Samsung’s lkmauth feature suffers from a kernel module verification bypass vulnerability.
Monthly Archives: January 2017
Red Hat Security Advisory 2017-0002-01
Red Hat Security Advisory 2017-0002-01 – Node.js is a platform built on Chrome’s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. The following packages have been upgraded to a newer upstream version: rh-nodejs4-nodejs, rh-nodejs4-http-parser. Security Fix: It was found that Node.js’ tls.checkServerIdentity() function did not properly validate server certificates containing wildcards. A malicious TLS server could use this flaw to get a specially crafted certificate accepted by a Node.js TLS client.
Gentoo Linux Security Advisory 201701-15
Gentoo Linux Security Advisory 201701-15 – Multiple vulnerabilities have been found in Mozilla Firefox, SeaMonkey, and Thunderbird the worst of which could lead to the execution of arbitrary code. Versions less than 45.6.0 are affected.
No Smoking Gun For Russian DNC Hacks
Android Tops 2016 Vuln List, With 523 Bugs
Libpng Library Gets Fix For Truly Ancient Bug
Why China Was Able To Steal A US Drone
Kaspersky Local CA Root Protected Incorrectly
Kaspersky fails to adequately protect its local CA root.
Samsung OTP Service Heap Overflow
As a part of the KNOX extensions available on Samsung devices, Samsung provides a new service which allows the generation of OTP tokens and suffers from a heap overflow vulnerability.
Critical Updates — RCE Flaws Found in SwiftMailer, PhpMailer and ZendMail
A security researcher recently reported a critical vulnerability in one of the most popular open source PHP libraries used to send emails that allowed a remote attacker to execute arbitrary code in the context of the web server and compromise a web application.
Disclosed by Polish security researcher Dawid Golunski of Legal Hackers, the issue (CVE-2016-10033) in PHPMailer used by more than 9
![]()
