Ubuntu Security Notice 5497-1 - It was discovered that Libjpeg6b was not properly performing bounds checks when compressing PPM and Targa image files. An attacker could possibly use this issue to cause a denial of service. Chijin Zhou discovered that Libjpeg6b was incorrectly handling the EOF character in input data when generating JPEG files. An attacker could possibly use this issue to force the execution of a large loop, force excessive memory consumption, and cause a denial of service.
b47ca684bbef0111c47f1ad4e5fd9948b894f84cf2a3bf283167bc4a0bfa0019
Ubuntu Security Notice 5496-1 - Mike Stroyan discovered that cloud-init could log password hashes when reporting schema failures. An attacker with access to these logs could potentially use this to gain user credentials.
e4cd80abff22f10cba13421606ac85772c273db6fa0a4dc234b9c49cf19f4651
Blue Team Training Toolkit (BT3) is an attempt to introduce improvements in current computer network defense analysis training. Based on adversary replication techniques, and with reusability in mind, BT3 allows individuals and organizations to create realistic computer attack scenarios, while reducing infrastructure costs, implementation time and risk. The Blue Team Training Toolkit is written in Python, and it includes the latest versions of Encripto's Maligno and Pcapteller.
39b24206653dbb67f70c0b9529ff7524fecc1226fe682a0fc729b46dba16a034
Backdoor.Win32.Coredoor.10.a malware suffers from an authentication bypass vulnerability.
055d74c98fd4886a4ab9e17cd07e71ac4ac4ad467f97fde9461333c1c7f00d4b
Backdoor.Win32.EvilGoat.b malware suffers from a hardcoded credential vulnerability.
19ef0671c05c0afcf2c8bf3c081a0188020bbea1b901243ff9829edcb89199ff
Backdoor.Win32.Cafeini.b malware suffers from a hardcoded credential vulnerability.
214a018ddc8a2c372d96a47976e8c26f81dd4d2ccb905c570b6443c8eca58854
launchd suffers from a heap corruption vulnerability due to incorrect rounding in launch_data_unpack.
5728e5ebf948c4d9fcd1bcdca177b71ce40167df17cbb2d5d1900427d642880f