|
Colapse all |
Post message
[SECURITY] [DSA 3778-1] ruby-archive-tar-minitar security update 2017-01-31 Salvatore Bonaccorso (carnil debian org) [security bulletin] HPESBGN03696 rev.1 - HPE Helion Eucalyptus, Remote Escalation of Privilege 2017-01-31 security-alert hpe com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c053828 68 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c05382868 Version: 1 HPESBGN03696 rev.1 [ more ] [ reply ] [security bulletin] HPSBHF03693 rev.1 - HPE iMC PLAT Network Products running Microsoft SQL Server, Remote Elevation of Privilege 2017-01-31 security-alert hpe com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c053827 40 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c05382740 Version: 1 HPSBHF03693 rev.1 [ more ] [ reply ] ESA-2017-007: EMC Documentum eRoom Unverified Password Change Vulnerability 2017-01-31 EMC Product Security Response Center (Security_Alert emc com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ESA-2017-007: EMC Documentum eRoom Unverified Password Change Vulnerability EMC Identifier: ESA-2017-007 CVE Identifier: CVE-2017-2766 Severity Rating: CVSS v3 Base Score: 5.7 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L) Affected products: EM [ more ] [ reply ] ESA-2016-094: RSA BSAFE Micro Edition Suite Multiple Vulnerabilities 2017-01-31 EMC Product Security Response Center (Security_Alert emc com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ESA-2016-094: RSA BSAFE® Micro Edition Suite Multiple Vulnerabilities EMC Identifier: ESA-2016-094 CVE Identifier: CVE-2016-0923, CVE-2016-0924 Affected Products: ? RSA BSAFE Micro Edition Suite (MES) all 4.1.x versions prior to 4.1.5 [ more ] [ reply ] [REVIVE-SA-2017-001] Revive Adserver - Multiple vulnerabilities 2017-01-31 Matteo Beccati (matteo beccati com) [security bulletin] HPESBMU03701 rev.1 - HPE Smart Storage Administrator, Remote Arbitrary Code Execution 2017-01-30 security-alert hpe com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c053823 49 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c05382349 Version: 1 HPESBMU03701 rev.1 [ more ] [ reply ] Secunia Research: libarchive "lha_read_file_header_1()" Out-Of-Bounds Memory Access Denial of Service Vulnerability 2017-01-30 Secunia Research (remove-vuln secunia com) secuvera-SA-2017-01: Privilege escalation in an OPSI Managed Client environment ("rise of the machines") 2017-01-30 sbieber secuvera de Persistent Cross-Site Scripting vulnerability in User Access Manager WordPress Plugin 2017-01-28 Summer of Pwnage (lists securify nl) ------------------------------------------------------------------------ Persistent Cross-Site Scripting vulnerability in User Access Manager WordPress Plugin ------------------------------------------------------------------------ Burak Kelebek, July 2016 ------------------------------------------ [ more ] [ reply ] Multiple blind SQL injection vulnerabilities in FormBuilder WordPress Plugin 2017-01-28 Summer of Pwnage (lists securify nl) ------------------------------------------------------------------------ Multiple blind SQL injection vulnerabilities in FormBuilder WordPress Plugin ------------------------------------------------------------------------ Burak Kelebek, July 2016 --------------------------------------------------- [ more ] [ reply ] CVE-2017-3160: Gradle Distribution URL used by Cordova-Android does not use https by default 2017-01-27 bowserj gmail com =================================================================== CVE-2017-3160: Gradle Distribution URL used by Cordova-Android does not use https by default Severity: High Vendor: The Apache Software Foundation Versions Affected: Cordova Android (6.1.1 and below) Description: After the Andro [ more ] [ reply ] ESA-2016-133: EMC Data Protection Advisor Path Traversal Vulnerability 2017-01-26 EMC Product Security Response Center (Security_Alert emc com) ESA-2016-154: RSA BSAFE® Crypto-J Multiple Security Vulnerabilities 2017-01-26 EMC Product Security Response Center (Security_Alert emc com) ESA-2016-037: EMC PowerPath Management Appliance