Monthly Archives: May 2015
Re: Xamarin for Android <5.1 DLL Hijack Vulnerability
Posted by Tim on May 20
Thanks for posting this to FD, these didn’t even include it in their
release notes;
http://developer.xamarin.com/releases/android/xamarin.android_5/xamarin.android_5.1/
Was there a bug reported in bugzilla to link back too?
-Tim Strazzere
Re: Xamarin for Android <5.1 DLL Hijack Vulnerability
Posted by ValdikSS on May 20
They don’t have public bugtracker. Case ID is 140518.
Re: Xamarin for Android <5.1 DLL Hijack Vulnerability
Posted by Tim on May 20
Isn’t this the public bug tracker?
https://bugzilla.xamarin.com/describecomponents.cgi?product=Android
Though, correct that case id doesn’t map to anything there.
-Tim Strazzere
Re: Xamarin for Android <5.1 DLL Hijack Vulnerability
Posted by ValdikSS on May 20
I had no idea they have one. All communication with Xamarin was over email at hello () xamarin com
Re: 0-day Denial of Service in IPsec-Tools
Posted by Christos Zoulas on May 20
— Subject: [FD] 0-day Denial of Service in IPsec-Tools
| Denial of Service in IPsec-Tools
| Vulnerability Report
| May 19, 2015
|
| Product: IPsec-Tools
| Version: 0.8.2
| Website: http://ipsec-tools.sourceforge.net/
| CVSS Score: 7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C)
|
| IPsec-Tools is vulnerable to a 0-day exploit that I made available yesterday. It is a null dereference crash in
racoon in gssapi.c. It requires HAVE_GSSAPI to be set, which is…
CVE-2014-6211
The command-line scripts in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 2 through 8, when debugging is configured, do not properly restrict the logging of personal data, which allows local users to obtain sensitive information by reading a log file.
RHBA-2015:1017-1: kernel bug fix update
Red Hat Enterprise Linux: Updated kernel packages that fix several bugs are now available for Red Hat
Enterprise Linux 6.5 Extended Update Support.
RHBA-2015:1016-1: bind bug fix update
Red Hat Enterprise Linux: Updated bind packages that fix one bug are now available for Red Hat Enterprise
Linux 6.
CVE-2015-0740
Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center 10.6(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus28826.