Ubuntu Security Notice 3048-1 – Bru Rom discovered that curl incorrectly handled client certificates when resuming a TLS session. It was discovered that curl incorrectly handled client certificates when reusing TLS connections. Marcelo Echeverria and Fernando Munoz discovered that curl incorrectly reused a connection struct, contrary to expectations. This issue only applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. Various other issues were also addressed.
Monthly Archives: August 2016
Navis WebAccess SQL Injection
Navis WebAccess Express version suffers from a remote SQL injection vulnerability.
WebNMS Framework 5.2 SP1 Traversal / Weak Obfuscation / User Impersonation
WebNMS Framework versions 5.2 and 5.2 SP1 suffer from directory traversal, code execution, weak obfuscation, and user impersonation vulnerabilities.
Breach Forces Password Change on Oracle MICROS PoS Customers
Oracle warns its MICROS point-of-sale system customers to change account passwords after malware was discovered on a support site that was infecting users.
RSA Authentication Manager Insecure Direct Object Reference
RSA AM Prime Self-Service Portal could allow a malicious authenticated user (attacker) to replace his/her token serial number in a PIN change request with the token serial number of a victim user, which may change the PIN of the victim user to the PIN value specified by the attacker in the PIN change request. This may also deny victim?s access to the system. Versions 3.0 and 3.1 prior to build version 1915 are affected.
Debian Security Advisory 3644-1
Debian Linux Security Advisory 3644-1 – Tobias Stoeckmann discovered that cache files are insufficiently validated in fontconfig, a generic font configuration library. An attacker can trigger arbitrary free() calls, which in turn allows double free attacks and therefore arbitrary code execution. In combination with setuid binaries using crafted cache files, this could allow privilege escalation.
First-Ever Ransomware For Smart Thermostat is Here — It's Hot!
Internet of Things (IoT) is the latest buzz in the world of technology, but they are much easier to hack than you think.
Until now we have heard many scary stories of hacking IoT devices, but how realistic is the threat?
Just think of a scenario where you enter in your house, and it’s sweltering, but when you head on to check the temperature of your thermostat, you find out that it has been
![]()
Bugtraq: [slackware-security] stunnel (SSA:2016-219-04)
[slackware-security] stunnel (SSA:2016-219-04)
Bugtraq: vBulletin <= 5.2.2 Preauth Server Side Request Forgery (SSRF)
vBulletin <= 5.2.2 Preauth Server Side Request Forgery (SSRF)
Bugtraq: phpCollab v2.5 CMS – SQL Injection Vulnerability
phpCollab v2.5 CMS – SQL Injection Vulnerability
