Red Hat Security Advisory 2014-1244-01 – The Berkeley Internet Name Domain is an implementation of the Domain Name System protocols. It contains a DNS server, a resolver library with routines for applications to use when interfacing with DNS, and tools for verifying that the DNS server is operating correctly. These packages contain version 9.7 of the BIND suite. A denial of service flaw was found in the way BIND handled queries for NSEC3-signed zones. A remote attacker could use this flaw against an authoritative name server that served NCES3-signed zones by sending a specially crafted query, which, when processed, would cause named to crash.
Category Archives: Security
Security
Red Hat Security Advisory 2014-1243-01
Red Hat Security Advisory 2014-1243-01 – Automake is a tool for automatically generating Makefile.in files compliant with the GNU Coding Standards. It was found that the distcheck rule in Automake-generated Makefiles made a directory world-writable when preparing source archives. If a malicious, local user could access this directory, they could execute arbitrary code with the privileges of the user running “make distcheck”.
Ubuntu Security Notice USN-2347-1
Ubuntu Security Notice 2347-1 – Florian Apolloner discovered that Django incorrectly validated URLs. A remote attacker could use this issue to conduct phishing attacks. David Wilson discovered that Django incorrectly handled file name generation. A remote attacker could use this issue to cause Django to consume resources, resulting in a denial of service. David Greisen discovered that Django incorrectly handled certain headers in contrib.auth.middleware.RemoteUserMiddleware. A remote authenticated user could use this issue to hijack web sessions. Various other issues were also addressed.
OSSEC 2.8 umask Clear Text Passwords
OSSEC version 2.8 inherits the umask of the user when adding cleartext passwords to the .passlist file, allowing for them to be world-readable instead of setting the permissions explicitly.
Attackers Tapping On SNMP Door To See If It's Open
Apple Takes 'Very Different View' On Customer Privacy
Julian Assange On Snowden, Disliking Google, And His "Inevitable" Freedom
Israeli Spies Rebel Over Mass-Snooping On Innocent Palestinians
CM Browser SOP Bypass
The CM browser suffers from a same-origin bypass vulnerability.