Ubuntu Security Notice USN-2459-1

Ubuntu Security Notice 2459-1 – Pieter Wuille discovered that OpenSSL incorrectly handled Bignum squaring. Markus Stenberg discovered that OpenSSL incorrectly handled certain crafted DTLS messages. A remote attacker could use this issue to cause OpenSSL to crash, resulting in a denial of service. Karthikeyan Bhargavan discovered that OpenSSL incorrectly handled certain handshakes. A remote attacker could possibly use this issue to downgrade to ECDH, removing forward secrecy from the ciphersuite. Various other issues were also addressed.

Red Hat Security Advisory 2015-0033-01

Red Hat Security Advisory 2015-0033-01 – Red Hat Satellite provides a solution to organizations requiring absolute control over and privacy of the maintenance and package deployment of their servers. It allows organizations to utilize the benefits of Red Hat Network without having to provide public Internet access to their servers or other client systems. This update introduces Red Hat Satellite 5.7.0.

Red Hat Security Advisory 2015-0034-01

Red Hat Security Advisory 2015-0034-01 – Red Hat JBoss Data Virtualization is a lean data integration solution that provides easy, real-time, and unified data access across disparate sources to multiple applications and users. JBoss Data Virtualization makes data spread across physically distinct systems such as multiple databases, XML files, and even Hadoop systems appear as a set of tables in a local database. This roll up patch serves as a cumulative upgrade for Red Hat JBoss Data Virtualization 6.0.0. It includes various bug fixes, which are listed in the README file included with the patch files.

Lizard Stresser rekt

Posted by Robert Cavanaugh on Jan 12

Hi FD,

I’m sure you’re all sick to death of hearing about Lizard Squad and the
skid marks they’re leaving all over the place, so we’ll make this brief:
Lizard Squad has been rekt and the source code for their bots is now
available for your viewing pleasure.

https://github.com/pop-pop-ret/lizkebab

0wned by: Chippy1337, @packetprophet

If you lulz’d, send BTC to 129UQoB3JvZg3iDERYZiXeHPkwT1iJF8u4
<…

Stored XSS Vulnerability in F5 BIG-IP Application Security Manager

Posted by Peter Lapp on Jan 12

Details
=======

Product: F5 BIG-IP Application Security Manager (ASM)
Vulnerability: Cross Site Scripting
Author: Peter Lapp, lappsec () gmail com
CVE: None assigned
Vulnerable Versions: Confirmed 11.4.0, 11.4.1. Likely 11.4.x-11.5.x.
Fixed Version: 11.6

Summary
=======

The F5 ASM is a web application firewall designed to protect web
applications from attacks. It allows for a custom HTML page to be displayed
to end users when they trigger a…

XSS Vulnerability in Fork CMS 3.8.3

Posted by ITAS Team on Jan 12

# Exploit Title: XSS Vulnerability in Fork CMS 3.8.3

# Google Dork: N/A

# Date: 12/26/2014

# Exploit Author: Le Ngoc phi (phi.n.le () itas vn) and ITAS Team (www.itas.vn)

# Vendor Homepage: http://www.fork-cms.com

# Software Link: http://www.fork-cms.com/blog/detail/fork-3.8.4-released

# Version: Fork 3.8.3

# Tested on: N/A

# CVE : CVE-2014-9470

::VULNERABILITY DETAIL::

– Vulnerable parameter: q_widget

– Vulnerable file:…

Software and Security Information