CVE-2014-2026 Reflected Cross-Site Scripting (XSS) in “Intrexx Professional”
Monthly Archives: December 2014
Bugtraq: Vulnerabilities in Ekahau Real-Time Location Tracking System [MZ-14-01]
Vulnerabilities in Ekahau Real-Time Location Tracking System [MZ-14-01]
Bugtraq: Persistent XSS Vulnerability in CMS Papoo Light v6.0.0 Rev. 4701
Persistent XSS Vulnerability in CMS Papoo Light v6.0.0 Rev. 4701
Bugtraq: [ MDVSA-2014:253 ] apache-mod_wsgi
[ MDVSA-2014:253 ] apache-mod_wsgi
GLSA 201412-30 (Normal): varnish
Varnish: Multiple vulnerabilities
MDVSA-2014:253: apache-mod_wsgi
Updated apache-mod_wsgi package fixes security vulnerability:
It was discovered that mod_wsgi incorrectly handled errors when
setting up the working directory and group access rights. A malicious
application could possibly use this issue to cause a local privilege
escalation when using daemon mode (CVE-2014-8583).
MDVSA-2014:252: nss
Updated nss packages fix security vulnerabilities:
In the QuickDER decoder in NSS before 3.17.3, ASN.1 DER decoding of
lengths is too permissive, allowing undetected smuggling of arbitrary
data (CVE-2014-1569).
This update adds support for the TLS Fallback Signaling Cipher Suite
Value (TLS_FALLBACK_SCSV) in NSS, which can be used to prevent protocol
downgrade attacks against applications which re-connect using a lower
SSL/TLS protocol version when the initial connection indicating the
highest supported protocol version fails. This can prevent a forceful
downgrade of the communication to SSL 3.0, mitigating CVE-2014-3566,
also known as POODLE. SSL 3.0 support has also been disabled by
default in this Firefox and Thunderbird update, further mitigating
POODLE.
RHEA-2014:1993-1: coreutils Shift_JIS enhancement update
Red Hat Enterprise Linux: Updated coreutils Shift_JIS packages that add one enhancement are now available
for Red Hat Enterprise Linux 5.
RHEA-2014:1991-1: bash Shift_JIS enhancement update
Red Hat Enterprise Linux: Updated bash Shift_JIS packages that add one enhancement are now available for
Red Hat Enterprise Linux 5.
RHBA-2014:1994-1: ibus-kkc bug fix update
Red Hat Enterprise Linux: Updated ibus-kkc packages that fix one bug are now available for Red Hat
Enterprise Linux 7.