Re: xdg-open RCE

Posted by Brandon Perry on Nov 17

This is very similar to this gksu bug (which only applies to gksu when in
SU_MODE)

http://savannah.nongnu.org/bugs/?40023

Attempted to email the gksu ‘maintainer’, but with no response.

Did a quick write up on the Rapid7 site on how I found out about it and the
vector I was using to exploit it:

https://community.rapid7.com/community/metasploit/blog/2014/07/07/virtualbox-filename-command-execution-via-gksu

Was assigned the following…

Reflected XSS in Nibbleblog <= v4.0.1

Posted by Manuel Garcia Cardenas on Nov 17

=============================================
MGC ALERT 2014-002
– Original release date: March 5, 2014
– Last revised: November 17, 2014
– Discovered by: Manuel Garcia Cardenas
– Severity: 4,8/10 (CVSS Base Score)
=============================================

I. VULNERABILITY
————————-
Reflected XSS in Nibbleblog <= v4.0.1

II. BACKGROUND
————————-
Nibbleblog is a powerful engine for creating blogs, all you…

XOOPS <= 2.5.6 – Blind SQL Injection

Posted by Manuel Garcia Cardenas on Nov 17

=============================================
MGC ALERT 2014-003
– Original release date: March 6, 2014
– Last revised: November 18, 2014
– Discovered by: Manuel Garcia Cardenas
– Severity: 7,1/10 (CVSS Base Score)
=============================================

I. VULNERABILITY
————————-
Blind SQL Injection in XOOPS <= 2.5.6

II. BACKGROUND
————————-
XOOPS is an acronym of “eXtensible Object Oriented…

Fedora 20 Security Update: libvirt-1.1.3.8-1.fc20

Resolved Bugs
1160823 – CVE-2014-3633 libvirt: qemu: out-of-bounds read access in qemuDomainGetBlockIoTune() due to invalid index [fedora-all]
1141131 – CVE-2014-3633 libvirt: qemu: out-of-bounds read access in qemuDomainGetBlockIoTune() due to invalid index
1160824 – CVE-2014-3657 libvirt: domain_conf: domain deadlock DoS [fedora-all]
1145667 – CVE-2014-3657 libvirt: domain_conf: domain deadlock DoS
1160822 – CVE-2014-7823 libvirt: dumpxml: information leak with migratable flag [fedora-all]
1160817 – CVE-2014-7823 libvirt: dumpxml: information leak with migratable flag<br
* Rebased to version 1.1.3.8
* CVE-2014-3633: out-of-bounds read in blockiotune (bz #1160823)
* CVE-2014-3657: Potential deadlock in domain_conf (bz #1160824)
* CVE-2014-7823: information leak with migratable flag (bz #1160822)