Cisco ASA software IKEv1 and IKEv2 remote buffer overflow exploit.
Monthly Archives: May 2016
Meteocontrol WEBLog Password Extractor
This Metasploit module exploits an authentication bypass vulnerability in Meteocontrol WEBLog (all models). This vulnerability allows extracting Administrator password for the device management portal.
Dell SonicWALL Scrutinizer 11.01 methodDetail SQL Injection
This Metasploit module exploits a vulnerability found in Dell SonicWALL Scrutinizer. The methodDetail parameter in exporters.php allows an attacker to write arbitrary files to the file system with an SQL Injection attack, and gain remote code execution under the context of SYSTEM for Windows, or as Apache for Linux. Authentication is required to exploit this vulnerability, but this module uses the default admin:admin credential.
Ubuntu Security Notice USN-2982-1
Ubuntu Security Notice 2982-1 – Hanno Boeck discovered that Libksba incorrectly handled decoding certain BER data. An attacker could use this issue to cause Libksba to crash, resulting in a denial of service. This issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. Hanno Boeck discovered that Libksba incorrectly handled decoding certain BER data. An attacker could use this issue to cause Libksba to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. Various other issues were also addressed.
Red Hat Security Advisory 2016-1086-01
Red Hat Security Advisory 2016-1086-01 – Libndp is a library that provides a wrapper for the IPv6 Neighbor Discovery Protocol. It also provides a tool named ndptool for sending and receiving NDP messages. Security Fix: It was found that libndp did not properly validate and check the origin of Neighbor Discovery Protocol messages. An attacker on a non-local network could use this flaw to advertise a node as a router, allowing them to perform man-in-the-middle attacks on a connecting client, or disrupt the network connectivity of that client.
Debian Security Advisory 3581-1
Debian Linux Security Advisory 3581-1 – Julien Bernard discovered that libndp, a library for the IPv6 Neighbor Discovery Protocol, does not properly perform input and origin checks during the reception of a NDP message. An attacker in a non-local network could use this flaw to advertise a node as a router, and cause a denial of service attack, or act as a man-in-the-middle.
Apple Security Advisory 2016-05-16-6
Apple Security Advisory 2016-05-16-6 – iTunes 12.4 is now available and addresses a code execution vulnerability.
Apple Security Advisory 2016-05-16-5
Apple Security Advisory 2016-05-16-5 – Safari 9.1.1 is now available and addresses history deletion, data disclosure, code execution, and various other vulnerabilities.
Ubuntu Security Notice USN-2981-1
Ubuntu Security Notice 2981-1 – It was discovered that libarchive incorrectly handled certain entry-size values in ZIP archives. A remote attacker could use this issue to cause libarchive to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS, Ubuntu 15.10 and Ubuntu 16.04 LTS. It was discovered that libarchive incorrectly handled memory when processing certain tar files. A remote attacker could use this issue to cause libarchive to crash, resulting in a denial of service. Various other issues were also addressed.
Gentoo Linux Security Advisory 201605-02
Gentoo Linux Security Advisory 201605-2 – Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code. Versions less than 50.0.2661.102 are affected.