telnetd in Cisco IOS XR 5.0.1 on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (device reload) via a malformed TELNET packet, aka Bug ID CSCuq31566.
Monthly Archives: June 2015
CVE-2015-4182
The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or change settings, via unspecified vectors, aka Bug ID CSCui72087.
Snapchat bolsters security with optional Two-factor authentication
Snapchat has added an option for two-factor authentication in its latest update, followed in the footsteps of Apple, Twitter and Facebook.
The post Snapchat bolsters security with optional Two-factor authentication appeared first on We Live Security.
![]()
Cisco Patches IPv6 Vulnerability in Carrier-Grade Router System
Cisco patched a denial of service vulnerability in its IOS XR software used in carrier-grade routers.
FreeBSD Security Advisory – OpenSSL
FreeBSD Security Advisory – A vulnerability in the TLS protocol would allow a man-in-the-middle attacker to downgrade vulnerable TLS connections using ephemeral Diffie-Hellman key exchange to 512-bit export-grade cryptography. This vulnerability is also known as Logjam. When processing an ECParameters structure OpenSSL enters an infinite loop if the curve specified is over a specially malformed binary polynomial field. When verifying a signedData message the CMS code can enter an infinite loop if presented with an unknown hash function OID. Various other issues have also been addressed.
ZENWorks Mobile Management 3.1.0 Cross Site Scripting
ZENWorks Mobile Management version 3.1.0 suffers from cross site scripting vulnerabilities.
ZCMS 1.1 Cross Site Scripting / SQL Injection
ZCMS version 1.1 suffers from cross site scripting and remote SQL injection vulnerabilities.
Slackware Security Advisory – php Updates
Slackware Security Advisory – New php packages are available for Slackware 14.0, 14.1, and -current to fix security issues.
Slackware Security Advisory – openssl Updates
Slackware Security Advisory – New openssl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues.