Product Asterisk
Summary Remote Crash Vulnerability in WebSocket Server
Nature of Advisory Denial of Service
Susceptibility Remote Unauthenticated Sessions
Severity Moderate…
This module enables you to use Moip (a Brazilian payment method) with Drupal Commerce.
The module doesn’t sufficiently filter the data passed by the automatic notifications, leaving the possibility for a malicious user to insert Cross Site Scripting (xss) attacks.
This vulnerability is mitigated by the fact that only sites running the dblog module are affected (this module is enabled by default).
CVE identifier(s) issued
A CVE identifier will be requested, and added upon issuance, in accordance
with Drupal Security Team processes.
Versions affected
Moip 7.x-1.x versions prior to 7.x-1.4.
Drupal core is not affected. If you do not use the contributed MoIP module,
there is nothing you need to do.
Solution
Install the latest version:
If you use the Moip module for Drupal 7.x, upgrade to Moip 7.x-1.4
This module enables you to execute arbitrary Javascript by adding the script to the title of a node.
The module doesn’t sufficiently sanitize Watchdog messages when viewing the detail view of a specific Watchdog notification. It improperly translated the message rather than using proper Watchdog message syntax.
This vulnerability is mitigated by the fact that an attacker must have a role allowing them to create nodes or edit the title of an existing node. It is further mitigated in that the script is only executed by admins when viewing a Watchdog notice when using dblog module (syslog users are not affected).
CVE identifier(s) issued
A CVE identifier will be requested, and added upon issuance, in accordance
with Drupal Security Team processes.
Versions affected
Godwin’s Law 7.x-1.0.
Drupal core is not affected. If you do not use the contributed Godwin’s Law module,
there is nothing you need to do.
Solution
Install the latest version:
If you use the Godwin’s Law module for Drupal 7.x, upgrade to Godwin’s Law 7.x-1.1
Some domain name server (DNS) implementations are at risk for denial-of-service attacks after a vulnerability was disclosed and patched in a few popular server packages, including BIND, PowerDNS and NLnetLabs.
The attackers behind the Red October APT campaign that was exposed nearly two years ago have resurfaced with a new campaign that is targeting some of the same victims and using similarly constructed tools and spear phishing emails. Red October emerged in January 2013 and researchers found that the attackers were targeting diplomats in some […]
Latest, and possibly earlier versions of K7Sentry.sys kernel mode driver, also named as the ‘K7AV Sentry DeviceDriver’,
suffers from a Out-of-bounds Write condition that…
Latest and possibly earlier versions of K7Sentry.sys kernel mode driver, also named as the ‘K7AV Sentry Device Driver’,
allows any local user to crash the system by…
From passwords and the Internet of Everything to nation-state cyber warfare and jumping mobile malware, WatchGuard helps you gain some security perspective for 2015
Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.