Red Hat Enterprise Linux: Updated jboss-ec2-eap packages that add an enhancement are now available for Red
Hat JBoss Enterprise Application Platform 6.3.2 on Red Hat Enterprise Linux 6.
Monthly Archives: November 2014
CVE-2014-2667
Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value. (CVSS:3.3) (Last Update:2014-11-17)
Vuln: Linux Kernel LZO Implementation 'lzo1x_decompress_safe.c' Memory Corruption Vulnerability
Linux Kernel LZO Implementation ‘lzo1x_decompress_safe.c’ Memory Corruption Vulnerability
Vuln: Linux Kernel 'ceph/auth_x.c' Buffer Overflow Vulnerability
Linux Kernel ‘ceph/auth_x.c’ Buffer Overflow Vulnerability
Vuln: HP System Management Homepage CVE-2014-2641 Unspecified Cross Site Request Forgery Vulnerability
HP System Management Homepage CVE-2014-2641 Unspecified Cross Site Request Forgery Vulnerability
Vuln: Linux Kernel CVE-2014-3153 Local Privilege Escalation Vulnerability
Linux Kernel CVE-2014-3153 Local Privilege Escalation Vulnerability
xdg-open RCE
Posted by joernchen on Nov 14
Hi,
I just ran into some RCE issue with xdg-open today and figured it’s known
and unfixed since 2013-06-10 [0] (respectively 2013-07-07 upstream [1])
As apparently noone cares about this I just leave a silly PoC [3]
(should work with Chromium on Arch/Gentoo Linux) here. Additional
requirement is a Window Manager which is _NOT_ one of the following:
* KDE
* GNOME
* MATE
* XFCE
* ENLIGHTENMENT
Cheers,
joernchen
[0]…
Re: Bypass Google Open Redirect Filter Based on Googleads.g.doubleclick.net
Posted by Nick Semenkovich on Nov 14
One of the cuter things I saw today was an “I’m Feeling Lucky” +
unique search term trick.
e.g. https://www.google.com/#&q=SomeUniqueLongStringHere&btnI=denoqa
(Specifically the string “uhcjljmguohkmywgylmin” I imagine this’ll be
adapted for some slightly more believable phishing URLs.)