HP Security Bulletin HPSBNS03635 1

HP Security Bulletin HPSBNS03635 1 – Multiple potential remote and local vulnerabilities impacting Perl and PHP have been addressed by HPE NonStop Servers OSS Script Languages. The vulnerabilities include Perl’s opportunistic loading of optional modules which might allow local users to gain elevation of privilege via a Trojan horse library under the current working directory. Revision 1 of this advisory.

Horizontal Privilege Escalation/Code Injection in ownCloud’s Windows Client

Posted by Florian Bogner on Aug 22

Horizontal Privilege Escalation/Code Injection in ownCloud’s Windows Client

Metadata
===================================================
Release Date: 17-08-2016
Author: Florian Bogner @ Kapsch BusinessCom AG (https://www.kapsch.net/kbc)
Affected versions: up to ownCloud’s Desktop client version 2.2.2
Tested on: Windows 7 64 bit
CVE : pending
URL: https://bogner.sh/2016/08/horizontal-privilege-escalation-in-ownclouds-windows-client/

Faraday v2.0: Collaborative Penetration Test and Vulnerability Management Platform

Posted by Francisco Amato on Aug 22

Faraday is the Integrated Multiuser Risk Environment you were looking
for! It maps and leverages all the knowledge you generate in real
time, letting you track and understand your audits. Our dashboard for
CISOs and managers uncovers the impact and risk being assessed by the
audit in real-time without the need for a single email. Developed with
a specialized set of functionalities that help users improve their own
work, the main purpose is to…

[CVE-2016-6582] Doorkeeper gem does not revoke tokens & uses wrong auth/auth method

Posted by Justin Bull on Aug 22

Good evening everyone,

A security bulletin for all of you.

Software:
——–
Doorkeeper (https://github.com/doorkeeper-gem/doorkeeper)

Description:
———-
Doorkeeper is an OAuth 2 provider for Rails written in Ruby.

Affected Versions:
—————
1.2.0 – 4.1.0 (all versions but latest patch supporting token revocation)

Fixed Versions:
————-
4.2.0 or apply this commit[0]

Problem:
——–
Doorkeeper failed to implement OAuth…