Debian Linux Security Advisory 3796-2 – CVE-2016-8743 meant being more stringent when dealing with whitespace patterns in HTTP requests, and that change broke the upload tool of sitesummary-client.
Ubuntu Security Notice USN-3238-1
Ubuntu Security Notice 3238-1 – An integer overflow was discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could exploit this to cause a denial of service via application crash or execute arbitrary code.
EMC RecoverPoint SSL Stripping
EMC RecoverPoint update contains a fix for an SSL stripping vulnerability that may potentially be exploited by malicious users to compromise the affected system. Versions prior to 5.0 are affected.
kernel-4.10.4-200.fc25
The 4.10.4 stable kernel update contains a number of important fixes across the tree. It also reverts CONFIG_CFG80211_CRDA_SUPPORT to match the previous 4.9 kernels.
—-
The 4.10.3 kernel rebase contains a number of new features, important fixes, and additional hardware support.
Re: Remote code execution via CSRF vulnerability in the web UI of Deluge 1.3.13
Posted by Thomas Deutschmann on Mar 20
I requested a CVE via MITRE web form and received the following ID:
CVE-2016-4927
Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a Space device is communicating with managed devices.
CVE-2016-4928
Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.
CVE-2016-4929
Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.
CVE-2016-4930
Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions.
CVE-2016-4926
Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to Junos Space web interface to perform certain administrative tasks without authentication.