A HTTP/2 implementation built using any version of the Python HPACK library between v1.0.0 and v2.2.0 could be targeted for a denial of service attack, specifically a so-called “HPACK Bomb” attack. This attack occurs when an attacker inserts a header field that is exactly the size of the HPACK dynamic header table into the dynamic header table. The attacker can then send a header block that is simply repeated requests to expand that field in the dynamic table. This can lead to a gigantic compression ratio of 4,096 or better, meaning that 16kB of data can decompress to 64MB of data on the target machine. (CVSS:7.8) (Last Update:2017-01-27)
Monthly Archives: January 2017
Vuln: Adobe Acrobat and Reader APSB17-01 Use-After-Free Multiple Remote Code Execution Vulnerabilities
Adobe Acrobat and Reader APSB17-01 Use-After-Free Multiple Remote Code Execution Vulnerabilities
Vuln: Adobe Acrobat and Reader APSB17-01 Multiple Unspecified Memory Corruption Vulnerabilities
Adobe Acrobat and Reader APSB17-01 Multiple Unspecified Memory Corruption Vulnerabilities
Vuln: Adobe Acrobat and Reader CVE-2017-2947 Security Bypass Vulnerability
Adobe Acrobat and Reader CVE-2017-2947 Security Bypass Vulnerability
Vuln: Adobe Acrobat and Reader Multiple Unspecified Heap Buffer Overflow Vulnerabilities
Adobe Acrobat and Reader Multiple Unspecified Heap Buffer Overflow Vulnerabilities
GLSA 201701-17: Adobe Flash Player: Multiple vulnerabilities
GLSA 201701-18: Python: Multiple vulnerabilities
php-ZendFramework2-2.2.10-3.el6
Fixes [ZF2016-04](https://framework.zend.com/security/advisory/ZF2016-04) / [CVE-2016-10034](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10034) vulnerability
php-ZendFramework2-2.4.11-1.el7
Fixes [ZF2016-04](https://framework.zend.com/security/advisory/ZF2016-04) / [CVE-2016-10034](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10034) vulnerability
MongoDB Attacks Jump From Hundreds to 28,000 In Just Days
Security researchers report a massive uptick in the number of MongoDB databases hijacked and held for ransom.