Security News

Vuln: OpenAFS CVE-2018-16949 Multiple Denial of Service Vulnerabilities

Security Focus Vulnerabilities - 10 September, 2019 - 23:00
OpenAFS CVE-2018-16949 Multiple Denial of Service Vulnerabilities

Bugtraq: [SECURITY] [DSA 4269-1] postgresql-9.6 security update

Security Focus Vulnerabilities - 5 min 26 sec ago
[SECURITY] [DSA 4269-1] postgresql-9.6 security update

Bugtraq: [SECURITY] [DSA 4268-1] openjdk-8 security update

Security Focus Vulnerabilities - 5 min 26 sec ago
[SECURITY] [DSA 4268-1] openjdk-8 security update

Bugtraq: [SECURITY] [DSA 4267-1] kamailio security update

Security Focus Vulnerabilities - 5 min 26 sec ago
[SECURITY] [DSA 4267-1] kamailio security update

Bugtraq: [CVE-2018-12584] Heap overflow vulnerability in reSIProcate through 1.10.2

Security Focus Vulnerabilities - 5 min 26 sec ago
[CVE-2018-12584] Heap overflow vulnerability in reSIProcate through 1.10.2

More rss feeds from SecurityFocus

Security Focus Vulnerabilities - 5 min 26 sec ago
News, Infocus, Columns, Vulnerabilities, Bugtraq ...

[slackware-security] httpd (SSA:2019-022-01)

Bug Traq - 23 January, 2019 - 02:40

Posted by Slackware Security Team on Jan 22

[slackware-security] httpd (SSA:2019-022-01)

New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to
fix security issues.

Here are the details from the Slackware 14.2 ChangeLog:
+--------------------------+
patches/packages/httpd-2.4.38-i586-1_slack14.2.txz: Upgraded.
This release contains security fixes and improvements.
mod_session: mod_session_cookie does not respect expiry time allowing
sessions to be...

CVE-2018-13042 - 1Password Android < 7.0 - Denial Of Service

Bug Traq - 23 January, 2019 - 01:14

Posted by Valerio Brussani on Jan 22

############
Description
############

The 1Password application < 7.0 for Android is affected by a Denial Of
Service vulnerability. By starting the activity
com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or
com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity from an
external application (since they are exported), it is possible to crash the
1Password instance.

############
Poc
############

To invoke the...

APPLE-SA-2019-1-22-4 tvOS 12.1.2

Bug Traq - 23 January, 2019 - 01:09

Posted by Apple Product Security on Jan 22

APPLE-SA-2019-1-22-4 tvOS 12.1.2

tvOS 12.1.2 is now available and addresses the following:

AppleKeyStore
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: A sandboxed process may be able to circumvent sandbox
restrictions
Description: A memory corruption issue was addressed with improved
validation.
CVE-2019-6235: Brandon Azad

CoreAnimation
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: A malicious application...

APPLE-SA-2019-1-22-3 watchOS 5.1.3

Bug Traq - 23 January, 2019 - 01:09

Posted by Apple Product Security on Jan 22

APPLE-SA-2019-1-22-3 watchOS 5.1.3

watchOS 5.1.3 is now available and addresses the following:

AppleKeyStore
Available for: All Apple Watch models
Impact: A sandboxed process may be able to circumvent sandbox
restrictions
Description: A memory corruption issue was addressed with improved
validation.
CVE-2019-6235: Brandon Azad

Core Media
Available for: All Apple Watch models
Impact: A malicious application may be able to elevate privileges...

APPLE-SA-2019-1-22-2 macOS Mojave 10.14.3, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra

Bug Traq - 23 January, 2019 - 01:08

Posted by Apple Product Security on Jan 22

APPLE-SA-2019-1-22-2 macOS Mojave 10.14.3,
Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra

macOS Mojave 10.14.3, Security Update 2019-001 High Sierra,
Security Update 2019-001 Sierra are now available
and addresses the following:

AppleKeyStore
Available for: macOS Mojave 10.14.2
Impact: A sandboxed process may be able to circumvent sandbox
restrictions
Description: A memory corruption issue was addressed with improved...

