Debian Linux Security Advisory 3795-1 – It was discovered that a maliciously crafted query can cause ISC’s BIND DNS server (named) to crash if both Response Policy Zones (RPZ) and DNS64 (a bridge between IPv4 and IPv6 networks) are enabled. It is uncommon for both of these options to be used in combination, so very few systems will be affected by this problem in practice.
Monthly Archives: February 2017
Android Malware On The Rise
SAP BusinessObjects Financial Consolidation 10.0.0.1933 Cross Site Scripting
SAP BusinessObjects Financial Consolidation version 10.0.0.1933 suffers from a cross site scripting vulnerability in the help component.
WordPress Kama Click Counter 3.4.9 SQL Injection
WordPress Kama Click Counter plugin version 3.4.9 suffers from a remote blind SQL injection vulnerability.
Red Hat Security Advisory 2017-0334-01
Red Hat Security Advisory 2017-0334-01 – KVM is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products. Security Fix: Quick emulator built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.
Red Hat Security Advisory 2017-0333-01
Red Hat Security Advisory 2017-0333-01 – KVM is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products. Security Fix: Quick emulator built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.
freeipa-4.4.3-2.fc25
Fixed CVE 2017-2590: freeipa: ipa: Insufficient permission check for ca-del, ca-disable and ca-enable commands [fedora-all]