Re: LiveZilla 5.3.0.7 Security Issue
Monthly Archives: October 2014
Bugtraq: [SECURITY] [DSA 3050-1] iceweasel security update
[SECURITY] [DSA 3050-1] iceweasel security update
Apple Releases Security Updates for iOS and Apple TV
Original release date: October 20, 2014
Apple has released security updates for iOS devices and Apple TV to address multiple vulnerabilities, one of which could allow an attacker to decrypt data protected by SSL.
Updates available include:
- iOS 8.1 for iPhone 4s and later, iPod touch 5th generation and later, and iPad 2 and later
- Apple TV 7.0.1 for Apple TV 3rd generation and later
Users and administrators are encouraged to review Apple security updates HT6541 and HT6542, and apply the necessary updates.
This product is provided subject to this Notification and this Privacy & Use policy.
Obama Executive Order Forces Chip & Pin Payment on Government
The Obama administration has issued an executive order aimed at speeding up the adoption of chip and PIN or EMV payment systems here in the United States.
RHEA-2014:1667-1: new packages: kmod-mlx4_en
Red Hat Enterprise Linux: New kmod-mlx4_en packages are now available for Red Hat Enterprise Linux 6.
RHEA-2014:1665-1: gcc enhancement update
Red Hat Enterprise Linux: Updated gcc packages that add one enhancement are now available for Red Hat
Enterprise Linux 6 Extended Update Support.
RHBA-2014:1666-1: gcc enhancement update
Red Hat Enterprise Linux: Updated gcc packages that add one enhancement are now available for Red Hat
Enterprise Linux 6.
CVE-2014-8365
Multiple cross-site scripting (XSS) vulnerabilities in Xornic Contact Us allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) email parameter to contact.php or (3) PATH_INFO to setup.php, related to the “PHP_SELF” variable.
CVE-2014-3863
Cross-site scripting (XSS) vulnerability in the JChatSocial component before 2.3 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the filename parameter in a file upload in an active JChat chat window.
CVE-2014-8366
SQL injection vulnerability in openSIS 4.5 through 5.3 allows remote attackers to execute arbitrary SQL commands via the Username and password to index.php.