Aternity CVE-2016-5061 Multiple Cross Site Scripting Vulnerabilities
Monthly Archives: September 2016
Vuln: Cisco IOS XR Software CVE-2016-6421 Denial of Service Vulnerability
Cisco IOS XR Software CVE-2016-6421 Denial of Service Vulnerability
Red Hat Security Advisory 2016-1944-01
Red Hat Security Advisory 2016-1944-01 – The Berkeley Internet Name Domain is an implementation of the Domain Name System protocols. BIND includes a DNS server ; a resolver library ; and tools for verifying that the DNS server is operating correctly. Security Fix: A denial of service flaw was found in the way BIND constructed a response to a query that met certain criteria. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS request packet.
Red Hat Security Advisory 2016-1945-01
Red Hat Security Advisory 2016-1945-01 – The Berkeley Internet Name Domain is an implementation of the Domain Name System protocols. BIND includes a DNS server ; a resolver library ; and tools for verifying that the DNS server is operating correctly. Security Fix: A denial of service flaw was found in the way BIND constructed a response to a query that met certain criteria. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS request packet.
Symantec Messaging Gateway 10.6.1 Directory Traversal
Symantec Messaging Gateway versions 10.6.1 and below suffer from a directory traversal vulnerability.
Cisco Security Advisory 20160927-openssl
Cisco Security Advisory – On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities.
Slackware Security Advisory – bind Updates
Slackware Security Advisory – New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.
D-Link DWR-932B Backdoors / Default WPS PIN
D-Link DWR-932B suffers from backdoor accounts, default WPS PIN, weak WPS PIN generation, and various other bad security practices and issues.
Microsoft Unveils Cloud-Based Fuzz-Testing Service
Microsoft announced a cloud-based fuzz testing service called Project Springfield that identifies software bugs in applications that could turn into vulnerabilities.
CVE-2016-7191
The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize the validateIssuer setting, which allows remote attackers to bypass authentication via a crafted token.