Core Security Technologies Advisory – TP-LINK TDDP suffers from buffer overflow and missing authentication vulnerabilities.
Monthly Archives: November 2016
Red Hat Security Advisory 2016-2815-01
Red Hat Security Advisory 2016-2815-01 – Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system with a Ceph management platform, deployment utilities, and support services. The following packages have been upgraded to a newer upstream version: ceph, ceph-deploy, calamari-server, nfs-ganesha, ceph-iscsi-config, libntirpc, ceph-iscsi-tools. Multiple security issues have been addressed.
Red Hat Security Advisory 2016-2816-01
Red Hat Security Advisory 2016-2816-01 – Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system with a Ceph management platform, deployment utilities, and support services. The following packages have been upgraded to a newer upstream version: ceph, ceph-deploy, calamari-server, nfs-ganesha, ceph-iscsi-config, libntirpc, ceph-iscsi-tools. Security Fix: A flaw was found in the way Ceph Object Gateway handles POST object requests. An authenticated attacker could launch a denial of service attack by sending null or specially crafted POST object requests.
Microsoft Internet Explorer 8 8 MSHTML SRunPointer::SpanQualifier/RunType Out-Of-Bounds Read
A specially crafted web-page can cause Microsoft Internet Explorer 8 to attempt to read data beyond the boundaries of a memory allocation. The issue does not appear to be easily exploitable.
EasyPHP Devserver 16.1.1 Cross Site Request Forgery / Remote Command Execution
EasyPHP Devserver version 16.1.1 suffers from cross site request forgery and remote code execution vulnerabilities.
Crestron AM-100 1.2.1 Path Traversal / Hard-Coded Credentials
Crestron AM-100 versions 1.1.1.11 through 1.2.1 suffer from hard-coded credential and path traversal vulnerabilities.
Huawei UTPS UTPS-V200R003B015D16SPC00C983 Privilege Escalation
Huawei UTPS software version UTPS-V200R003B015D16SPC00C983 suffers from an unquoted service path privilege escalation vulnerability.
xen-4.5.5-4.fc23
xen : various security flaws (#1397383)
x86 null segments not always treated as unusable [XSA-191, CVE-2016-9386]
x86 task switch to VM86 mode mis-handled [XSA-192, CVE-2016-9382]
x86 segment base write emulation lacking canonical address checks [XSA-193,
CVE-2016-9385]
x86 64-bit bit test instruction emulation broken [XSA-195, CVE-2016-9383]
x86 software interrupt injection mis-handled [XSA-196, CVE-2016-9377,
CVE-2016-9378]
qemu incautious about shared ring processing [XSA-197, CVE-2016-9381]
delimiter injection vulnerabilities in pygrub [XSA-198, CVE-2016-9379,
CVE-2016-9380]
Linux Reboot Shellcode
89 bytes small /bin/sh -c reboot shellcode for Linux.
Acunetix 10.0 DLL Hijacking
Acunetix version 10 suffers from multiple dll hijacking vulnerabilities.