Information Disclosure Vulnerability 2017-01-26 EMC Product Security Response Center (Security_Alert emc com) Secunia Research: Oracle Outside In VSDX Use-After-Free Vulnerability 2017-01-27 Secunia Research (remove-vuln secunia com) [slackware-security] mozilla-thunderbird (SSA:2017-026-01) 2017-01-27 Slackware Security Team (security slackware com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] mozilla-thunderbird (SSA:2017-026-01) New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +---------------------- [ more ] [ reply ] CA20170126-01: Security Notice for CA Common Services casrvc 2017-01-26 Kotas, Kevin J (Kevin Kotas ca com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 CA20170126-01: Security Notice for CA Common Services casrvc Issued: January 26, 2017 Last Updated: January 26, 2017 CA Technologies support is alerting customers about a medium risk vulnerability that may allow a local attacker to gain additional p [ more ] [ reply ] ESA-2016-167: EMC Documentum D2 Multiple Vulnerabilities 2017-01-26 EMC Product Security Response Center (Security_Alert emc com) ESA-2016-160: EMC Data Domain DD OS Command Injection Vulnerability 2017-01-26 EMC Product Security Response Center (Security_Alert emc com) ESA-2016-132: EMC RecoverPoint Multiple Vulnerabilities 2017-01-26 EMC Product Security Response Center (Security_Alert emc com) ESA-2016-092: RSA® Web Threat Detection Cross Site Scripting Vulnerability 2017-01-26 EMC Product Security Response Center (Security_Alert emc com) PEAR HTTP_Upload v1.0.0b3 Arbitrary File Upload 2017-01-26 apparitionsec gmail com (hyp3rlinx) [+]##################################################################### ########################### [+] Credits: John Page AKA Hyp3rlinx [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/PEAR-HTTP_UPLOAD-ARBITRARY-FI LE-UPLOAD.txt [+] ISR: ApparitionSEC [ more ] [ reply ] Google Forms WordPress Plugin unauthenticated PHP Object injection vulnerability 2017-01-25 Summer of Pwnage (lists securify nl) ------------------------------------------------------------------------ Google Forms WordPress Plugin unauthenticated PHP Object injection vulnerability ------------------------------------------------------------------------ Yorick Koster, June 2016 ----------------------------------------------- [ more ] [ reply ] Cisco Security Advisory: Cisco TelePresence Multipoint Control Unit Remote Code Execution Vulnerability 2017-01-25 Cisco Systems Product Security Incident Response Team (psirt cisco com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Cisco Security Advisory: Cisco TelePresence Multipoint Control Unit Remote Code Execution Vulnerability Advisory ID: cisco-sa-20170125-telepresence Revision 1.0 For Public Release 2017 January 25 16:00 UTC (GMT) +----------------------------------- [ more ] [ reply ] Cisco Security Advisory: Cisco Expressway Series and TelePresence VCS Denial of Service Vulnerability 2017-01-25 Cisco Systems Product Security Incident Response Team (psirt cisco com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Cisco Security Advisory: Cisco Expressway Series and TelePresence VCS Denial of Service Vulnerability Advisory ID: cisco-sa-20170125-expressway Revision 1.0 For Public Release 2017 January 25 16:00 UTC (GMT) +--------------------------------------- [ more ] [ reply ] Cisco Security Advisory: Cisco Adaptive Security Appliance CX Context-Aware Security Denial of Service Vulnerability 2017-01-25 Cisco Systems Product Security Incident Response Team (psirt cisco com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Cisco Security Advisory: Cisco Adaptive Security Appliance CX Context-Aware Security Denial of Service Vulnerability Advisory ID: cisco-sa-20170125-cas Revision 1.0 For Public Release 2017 January 25 16:00 UTC (GMT) +------------------------------- [ more ] [ reply ] |
|
Privacy Statement |
Hash: SHA512
- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3778-1 security (at) debian (dot) org [email concealed]
https://www.debian.org/security/ Salvatore Bonaccorso
January 31, 2017
[ more ] [ reply ]