Uber Now Tracks Your Location Even After Your Ride

Uber was in controversies at the mid of this year for monitoring the battery life of its users, as the company believed that its users were more likely to pay a much higher price to hire a cab when their phone’s battery is close to dying.

Uber is now tracking you even when your ride is over, and, according to the ride-hailing company, the surveillance will improve its service.

Uber recently

dovecot-2.2.27-1.fc24

– Fixed crash in auth process when auth-policy was configured and authentication was aborted/failed without a username set.
– director: If two users had different tags but the same hash, the users may have been redirected to the wrong tag’s hosts.
– Index files may have been thought incorrectly lost, causing “Missing middle file seq=..” to be logged and index rebuild. This happened more easily with IMAP hibernation enabled.
– Various fixes to restoring state correctly in un-hibernation.
– dovecot.index files were commonly 4 bytes per email too large. This is because 3 bytes per email were being wasted that could have been used for IMAP keywords.
– Various fixes to handle dovecot.list.index corruption better.
– lib-fts: Fixed assert-crash in address tokenizer with specific input.
– Fixed assert-crash in HTML to text parsing with specific input (e.g. for FTS indexing or snippet generation)
– doveadm sync -1: Fixed handling mailbox GUID conflicts.
– sdbox, mdbox: Perform full index rebuild if corruption is detected inside lib-index, which runs index fsck.
– quota: Don’t skip quota checks when moving mails between different quota roots.
– search: Multiple sequence sets or UID sets in search parameters weren’t handled correctly. They were incorrectly merged together.

dovecot-2.2.27-1.fc25

– Fixed crash in auth process when auth-policy was configured and authentication was aborted/failed without a username set.
– director: If two users had different tags but the same hash, the users may have been redirected to the wrong tag’s hosts.
– Index files may have been thought incorrectly lost, causing “Missing middle file seq=..” to be logged and index rebuild. This happened more easily with IMAP hibernation enabled.
– Various fixes to restoring state correctly in un-hibernation.
– dovecot.index files were commonly 4 bytes per email too large. This is because 3 bytes per email were being wasted that could have been used for IMAP keywords.
– Various fixes to handle dovecot.list.index corruption better.
– lib-fts: Fixed assert-crash in address tokenizer with specific input.
– Fixed assert-crash in HTML to text parsing with specific input (e.g. for FTS indexing or snippet generation)
– doveadm sync -1: Fixed handling mailbox GUID conflicts.
– sdbox, mdbox: Perform full index rebuild if corruption is detected inside lib-index, which runs index fsck.
– quota: Don’t skip quota checks when moving mails between different quota roots.
– search: Multiple sequence sets or UID sets in search parameters weren’t handled correctly. They were incorrectly merged together.

dovecot-2.2.27-1.fc23

– Fixed crash in auth process when auth-policy was configured and authentication was aborted/failed without a username set.
– director: If two users had different tags but the same hash, the users may have been redirected to the wrong tag’s hosts.
– Index files may have been thought incorrectly lost, causing “Missing middle file seq=..” to be logged and index rebuild. This happened more easily with IMAP hibernation enabled.
– Various fixes to restoring state correctly in un-hibernation.
– dovecot.index files were commonly 4 bytes per email too large. This is because 3 bytes per email were being wasted that could have been used for IMAP keywords.
– Various fixes to handle dovecot.list.index corruption better.
– lib-fts: Fixed assert-crash in address tokenizer with specific input.
– Fixed assert-crash in HTML to text parsing with specific input (e.g. for FTS indexing or snippet generation)
– doveadm sync -1: Fixed handling mailbox GUID conflicts.
– sdbox, mdbox: Perform full index rebuild if corruption is detected inside lib-index, which runs index fsck.
– quota: Don’t skip quota checks when moving mails between different quota roots.
– search: Multiple sequence sets or UID sets in search parameters weren’t handled correctly. They were incorrectly merged together.

CVE-2016-8858

** DISPUTED ** The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that “OpenSSH upstream does not consider this as a security issue.”

[ESNC-2041217] Critical Security Vulnerability in PwC ACE Software for SAP Security

Posted by ESNC Security on Dec 09

*[ESNC-2041217] Critical Security Vulnerability in PwC ACE Software for SAP
Security*

Please refer to https://www.esnc.de for the original security advisory,
updates, and additional information.

*———————————————————————-*
*1. Business Impact*
*———————————————————————-*

According to PwC website:
– “Using the proprietary ACE software, we perform…

Roundcube 1.2.2: Command Execution via Email

Posted by Martin Bednorz on Dec 09

Roundcube 1.2.2: Command Execution via Email
============================================
You can find the online version of the advisory here:
https://blog.ripstech.com/2016/roundcube-command-execution-via-email/

Found by Robin Peraglie with RIPS

Introduction
————
Roundcube is a widely distributed open-source webmail software used by
many organizations and companies around the globe. The mirror on
SourceForge, for example, counts more…