‼ CVE-2020-29565 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-28916 ‼
📖 Read
via "National Vulnerability Database".
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-29562 ‼
📖 Read
via "National Vulnerability Database".
The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.📖 Read
via "National Vulnerability Database".
❌ Vancouver Metro Disrupted by Egregor Ransomware ❌
📖 Read
via "Threat Post".
The attack, which prevented Translink users from using their metro cards or to buy tickets at kiosks, is the second from the prolific threat group just this week.📖 Read
via "Threat Post".
Threat Post
Vancouver Metro Disrupted by Egregor Ransomware
The attack, which prevented Translink users from using their metro cards or buying tickets at kiosks, is the second from the prolific threat group just this week.
🕴 Flash Dies but Warning Signs Persist: A Eulogy for Tech's Terrible Security Precedent 🕴
📖 Read
via "Dark Reading".
Flash will be gone by the end of the year, but the ecosystem that allowed it to become a software security serial killer is ready to let it happen again.📖 Read
via "Dark Reading".
Dark Reading
Flash Dies but Warning Signs Persist: A Eulogy for Tech's Terrible Security Precedent
Flash will be gone by the end of the year, but the ecosystem that allowed it to become a software security serial killer is ready to let it happen again.
🛠 Suricata IDPE 6.0.1 🛠
📖 Read
via "Packet Storm Security".
Suricata is a network intrusion detection and prevention engine developed by the Open Information Security Foundation and its supporting vendors. The engine is multi-threaded and has native IPv6 support. It's capable of loading existing Snort rules and signatures and supports the Barnyard and Barnyard2 tools.📖 Read
via "Packet Storm Security".
Packetstormsecurity
Suricata IDPE 6.0.1 ≈ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
❌ VMware Rolls a Fix for Formerly Critical Zero-Day Bug ❌
📖 Read
via "Threat Post".
VMware has issued a full patch and revised the severity level of the NSA-reported vulnerability to "important."📖 Read
via "Threat Post".
Threat Post
VMware Rolls a Fix for Formerly Critical Zero-Day Bug
VMware has issued a full patch and revised the severity level of the NSA-reported vulnerability to "important."
🔏 Friday Five 12/4 🔏
📖 Read
via "Digital Guardian".
Trickbot's new tricks, attacking vaccine cold chains, and CFAA in front of the Supreme Court - catch up on all of the week's infosec news with the Friday Five!📖 Read
via "Digital Guardian".
Digital Guardian
Friday Five 12/4
Trickbot's new tricks, attacking vaccine cold chains, and CFAA in front of the Supreme Court - catch up on all of the week's infosec news with the Friday Five!
‼ CVE-2020-27767 ‼
📖 Read
via "National Vulnerability Database".
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of types `float` and `unsigned char`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-27766 ‼
📖 Read
via "National Vulnerability Database".
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.8-69.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-27765 ‼
📖 Read
via "National Vulnerability Database".
A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-27771 ‼
📖 Read
via "National Vulnerability Database".
In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could result in values outside the range of representable for the unsigned char type. The patch casts the return value of GetPixelIndex() to ssize_t type to avoid this bug. This undefined behavior could be triggered when ImageMagick processes a crafted pdf file. Red Hat Product Security marked this as Low severity because although it could potentially lead to an impact to application availability, no specific impact was demonstrated in this case. This flaw affects ImageMagick versions prior to 7.0.9-0.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-27408 ‼
📖 Read
via "National Vulnerability Database".
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-27409 ‼
📖 Read
via "National Vulnerability Database".
OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-27770 ‼
📖 Read
via "National Vulnerability Database".
Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered by a crafted input file that is processed by ImageMagick. This flaw affects ImageMagick versions prior to 7.0.8-68.📖 Read
via "National Vulnerability Database".
🦿 Most used passwords for 2020: The internet's favorite curse word, name, food, and team 🦿
📖 Read
via "Tech Republic".
CyberNews analyzed more than 15 billion passwords; if your favorite one is at the top of the list, it's time to change right now.📖 Read
via "Tech Republic".
TechRepublic
Most used passwords for 2020: The internet's favorite curse word, name, food, and team
CyberNews analyzed more than 15 billion passwords; if your favorite one is at the top of the list, it's time to change right now.
🕴 Intel Doubles Down on Emerging Technologies for Sharing and Using Data Securely 🕴
📖 Read
via "Dark Reading".
Homomorphic encryption and federated learning could allow groups to share data and analysis while protecting the actual information.📖 Read
via "Dark Reading".
Dark Reading
Intel Doubles Down on Emerging Technologies for Sharing and Using Data Securely
Homomorphic encryption and federated learning could allow groups to share data and analysis while protecting the actual information.
‼ CVE-2020-25461 ‼
📖 Read
via "National Vulnerability Database".
Invalid Memory Access in the fxProxyGetter function in moddable/xs/sources/xsProxy.c in Moddable SDK before OS200908 causes a denial of service (SEGV).📖 Read
via "National Vulnerability Database".
‼ CVE-2020-25463 ‼
📖 Read
via "National Vulnerability Database".
Invalid Memory Access in fxUTF8Decode at moddable/xs/sources/xsCommon.c:916 in Moddable SDK before OS200908 causes a denial of service (SEGV).📖 Read
via "National Vulnerability Database".
‼ CVE-2020-25464 ‼
📖 Read
via "National Vulnerability Database".
Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is only partially initialized because the stack overflowed while creating the frame. This leads to a crash in the code sending the stack frame to the debugger.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-25465 ‼
📖 Read
via "National Vulnerability Database".
Null Pointer Dereference. in xObjectBindingFromExpression at moddable/xs/sources/xsSyntaxical.c:3419 in Moddable SDK before OS200908 causes a denial of service (SEGV).📖 Read
via "National Vulnerability Database".