🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2022-0685

Use of Out-of-range Pointer Offset in Conda vim prior to 8.2.

📖 Read

via "National Vulnerability Database".
CVE-2022-23053

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget� element, that allows the injection of malicious JavaScript into the ‘URL†field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

📖 Read

via "National Vulnerability Database".
CVE-2022-22126

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page� element, that allows the injection of malicious JavaScript into the ‘URL†field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

📖 Read

via "National Vulnerability Database".
CVE-2022-25372

Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go.

📖 Read

via "National Vulnerability Database".
CVE-2022-23848

In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-25375

An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory.

📖 Read

via "National Vulnerability Database".
CVE-2022-23054

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget� element, that allows the injection of malicious JavaScript into the ‘URL†field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

📖 Read

via "National Vulnerability Database".
CVE-2022-25297

This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designated target folder.

📖 Read

via "National Vulnerability Database".
CVE-2022-0691

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.

📖 Read

via "National Vulnerability Database".
🗓️ Introducing Ghostbuster – AWS security tool protects against dangling elastic IP takeovers  🗓️

New defense against attacks that can cause more damage than other flavors of subdomain takeover

📖 Read

via "The Daily Swig".
CVE-2022-0692

Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.

📖 Read

via "National Vulnerability Database".
🛠 Collabfiltrator 2.1 🛠

Collabfiltrator is a tool to exfiltrate blind remote code execution output over DNS via Burp Collaborator.

📖 Read

via "Packet Storm Security".
🛠 TestSSL 3.0.7 🛠

testssl.sh is a free command line tool which checks a server's service on any port for the support of TLS/SSL ciphers, protocols as well as recent cryptographic flaws, and much more. It is written in (pure) bash, makes only use of standard Unix utilities, openssl and last but not least bash sockets.

📖 Read

via "Packet Storm Security".
🛠 OpenStego Free Steganography Solution 0.8.4 🛠

OpenStego is a tool implemented in Java for generic steganography, with support for password-based encryption of the data. It supports plugins for various steganographic algorithms (currently, only Least Significant Bit algorithm is supported for images).

📖 Read

via "Packet Storm Security".
CVE-2021-44142

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.

📖 Read

via "National Vulnerability Database".
Irony alert! PHP fixes security flaw in input validation code

What's wrong with this sequence? 1. Step into the road 2. Check if it's safe 3. Keep on walki...

📖 Read

via "Naked Security".
French cybercriminals using sextortion scams with no text or links

You'd spot this one a mile away... but what about your friends or family?

📖 Read

via "Naked Security".
👍1
CVE-2022-0708

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

📖 Read

via "National Vulnerability Database".
CVE-2021-44568

Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.

📖 Read

via "National Vulnerability Database".
CVE-2021-27796

A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated attacker within the restricted shell environment (rbash) as either the “user� or “factory� account, to read the contents of any file on the filesystem utilizing one of a few available binaries.

📖 Read

via "National Vulnerability Database".
CVE-2022-25599

Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0).

📖 Read

via "National Vulnerability Database".