what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 20 of 20 RSS Feed

Files Date: 2013-11-12 to 2013-11-13

Red Hat Security Advisory 2013-1514-01
Posted Nov 12, 2013
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2013-1514-01 - Red Hat Satellite is a systems management tool for Linux-based infrastructures. It allows for provisioning, monitoring, and remote management of multiple Linux deployments with a single, centralized tool. The spacewalk-java packages contain the code for the Java version of the Spacewalk Web site. It was found that the web interface provided by Red Hat Satellite to create the initial administrator user was not disabled after the initial user was created. A remote attacker could use this flaw to create an administrator user with credentials they specify. This user could then be used to assume control of the Satellite server.

tags | advisory, java, remote, web
systems | linux, redhat
advisories | CVE-2013-4480
SHA-256 | 203782e1514ae70173db7465aa34b5d32fbd6c9a309ccfdb367d261433757054
Ubuntu Security Notice USN-2028-1
Posted Nov 12, 2013
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 2028-1 - James Forshaw discovered that Apache XML Security for Java incorrectly validated CanonicalizationMethod parameters. An attacker could use this flaw to spoof XML signatures.

tags | advisory, java, spoof
systems | linux, ubuntu
advisories | CVE-2013-2172
SHA-256 | 88523e4f3d0fedc681e3244a1828a96d2b3216fd12a178efcd46a81d5a07f83b
Troopers 14 Call For Papers
Posted Nov 12, 2013
Site troopers.de

Call For Papers for Troopers 2014 - The conference will be held in Heidelberg, Germany from March 19th through the 20th, 2014.

tags | paper, conference
SHA-256 | 56f21dc8abad7c1716e0a2a0e1512a411dcb020a50803e22d53460baf99135f5
Microsoft CryptoAPI / Outlook 2007-2013 Design Bug
Posted Nov 12, 2013
Authored by Alexander Klink

A design bug in X.509 certificate chain validation (RFC 3280) allows attackers to trigger (blind) HTTP requests for both external as well as internal IPs if a specially-crafted, S/MIME-signed email is opened in Microsoft Outlook. This issue, which has been originally reported in 2008, has been revisited and timing differences make it possible to identify open and closed ports on internal networks.

tags | advisory, web
advisories | CVE-2013-3870
SHA-256 | 9365e6ebb217675995930a39307adaa0068c69e67328ec203f67fb4ba9ac8f00
Microsoft Security Bulletin Release For November, 2013
Posted Nov 12, 2013
Site microsoft.com

This bulletin summary lists 8 released Microsoft security bulletins for November, 2013.

tags | advisory
SHA-256 | 2d5e42d213add7e7ac2fa2c2f036b27a1cd22dd1d34b18e03052b4e6d42b7bc9
Red Hat Security Advisory 2013-1513-01
Posted Nov 12, 2013
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2013-1513-01 - Red Hat Network Satellite is a systems management tool for Linux-based infrastructures. It allows for provisioning, monitoring, and remote management of multiple Linux deployments with a single, centralized tool. The rhn-java-sat packages contain the code for the Java version of the Red Hat Network Satellite Web site. It was found that the web interface provided by Red Hat Network Satellite to create the initial administrator user was not disabled after the initial user was created. A remote attacker could use this flaw to create an administrator user with credentials they specify. This user could then be used to assume control of the Satellite server.

tags | advisory, java, remote, web
systems | linux, redhat
advisories | CVE-2013-4480
SHA-256 | 6ce9f5234df93768d0306076740eb3189bc26545649424450d072d5f7cdb7b94
Ubuntu Security Notice USN-2027-1
Posted Nov 12, 2013
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 2027-1 - Tomas Jamrisko discovered that SPICE incorrectly handled long passwords in SPICE tickets. An attacker could use this issue to cause the SPICE server to crash, resulting in a denial of service.

tags | advisory, denial of service
systems | linux, ubuntu
advisories | CVE-2013-4282
SHA-256 | c9a1b85789ee48c343136198d9874457809c8249c234fe57da71674af1ccd40b
IJG jpeg6b / libjpeg-turbo Uninitialized Memory
Posted Nov 12, 2013
Authored by Michal Zalewski | Site lcamtuf.coredump.cx

jpeg6b and some of its optimized clones (e.g., libjpeg-turbo) will use uninitialized memory when decoding images with missing SOS data for the luminance component (Y) in presence of valid chroma data (Cr, Cb).

tags | advisory
advisories | CVE-2013-6629, CVE-2013-6630
SHA-256 | 75281af87c2ac01e67120a1b37a4356f62199b948183ba8069556c239c29df05
ZoneDirector Code Injection
Posted Nov 12, 2013
Authored by Ruckus Product Security Team

