Category Archives: Security

Security

Cisco Security Advisory 20141008-asa

Cisco Security Advisory – Cisco Adaptive Security Appliance (ASA) Software is affected by denial of service, cross site scripting, and command injection vulnerabilities. Cisco has released free software updates that address these vulnerabilities. Workarounds that mitigate some of these vulnerabilities are available.

HP Security Bulletin HPSBHF03136

HP Security Bulletin HPSBHF03136 – A potential security vulnerability has been identified with HP TippingPoint NGFW running OpenSSL. This is the OpenSSL vulnerability known as “Heartbleed” which could be exploited remotely resulting in disclosure of information. Revision 1 of this advisory.

Ubuntu Security Notice USN-2379-1

Ubuntu Security Notice 2379-1 – Steven Vittitoe reported multiple stack buffer overflows in Linux kernel’s magicmouse HID driver. A physically proximate attacker could exploit this flaw to cause a denial of service (system crash) or possibly execute arbitrary code via specially crafted devices. Ben Hawkes reported some off by one errors for report descriptors in the Linux kernel’s HID stack. A physically proximate attacker could exploit these flaws to cause a denial of service (out-of-bounds write) via a specially crafted device. Various other issues were also addressed.