APPLE-SA-2019-1-22-5 Safari 12.0.3

Bug Traq - 23 January, 2019 - 01:03

Posted by Apple Product Security on Jan 22

APPLE-SA-2019-1-22-5 Safari 12.0.3

Safari 12.0.3 is now available and addresses the following:

Safari Reader
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, and
macOS Mojave 10.14.3
Impact: Processing maliciously crafted web content may lead to a
cross site scripting attack
Description: A cross-site scripting issue existed in Safari. This
issue was addressed with improved URL validation.
CVE-2019-6228: Ryan Pickren...

APPLE-SA-2019-1-22-6 iCloud for Windows 7.10

Bug Traq - 23 January, 2019 - 00:58

Posted by Apple Product Security on Jan 22

APPLE-SA-2019-1-22-6 iCloud for Windows 7.10

iCloud for Windows 7.10 is now available and addresses the following:

SQLite
Available for: Windows 7 and later
Impact: A maliciously crafted SQL query may lead to arbitrary code
execution
Description: Multiple memory corruption issues were addressed with
improved input validation.
CVE-2018-20346: Tencent Blade Team
CVE-2018-20505: Tencent Blade Team
CVE-2018-20506: Tencent Blade Team

WebKit...

APPLE-SA-2019-1-22-1 iOS 12.1.3

Bug Traq - 23 January, 2019 - 00:54

Posted by Apple Product Security on Jan 22

APPLE-SA-2019-1-22-1 iOS 12.1.3

iOS 12.1.3 is now available and addresses the following:

AppleKeyStore
Available for: iPhone 5s and later, iPad Air and later, and iPod
touch 6th generation
Impact: A sandboxed process may be able to circumvent sandbox
restrictions
Description: A memory corruption issue was addressed with improved
validation.
CVE-2019-6235: Brandon Azad

Bluetooth
Available for: iPhone 5s and later, iPad Air and later, and iPod...

Vuln: Tridium Niagara Directory Traversal and Authentication-Bypass Vulnerabilities

Security Focus Vulnerabilities - 23 January, 2019 - 00:00
Tridium Niagara Directory Traversal and Authentication-Bypass Vulnerabilities

Vuln: Oracle Java SE CVE-2019-2426 Information Disclosure Vulnerability

Security Focus Vulnerabilities - 23 January, 2019 - 00:00
Oracle Java SE CVE-2019-2426 Information Disclosure Vulnerability

Vuln: Oracle Java SE CVE-2019-2422 Information Disclosure Vulnerability

Security Focus Vulnerabilities - 23 January, 2019 - 00:00
Oracle Java SE CVE-2019-2422 Information Disclosure Vulnerability

[Several CVE]: NUUO CMS - multiple vulnerabilities resulting in unauth RCE

Full Disclosure - 22 January, 2019 - 13:12

Posted by Pedro Ribeiro on Jan 22

Hi,

In October 2018, ICS-CERT issued an advisory for Nuuo CMS:
https://ics-cert.us-cert.gov/advisories/ICSA-18-284-02

Long story short, Nuuo CMS contained several vulnerabilities that allow
an unauthenticated attacker (up to version 2.3) or an authenticated
attacker (up to version 3.5) to achieve RCE, download arbitrary files, etc.

Disclosure on this one took near TWO YEARS. And even after Nuuo saying
they have fixed everything, they clearly...

CA20190117-01: Security Notice for CA Service Desk Manager

Full Disclosure - 22 January, 2019 - 13:12

Posted by Kevin Kotas via Fulldisclosure on Jan 22

CA20190117-01: Security Notice for CA Service Desk Manager

Issued: January 17, 2019
Last Updated: January 17, 2019

CA Technologies Support is alerting customers to multiple potential
risks with CA Service Desk Manager. Multiple vulnerabilities exist
that can allow a remote attacker to access sensitive information or
possibly gain additional privileges. CA published solutions to
address the vulnerabilities.

The first vulnerability,...

Call For Paper - leHACK - July 6th - July 7th, 2019

Full Disclosure - 22 January, 2019 - 13:12

Posted by Hackira via Fulldisclosure on Jan 22

The whole HZV team wishes you a happy new year !

Hello everyone,

For the first edition, leHACK will be held at la Cité des Sciences et de l'Industire, in Paris, on July 6 & 7 2019.

Since our community and the team enjoyed the site from the last year, it wasn't hard to pick a location, which hosted
la Nuit du Hack last year.

This year again will be at your disposal : a 3 level mezzanine, a 900 seats amphitheater, 2000m2 area...
Syndicate content