IBM Tealeaf Customer Experience CVE-2016-5976 Information Disclosure Vulnerability
Monthly Archives: September 2016
Vuln: Apache Derby CVE-2015-1832 XML External Entity Information Disclosure Vulnerability
Apache Derby CVE-2015-1832 XML External Entity Information Disclosure Vulnerability
Vuln: IBM Tealeaf Customer Experience CVE-2016-5976 Information Disclosure Vulnerability
IBM Tealeaf Customer Experience CVE-2016-5976 Information Disclosure Vulnerability
OpenSSL Toolkit 1.0.2j
OpenSSL is a robust, fully featured Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols with full-strength cryptography world-wide.
Slackware Security Advisory – openssl Updates
Slackware Security Advisory – New openssl packages are available for Slackware 14.2 and -current to fix a security issue.
MIMEDefang Email Scanner 2.79
MIMEDefang is a flexible MIME email scanner designed to protect Windows clients from viruses. Includes the ability to do many other kinds of mail processing, such as replacing parts of messages with URLs. It can alter or delete various parts of a MIME message according to a very flexible configuration file. It can also bounce messages with unacceptable attachments. MIMEDefang works with the Sendmail 8.11 and newer “Milter” API, which makes it more flexible and efficient than procmail-based approaches.
360-FAAR Firewall Analysis Audit And Repair 0.6.0
360-FAAR Firewall Analysis Audit and Repair is an offline command line perl policy manipulation tool to filter, compare to logs, merge, translate and output firewall commands for new policies, in checkpoint dbedit or screenos commands.
Sofacy APT Targeting OS X Machines with Komplex Trojan
APT gang Sofacy is targeting Mac OS X users with a Trojan that allows an attacker to execute remote commands on infected systems.
CVE-2016-6304
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.
CVE-2016-6305
The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call.