compiler. This update also hardens ikiwiki’s use of imagemagick in the img plugin.
Red Hat Security Advisory 2016-0722-01
Red Hat Security Advisory 2016-0722-01 – OpenSSL is a toolkit that implements the Secure Sockets Layer and Transport Layer Security protocols, as well as a full-strength general-purpose cryptography library. Security Fix: A flaw was found in the way OpenSSL encoded certain ASN.1 data structures. An attacker could use this flaw to create a specially crafted certificate which, when verified or re-encoded by OpenSSL, could cause it to crash, or execute arbitrary code using the permissions of the user running an application compiled against the OpenSSL library.
Ubuntu Security Notice USN-2965-2
Ubuntu Security Notice 2965-2 – USN-2965-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04 LTS. This update provides the corresponding updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu 14.04 LTS. Jann Horn discovered that the extended Berkeley Packet Filter (eBPF) implementation in the Linux kernel did not properly reference count file descriptors, leading to a use-after-free. A local unprivileged attacker could use this to gain administrative privileges. Various other issues were also addressed.
Re: CVE Request for ManageEngine Applications Manager Build No: 12700 Information Disclosure and Un-Authenticated SQL injection.
Posted by Saif El-Sherei on May 09
Heya,
I was already informed that the product is mot covered by Mitre CVE the release is just for responsible disclosure not
CVE request.
Regards,
Saif
Sent from my iPhone
WheresMyDroid Android App issues
Posted by 0x3d5157636b525761 iddqd on May 09
Brief
=====
Android App WheresMyDroid (10M – 50M installations) allows a malicious
user to perform the following:
– Take silent camera photos, automatically uploading them.
– Getting the GPS location.
– Possibly wiping the phone, locking and unlocking the device.
– Upgrading the App to the Pro version.
These are all possible via SMS messages.
Disclosure timeline
===================
April 20th, 2016: discovered issues.
April 21st, 2016:…