Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
Monthly Archives: June 2016
CVE-2016-4356
The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.
CVE-2016-4414
The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data.
CVE-2016-4478
Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding.
CVE-2016-4574
Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-4356.
CVE-2016-4579
Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the “returned length of the object from _ksba_ber_parse_tl.”
MSPs Share Positive Feedback on AVG Managed Workplace
Monitoring and managing your customers can be challenging as demands increase and environments become more complex. Your tools must present fast and complete information– reducing complexity, not adding to it.
In April, we introduced AVG Managed Workplace 10 – a simplified approach to RMM that enables MSPs to deliver managed services and advanced security in a simplified, scalable and applied way that also meets their own business goals.
Feedback from our AVG partners indicates we’re on the right track – take a look:
“We have used Managed Workplace since 2006; it is our eyes and ears to everything. We looked at Kaseya, LabTech, Microsoft Systems Center – but AVG had the full featured RMM solution and with Managed Workplace 10, keeps improving.”
“Managed Workplace 10 is helping us reduce our onboarding time. The change to service plans was a big step forward in terms of architecting a managed service offering. We have gained immediate time savings and it’s easier to roll this out for our technicians.”
“The AVG Managed Workplace service templates are a stroke of genius. We literally onboarded a new customer on the first day of the product’s release and applied a monitoring, antivirus and proactive plan for a new customer within 10 minutes. We removed about five days of technician time thanks to the solution.”
“We can see that AVG Managed Workplace represents a significant improvement. We like the ability to apply a service plan to a site and like the fact that these are customizable. We also see the ease of use in setting up services and linking these to the service plans and speeding onboarding.”
“Using AVG Managed Workplace 10, onboarding is a breeze. There are multiple things you need to do when onboarding customers and setting up a site but with AVG Managed Workplace’s service plan model, all the alerting is pre-configured and ready to go. You don’t have to go in and customize each individual client based on the service plan they are part of and you can see quickly how the customer is being supported and the specific environment.”
“During the beta process, AVG really encouraged us to put Managed Workplace through its paces. They gave us a checklist of items to try and it enabled us to experiment with everything – it was a fantastic approach. We upgraded all customers without a hitch.”
“We have used different RMM tools in the past but they either had terrible support or too much required maintenance. AVG has a good balance of necessary information, self-management, and of course, price point. With the new Managed Workplace 10, we were able to easily transition our clients into standardized Service Plans. It was easy to reassign sites into their proper service plans. Configuration changes can now be adjusted very easily and only one time!”
Put Managed Workplace to the test today for your business. Join our Daily Demo and experience the simplicity by clicking here.
![]()
![]()
51 Million iMesh Accounts Available on Black Market
Fifty-one million iMesh accounts are for sale on Dark Web for $700, bringing the number of user accounts tied to recent breaches to over 700 million.
nagios phishing vector & xss
Posted by randomsec guy on Jun 13
corewindow can be used to phish users:
http://jdoe:jdoe () nagioscore demos nagios com/nagios/index.php?corewindow=http://wikipedia.com
also to perform xss:
http://jdoe:jdoe () nagioscore demos nagios
com/nagios/index.php?corewindow=javascript://zz%250a;onload=alert(document.domain)//
Samsung SW Update – Insecure ACLs on SW Update Service Directory – EoP Vulnerability
Posted by Benjamin Gnahm on Jun 13
Blue Frost Security GmbH
https://www.bluefrostsecurity.de/
research(at)bluefrostsecurity.de
BFS-SA-2016-003
25-April-2016