Lynis is an auditing tool for Unix (specialists). It scans the system and available software to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes. This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems.
Monthly Archives: February 2017
FireHOL 3.1.3
FireHOL a simple yet powerful way to configure stateful iptables firewalls. It can be used for almost any purpose, including control of any number of internal/external/virtual interfaces, control of any combination of routed traffic, setting up DMZ routers and servers, and all kinds of NAT. It provides strong protection (flooding, spoofing, etc.), transparent caches, source MAC verification, blacklists, whitelists, and more. Its goal is to be completely abstracted and powerful but also easy to use, audit, and understand.
QEMU Host Filesystem Arbitrary Access
QEMU has an issue where virtfs permits a guest to access the entire host filesystem.
Adobe Flash MP4 AMF Parsing Overflow
Adobe Flash suffers from an overflow vulnerability during MP4 AMF parsing.
Adobe Flash YUVPlane Decoding Heap Overflow
Adobe Flash suffers from a heap overflow vulnerability during YUVPLane decoding.
Adobe Flash SWF Stack Corruption
Adobe Flash suffers from a stack corruption vulnerability using a fuzzed SWF file.
Adobe Flash Bitmapfilter Use-After-Free
Adobe Flash suffers from a use-after-free vulnerability in applying bitmapfilter.
Google Chrome Download Filetype Blacklist Bypass
Google Chrome suffers from a bypass vulnerability in the download filetype blacklist functionality. Versions 54.0.2840.100 stable is affected.
Cisco ASA WebVPN CIFS Handling Buffer Overflows
Cisco ASA WebVPN CIFS handling buffer overflow conditions have been discovered.
GDI GDI32!ConvertDxArray Insufficient Bounds Check
GDI suffers from an insufficient bounds check on GDI32!ConvertDxArray.