Spark (sparkjava.com) is a mildly hyped Java micro web framework that
also provides functionality to serve static files. Unfortunately,
there’s no protection against directory traversal attacks and I haven’t
been able to contact anyone related to the project (after trying 4
people over 2 weeks). As this bug is not that awesome, and fairly
trivial to find, please help yourself to some semi-shitty 0-day.
Aleksandar Nikolic of Cisco Talos discovered several integer overflow
vulnerabilities in memcached, a high-performance memory object caching
system. A remote attacker can take advantage of these flaws to cause a
denial of service (daemon crash), or potentially to execute arbitrary
code.
Ubuntu Security Notice 3120-1 – Aleksandar Nikolic discovered that Memcached incorrectly handled certain malformed commands. A remote attacker could use this issue to cause Memcached to crash, resulting in a denial of service, or possibly execute arbitrary code.
Cisco has released several updates to address vulnerabilities affecting multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.
Users and administrators are encouraged to review the following Cisco Security Advisories and apply the necessary updates:
Cisco ASR 900 Series Aggregation Services Routers Buffer Overflow Vulnerability [cisco-sa-20161102-tl1]
Google has released Chrome version 54.0.2840.87 for Windows and Mac, and version 54.0.2840.90 for Linux. These new versions address a vulnerability that, if exploited, may allow an attacker to create a denial-of-service condition.
US-CERT encourages users and administrators to review the Chrome Releases page and apply the necessary updates.
This module enables you to create and manage custom editorial workflows around a site’s content.
The module could result in unpublished content being temporarily made visible via content lists, e.g. as generated by Views, when its editorial status was being changed, e.g. from “draft” to “needs work”.
This vulnerability is mitigated by the fact that the content lists must be regenerated at exactly the moment when a person saves the node.
CVE identifier(s) issued
A CVE identifier will be requested, and added upon issuance, in accordance with Drupal Security Team processes.
Versions affected
Workbench Moderation 7.x-1.x versions and 7.x-3.x versions prior to 7.x-3.0.
Drupal core is not affected. If you do not use the contributed Workbench Moderation module, there is nothing you need to do.