Markus Vervier of X41 D-Sec GmbH discovered an integer overflow
vulnerability in libotr, an off-the-record (OTR) messaging library, in
the way how the sizes of portions of incoming messages were stored. A
remote attacker can exploit this flaw by sending crafted messages to an
application that is using libotr to perform denial of service attacks
(application crash), or potentially, execute arbitrary code with the
privileges of the user running the application.
Monthly Archives: March 2016
DSA-3511 bind9 – security update
Two vulnerabilites have been discovered in ISC’s BIND DNS server.
DSA-3509 rails – security update
Two vulnerabilities have been discovered in Rails, a web application
framework written in Ruby. Both vulnerabilities affect Action Pack, which
handles the web requests for Rails.
GLSA 201603-03: Roundcube: Multiple Vulnerabilities
Windows Mail Find People DLL side loading vulnerability
Posted by Securify B.V. on Mar 08
————————————————————————
Windows Mail Find People DLL side loading vulnerability
————————————————————————
Yorick Koster, September 2015
————————————————————————
Abstract
————————————————————————
A DLL side loading vulnerability was found in the Windows Mail…
Mac users get first taste of ransomware
“The main threats targeting Mac users are mostly adware, but this new threat shows that the trend may change.”

For Mac users, hell has finally frozen over. The first case of working ransomware targeting OS X was reported this past weekend.
“This is the first one in the wild that is definitely functional, encrypts your files and seeks a ransom,” said Palo Alto Threat Intelligence Director Ryan Olson in a Reuters interview. The researchers dubbed the ransomware “KeRanger.”
Ransomware has successfully attacked Windows and Android users, usually when a user is tricked into clicking an infected link in an email or an infected ad on a website. The ransomware then locks all the files in the system and demands money for a key that will unlock the files. (another good reason not to click on links in emails.)
“Any ransomware that gets onto your device, whether a Mac, PC, or smartphone, is a serious threat. Most people are scared when they see their device has been locked and their data has been encrypted so they pay the ransom,” said Jan Sirmer, a researcher from the Avast Virus Lab. “We generally advise against paying the ransom, because this rewards the malware authors for their work and encourages them to continue spreading ransom, but sometimes it can’t be helped.”
One of the most recent attacks locked up the servers of the Hollywood Presbyterian Medical Center in Los Angeles. Because their patient records are vital to hospital operation, they opted to pay $17,000 in bitcoin, the preferred digital currency of cybercrooks, to get them back. Law enforcement offices have been victims as well.
![]()
Exim 4.84-3 Local Root / Privilege Escalation
Exim versions 4.84-3 and below suffer from a local privilege escalation vulnerability.
Mozilla Releases Security Updates
Original release date: March 08, 2016
Mozilla has released security updates to address multiple vulnerabilities in Firefox and Firefox ESR. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Available updates include:
- Firefox 45
- Firefox ESR 38.7
Users and administrators are encouraged to review the Mozilla Security Advisories for Firefox and Firefox ESR and apply the necessary updates.
This product is provided subject to this Notification and this Privacy & Use policy.
Microsoft Patches Critical Vulnerabilities in its Browsers
Microsoft released 13 security bulletins, five of which it rated critical, including separate advisories patching two dozen flaws in IE and Microsoft Edge browsers.
Microsoft Releases March 2016 Security Bulletin
Original release date: March 08, 2016
Microsoft has released 13 updates to address vulnerabilities in Microsoft software. Exploitation of some of these vulnerabilities could allow a remote attacker to take control of an affected system.
US-CERT encourages users and administrators to review Microsoft Security Bulletins MS16-023 through MS16-035 and apply the necessary updates.
This product is provided subject to this Notification and this Privacy & Use policy.