The Talk Radio Europe (aka com.nobexinc.wls_31251464.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Monthly Archives: October 2014
CVE-2014-7102
The Car Insurance Quote Comparison (aka com.seopa.quotezone) application 2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7103
The Oskarshamnsliv (aka appinventor.ai_stadslivsguiden.Oskarshamnsliv) application 6.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7104
The gymnoOVP (iOVP) (aka com.johtru.gymnoOVP) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7106
The Orakel-Ball (aka com.wOrakelball) application 0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7107
The Human Factor (aka com.magzter.thehumanfactor) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2014-7191
The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.
CVE-2014-7874
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Cyanogenmod MITM: proven, despite cyanogenmod's public denail
Posted by Lord Tuskington on Oct 19
After reading el reg’s article regarding a cyanogenmod MITM flaw, I started
looking through the code to see if I could find it. It didn’t take long.
This finding was not what users are led to believe by cyanogenmod’s blog
post:
http://www.cyanogenmod.org/blog/in-response-to-the-register-mitm-article
I reported the issue to cyanogenmod, but got a rather unsatisfactory reply.
They didn’t seem willing to modify the blog post to…
RHBA-2014:1664-1: Red Hat OpenShift Enterprise 2.1 rubygem-httpclient bug fix
Red Hat Enterprise Linux: Updated rubygem-httpclient and ruby193-rubygem-httpclient packages that fix a
bug are now available for Red Hat OpenShift Enterprise 2.1.