Francisco Alonso of Red Hat Product Security found an issue in the file
utility, whose code is embedded in PHP, a general-purpose scripting
language. When checking ELF files, note headers are incorrectly
checked, thus potentially allowing attackers to cause a denial of
service (out-of-bounds read and application crash) by supplying a
specially crafted ELF file.
Monthly Archives: November 2014
Zoph 0.9.1 Cross Site Scripting / SQL Injection
Zoph versions 0.9.1 and below suffer from cross site scripting and remote SQL injection vulnerabilities.
Vuln: D-Bus CVE-2014-3638 Denial of Service Vulnerability
D-Bus CVE-2014-3638 Denial of Service Vulnerability
Vuln: D-Bus CVE-2014-3639 Denial of Service Vulnerability
D-Bus CVE-2014-3639 Denial of Service Vulnerability
Vuln: Adobe Flash Player and AIR CVE-2014-0574 Double Free Remote Code Execution Vulnerability
Adobe Flash Player and AIR CVE-2014-0574 Double Free Remote Code Execution Vulnerability
WebsiteBaker 2.8.3 XSS / SQL Injection / HTTP Response Splitting
WebsiteBaker versions 2.8.3 and below suffers from cross site scripting, HTTP response splitting, and remote SQL injection vulnerabilities.
XOOPS 2.5.6 SQL Injection
XOOPS versions 2.5.6 and below suffer from a remote blind SQL injection vulnerability.
Red Hat Security Advisory 2014-1865-01
Red Hat Security Advisory 2014-1865-01 – The GNU Bourne Again shell is a shell and command language interpreter compatible with the Bourne shell. Bash is the default shell for Red Hat Enterprise Linux. Shift_JIS, also known as “SJIS”, is a character encoding for the Japanese language. This package provides bash support for the Shift_JIS encoding. It was found that the fix for CVE-2014-6271 was incomplete, and Bash still allowed certain characters to be injected into other environments via specially crafted environment variables. An attacker could potentially use this flaw to override or bypass environment restrictions to execute shell commands. Certain services and applications allow remote unauthenticated attackers to provide environment variables, allowing them to exploit this issue.
Nibbleblog 4.0.1 Cross Site Scripting
NibbleBlog versions 4.0.1 and below suffer from a cross site scripting vulnerability.
Red Hat Security Advisory 2014-1863-01
Red Hat Security Advisory 2014-1863-01 – Red Hat Subscription Asset Manager acts as a proxy for handling subscription information and software updates on client machines. Red Hat Subscription Asset Manager is built on Ruby on Rails, a model-view-controller framework for web application development. Action Pack implements the controller and the view components. A directory traversal flaw was found in the way Ruby on Rails handled wildcard segments in routes with implicit rendering. A remote attacker could use this flaw to retrieve arbitrary local files accessible to a Ruby on Rails application using the aforementioned routes via a specially crafted request.