Red Hat Security Advisory 2014-1670-01 – KVM is a full virtualization solution for Linux on AMD64 and Intel 64 systems. The qemu-kvm-rhev package provides the user-space component for running virtual machines using KVM in environments managed by Red Hat Enterprise Virtualization Manager. An information leak flaw was found in the way QEMU’s VGA emulator accessed frame buffer memory for high resolution displays. A privileged guest user could use this flaw to leak memory contents of the host to the guest by setting the display to use a high resolution in the guest. This issue was discovered by Laszlo Ersek of Red Hat.
Monthly Archives: October 2014
Red Hat Security Advisory 2014-1671-01
Red Hat Security Advisory 2014-1671-01 – The rsyslog packages provide an enhanced, multi-threaded syslog daemon that supports writing to relational databases, syslog/TCP, RFC 3195, permitted sender lists, filtering on any message part, and fine grained output format control. A flaw was found in the way rsyslog handled invalid log message priority values. In certain configurations, a local attacker, or a remote attacker able to connect to the rsyslog port, could use this flaw to crash the rsyslog daemon.
Debian Security Advisory 3054-1
Debian Linux Security Advisory 3054-1 – Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.40.
Huawei Mobile Partner DLL Hijacking
Huawei Mobile Partner suffers from a DLL hijacking vulnerability.
Vuln: Bugzilla CVE-2014-1573 Multiple Cross Site Scripting Vulnerabilities
Bugzilla CVE-2014-1573 Multiple Cross Site Scripting Vulnerabilities
Vuln: PHP CVE-2014-3669 Denial of Service Vulnerability
PHP CVE-2014-3669 Denial of Service Vulnerability
Vuln: OpenSSL CVE-2014-3566 Man In The Middle Information Disclosure Vulnerability
OpenSSL CVE-2014-3566 Man In The Middle Information Disclosure Vulnerability
Vuln: Oracle Java SE CVE-2014-4244 Remote Security Vulnerability
Oracle Java SE CVE-2014-4244 Remote Security Vulnerability
CVE-2014-5026 (cacti, debian_linux, opensuse)
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input Method Name, or (5) Host Templates Name in a delete action; (6) Data Source Title; (7) Graph Title; or (8) Graph Template Name in a delete or (9) duplicate action.
Bugtraq: Elastix Multiple vulnerabilities (Remote Command Execution, XSS, CSRF)
Elastix Multiple vulnerabilities (Remote Command Execution, XSS, CSRF)