The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory. (CVSS:4.6) (Last Update:2016-08-03)
Monthly Archives: August 2016
CVE-2016-1238
(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan/IO-Compress/bin/zipdetails, (13) cpan/JSON-PP/bin/json_pp, (14) cpan/Test-Harness/bin/prove, (15) dist/ExtUtils-ParseXS/lib/ExtUtils/xsubpp, (16) dist/Module-CoreList/corelist, (17) ext/Pod-Html/bin/pod2html, (18) utils/c2ph.PL, (19) utils/h2ph.PL, (20) utils/h2xs.PL, (21) utils/libnetcfg.PL, (22) utils/perlbug.PL, (23) utils/perldoc.PL, (24) utils/perlivp.PL, and (25) utils/splain.PL in Perl 5.x before 5.22.3-RC2 and 5.24 before 5.24.1-RC2 do not properly remove . (period) characters from the end of the includes directory array, which might allow local users to gain privileges via a Trojan horse module under the current working directory. (CVSS:7.2) (Last Update:2016-08-03)
Vuln: OpenSSL 'crypto/bio/b_print.c' Denial of Service Vulnerability
OpenSSL ‘crypto/bio/b_print.c’ Denial of Service Vulnerability
Vuln: OpenSSL CVE-2015-3197 Security Bypass Vulnerability
OpenSSL CVE-2015-3197 Security Bypass Vulnerability
ACSC Releases Risk Mitigation Strategies Against Malicious Email
Original release date: August 01, 2016
The Australian Cyber Security Centre (ACSC) has published guidance to organizations on risks posed by malicious email. Systems infected through targeted email phishing campaigns act as an entry point for attackers to spread throughout an organization’s entire enterprise, steal sensitive business or personal information, or disrupt business operations.
US-CERT encourages users and administrators to review the ACSC publication on Malicious Email Mitigation Strategies and US-CERT Alert TA15-213A for additional information.
This product is provided subject to this Notification and this Privacy & Use policy.
Google Domain Enables HSTS Protection
Google ensures HTTPS connections to its domains with support for HTTP Strict Transport Security, or HSTS.
Bugtraq: Car CMS v3.00.30 – Search Cross Site Scripting Vulnerability
Car CMS v3.00.30 – Search Cross Site Scripting Vulnerability
Bugtraq: Kaspersky Safe Browser iOS Application – MITM SSL Certificate Vulnerability (CVE-2016-6231)
Kaspersky Safe Browser iOS Application – MITM SSL Certificate Vulnerability (CVE-2016-6231)
Bugtraq: Cross-Site Request Forgery in ALO EasyMail Newsletter WordPress Plugin
Cross-Site Request Forgery in ALO EasyMail Newsletter WordPress Plugin
Bugtraq: [CVE-2016-6480] Double-Fetch Vulnerability in Linux-4.5/drivers/scsi/aacraid/commctrl.c
[CVE-2016-6480] Double-Fetch Vulnerability in Linux-4.5/drivers/scsi/aacraid/commctrl.c