Red Hat Security Advisory 2016-1205-01 – The Simple Protocol for Independent Computing Environments is a remote display system built for virtual environments which allows the user to view a computing ‘desktop’ environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. Security Fix: A memory allocation flaw, leading to a heap-based buffer overflow, was found in spice’s smartcard interaction, which runs under the QEMU-KVM context on the host. A user connecting to a guest VM using spice could potentially use this flaw to crash the QEMU-KVM process or execute arbitrary code with the privileges of the host’s QEMU-KVM process.
Monthly Archives: June 2016
Ubuntu Security Notice USN-2994-1
Ubuntu Security Notice 2994-1 – It was discovered that libxml2 incorrectly handled certain malformed documents. If a user or automated system were tricked into opening a specially crafted document, an attacker could possibly cause libxml2 to crash, resulting in a denial of service. CVE-2016-3627,CVE-2016-3705, It was discovered that libxml2 incorrectly handled certain malformed documents. If a user or automated system were tricked into opening a specially crafted document, an attacker could cause libxml2 to crash, resulting in a denial of service, or possibly execute arbitrary code. Various other issues were also addressed.
GNU Transport Layer Security Library 3.4.13
GnuTLS is a secure communications library implementing the SSL and TLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols, as well as APIs to parse and write X.509, PKCS #12, OpenPGP, and other required structures. It is intended to be portable and efficient with a focus on security and interoperability. This is the previous stable release.
Electroweb Online Examination System 1.0 SQL Injection
Electroweb Online Examination System version 1.0 suffers from a remote SQL injection vulnerability.
Apache Continuum 1.4.2 Command Injection / Cross Site Scripting
Apache Continuum version 1.4.2 suffers from command injection and cross site scripting vulnerabilities.
Joomla JobGrokApp 3.1-1.2.55 SQL Injection
Joomla JobGrokApp component version 3.1-1.2.55 suffers from a remote SQL injection vulnerability.
Bugtraq: [SECURITY] [DSA 3594-1] chromium-browser security update
[SECURITY] [DSA 3594-1] chromium-browser security update
Bugtraq: [SECURITY] [DSA 3548-3] samba regression update
[SECURITY] [DSA 3548-3] samba regression update
Bugtraq: [SECURITY] [DSA 3595-1] mariadb-10.0 security update
[SECURITY] [DSA 3595-1] mariadb-10.0 security update
Bugtraq: [SECURITY] [DSA 3596-1] spice security update
[SECURITY] [DSA 3596-1] spice security update