The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large memory allocations) via vectors involving the header information and the file size.
Monthly Archives: February 2017
CVE-2017-5368
ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others).
CVE-2016-5102
Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file.
CVE-2016-7447
Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.
Banking chiefs ‘lack confidence to identify data breaches’
Just over one in five banks and insurers are confident in their ability to identify data breaches, according to a new global survey from Capgemini Consulting.
The post Banking chiefs ‘lack confidence to identify data breaches’ appeared first on WeLiveSecurity
![]()
openssl-1.0.2k-1.fc25
Minor upstream release fixing CVE-2016-8610, CVE-2017-3731, CVE-2017-3732.
openssl-1.0.2k-1.fc24
Minor upstream release fixing CVE-2016-8610, CVE-2017-3731, CVE-2017-3732.
gnome-boxes-3.20.4-1.fc24
gnome-boxes 3.20.4 release, fixing a possible security issue with storing the express installation password in clear text.
– Store the user password in the keyring during an express installation.
– Fix typo in debug string.
– Fix printf format strings.
gnome-boxes-3.22.4-1.fc25
gnome-boxes 3.22.4 release, fixing a possible security issue with storing the express installation password in clear text.
– Store the user password in the keyring during an express installation.
– Fix typo in debug string in vm-configurator.
– Fix printf format strings in the selectiontoolbar.
CVE-2017-5877
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter.