Debian Linux Security Advisory 3585-1 – Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP which could result in denial of service.
Monthly Archives: May 2016
Red Hat Security Advisory 2016-1096-01
Red Hat Security Advisory 2016-1096-01 – The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix: Two flaws were found in the way the Linux kernel’s networking implementation handled UDP packets with incorrect checksum values. A remote attacker could potentially use these flaws to trigger an infinite loop in the kernel, resulting in a denial of service on the system, or cause a denial of service in applications using the edge triggered epoll functionality.
JobScript Remote Code Execution
JobScript suffers from an authenticated arbitrary PHP code execution. The vulnerability is caused due to the improper verification of uploaded files in ‘/admin-ajax.php’ script thru the ‘name’ and ‘file’ POST parameters. This can be exploited to execute arbitrary PHP code by uploading a malicious PHP script file with ‘.php’ extension (to bypass the ‘.htaccess’ block rule) that will be stored in ‘/jobmonster/wp-content/uploads/jobmonster/’ directory.
Operation Technology ETAP 14.1.0 Stack Buffer Overflow
Multiple ETAP binaries are prone to a stack-based buffer overflow vulnerability because the application fails to handle malformed arguments. Version 14.1.0.0 is affected. An attacker can exploit these issues to execute arbitrary code within the context of the application or to trigger a denial-of-service conditions.
Edward Snowden Won't Say Hello To Allo
Oculus Anti-Piracy Update Cracked In A Day
Shuttered Instagram Holes Opened 20 Million Accounts To Hijack
Enterprise Android Users Possibly At Risk From QSEE Flaw
SWIFT Network Doubles Down on Security
SWIFT reminds banks of their responsibility in securing their access to the financial network, and creates a centralized information sharing resources for users.
Linknat VOS3000/VOS2009 SQL Injection
Linknat VOS3000/VOS2009 suffers from a remote SQL injection vulnerability.