A vulnerability has been discovered in ZoneDirector controllers (ZD) which may allow an attacker to inject malicious code via controller's admin web interface. The attacker needs access to an authenticated admin session with ZD's web interface for carrying out this attack. Affected software includes versions 9.3.x, 9.4.x, 9.5.x, and 9.6.x.

tags | advisory, web
SHA-256 | 62b972e7d6dbdf0c5f635f6e3a470a83f15461c4159ea625712a0156763d1448
VideoSpirit Lite 1.77 SEH Buffer Overflow
Posted Nov 12, 2013
Authored by metacom

VideoSpirit Lite version 1.77 SEH buffer overflow exploit that creates a malicious visprj file.

tags | exploit, overflow
SHA-256 | 2f806a028ae096fc6978400a3bb237a786e0fd936ec797193b1477ea38199e0e
VideoSpirit Pro 1.90 SEH Buffer Overflow
Posted Nov 12, 2013
Authored by metacom

VideoSpirit Pro version 1.90 SEH buffer overflow exploit that creates a malicious visprj file.

tags | exploit, overflow
SHA-256 | a4beddfaf1f6831e6f2c80bbfc01786426cd51012e8ab075533aca32a1b80b73
Fortianalyzer VM / Appliance 5.0.4 Cross Site Request Forgery
Posted Nov 12, 2013
Authored by William Costa

Fortianalyzer VM / appliance version 5.0.4 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | 34682053137037ed3f4ef50b114b8970e4f9d3260db32fdcb688f63e62a68a0b
ALLPlayer 5.6.2 SEH Buffer Overflow
Posted Nov 12, 2013
Authored by metacom, Mike Czumak

ALLPlayer version 5.6.2 SEH buffer overflow exploit that creates a malicious .m3u file.

tags | exploit, overflow
SHA-256 | 63cb1b6c0aa914118e2ef155698d941f056884e847fc41d16545171a90dd5421
JunOS 11.4 Cross Site Scripting
Posted Nov 12, 2013
Authored by Andrea Bodei | Site A2secure.com

JunOS versions up to 11.4 (and possibly 12.1 and 12.3) suffer from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 69df81c751f416b7a8cb49c8a7c3377e212652b38602d1040877384fc67bc501
Plogue Sforzando 1.665 Buffer Overflow
Posted Nov 12, 2013
Authored by Mike Czumak

Plogue Sforzando version 1.665 SEH buffer overflow proof of concept exploit.

tags | exploit, overflow, proof of concept
SHA-256 | 5030ed687af9d04851f73881c1da274f56fa8d602554018f4dbaa86bbdcd6d32
Beleth SSH Password Auditing Tool
Posted Nov 12, 2013
Authored by stderr | Site chokepoint.net

Beleth is a fast multi-threaded SSH password auditing tool. It out performs Ncrack and THC-Hydra in speed.

tags | tool, cracker
SHA-256 | 5174a1c94e6dfd742ba77e3649c4ef3caf16d50b2648337abc9629e9d4698c33
WordPress Theme Kernel Shell Upload
Posted Nov 12, 2013
Authored by Black Devils | Site metasploit.com

This Metasploit module exploits a vulnerability found in WP Theme Kernel. By abusing the upload-handler.php file, a malicious user can upload a file to a temp directory without authentication, which results in arbitrary code execution.

tags | exploit, arbitrary, kernel, php, code execution
SHA-256 | 65f4c2c31ec8c1ea7ff40deb824d16c64f3f052a6e9c1a8ec1c3ec1f1cea8157
WordPress Curvo Theme Shell Upload
Posted Nov 12, 2013
Authored by Black Devils | Site metasploit.com

This Metasploit module exploits a vulnerability found in WP Curvo Theme. By abusing the upload-handler.php file, a malicious user can upload a file to a temp directory without authentication, which results in arbitrary code execution.

tags | exploit, arbitrary, php, code execution
SHA-256 | d2ee43b614a91e7fe733a6895cce75fdf5c2fd765821db8e7fc6e30e8a2031f4
Provj 5.1.5.8 Buffer Overflow
Posted Nov 12, 2013
Authored by Necmettin COSKUN

Provj version 5.1.5.8 buffer overflow proof of concept denial of service exploit that generates a malicious .m3u file.

tags | exploit, denial of service, overflow, proof of concept
SHA-256 | d626a6a1226f337c74ee5be74c6f00c2b96ca7dd148919a687c76ead4b265c46
Bypassing AddressSanitizer
Posted Nov 12, 2013
Authored by Eric Wimberley | Site glidersecurity.com

This paper evaluates AddressSanitizer as a next generation memory corruption prevention framework. It provides demonstrable tests of problems that are fixed, as well as problems that still exist.

tags | paper
SHA-256 | 8245bb4a3851c5b9dd116e5ce5f16365b106f7cd68233e4a4905c1d4cf4e7e8a
Page 1 of 1
Back1Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    17 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close