1. Vulnerabilities in Cisco Products
(cisco-sa-20150730-asr1k)
[31/07/2015] Vulnerabilities were identified in the Cisco ASR 1000 Series
Aggregation Services Routers, Cisco AnyConnect Secure Mobilty Client, Cisco
Prime Central Hosted Collaboration Solution, Cisco IM and Presence Service,
Cisco IOS-XE Software and Cisco Unified Communications Manager. An attacker
could bypass security restrictions, obtain sensitive information, execute
arbitrary code, perform cross-site scripting attacks, cause a denial of service
condition and crash the system. These vulnerabilities affect multiple firmware
versions of the mentioned products. Security patches are available to resolve
these vulnerabilities except the Cisco Prime Central Hosted Collaboration
Solution and Cisco Unified Communications
Manager.
URL:tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150730-asr1k
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40175
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40214
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40215
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40217
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40223
URL:www.us-cert.gov/ncas/current-activity/2015/07/30/Cisco-Releases-Security-Updates
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105203
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105222
2. Vulnerabilities in Symantec Endpoint Protection
(SYM15-007)
[31/07/2015] Vulnerabilities were identified in the Symantec Endpoint
Protection Manager and Clients. An attacker could bypass security restrictions,
obtain sensitive information, gain elevated privileges, execute arbitrary code
and perform code injection attacks. These vulnerabilities affect versions prior
to 12.1-RU6-MP1 of the mentioned products. Security patches are available to
resolve these
vulnerabilities.
URL:www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2015&suid=20150730_00
3. Vulnerability in Multiple BIOS implementations
(VU#577140)
[31/07/2015] Vulnerability was identified in multiple BIOS
implementations. An attacker could bypass security restrictions, cause a denial
of service condition and execute arbitrary code. This vulnerability affects
multiple Vendor BIOS implementations. Security patches are available to resolve
this
vulnerability.
URL:www.kb.cert.org/vuls/id/577140
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105219
4. Vulnerability in Dell NetVault Backup
(105220)
[31/07/2015]
Vulnerability was identified in the Dell
NetVault Backup. An attacker could bypass security restrictions, cause a denial
of service condition and crash the system. This vulnerability affects versions
prior to 10.0.5 of the mentioned product. Security patches are available to
resolve this
vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105220
5. Vulnerability in F5 Products
(SOL17025)
[31/07/2015]
Vulnerability was identified in the F5 BIG-IP
GTM. An attacker could bypass security restrictions, cause a denial of service
condition and crash the system. This vulnerability affects versions 10.0.0 -
10.1.0 of the mentioned product. Security patches are available to resolve this
vulnerability.
URL:support.f5.com/kb/en-us/solutions/public/17000/000/sol17025.html
6. Vulnerability in Huawei eCloud CC solution
(HW-445981)
[31/07/2015] Vulnerability was identified in the Huawei eCloud CC
solution. An attacker could bypass security restrictions and execute arbitrary
code. This vulnerability affects multiple versions of the mentioned product.
Security patches are available to resolve this
vulnerability.
URL:www.huawei.com/en/security/psirt/security-bulletins/security-notices/archive/hw-445981.htm
7. Security Updates in Oracle Linux (ELSA-2015-1526,
ELSA-2015-3064)
[31/07/2015] Oracle has
released security update packages for fixing the vulnerabilities identified in
the java-1.6.0-openjdk and kernel-uek packages for Oracle Linux 6 and 7. Due to
multiple errors, an attacker could bypass security restriction, obtain sensitive
information, gain elevated privileges, execute arbitrary code, cause a denial of
service condition and compromise the
system.
URL:linux.oracle.com/errata/ELSA-2015-1526.html
URL:linux.oracle.com/errata/ELSA-2015-3064.html
8. Security Updates in Debian (DSA-3320-1,
DSA-3321-1)
[31/07/2015] Debian has
released security update packages for fixing the vulnerabilities identified in
the openafs and xmltooling package for multiple versions of Debian GNU/Linux. An
attacker could bypass security restrictions, obtain sensitive information,
execute arbitrary code, cause a denial of service condition and crash the
system.
URL:www.debian.org/security/2015/dsa-3320
URL:www.debian.org/security/2015/dsa-3321
9. Security Updates in Mageia
(MGASA-2015-0296)
[31/07/2015] Mageia has
released security update packages for fixing the vulnerability identified in the
groovy package for multiple versions of Mageia. Due to multiple errors, an
attacker could bypass security restrictions and execute arbitrary
code.
URL:advisories.mageia.org/MGASA-2015-0296.html
10.
Security Updates in Red Hat Enterprise
Linux (RHSA-2015:1526-1)
[31/07/2015] Red Hat
has released security update packages for fixing the vulnerabilities identified
in the java-1.6.0-openjdk packages for Red Hat Enterprise Linux 5, 6 and 7. Due
to multiple errors, an attacker could bypass security restrictions, obtain
sensitive information, gain elevated privileges, execute arbitrary code, cause a
denial of service condition and compromise the
system.
URL:rhn.redhat.com/errata/RHSA-2015-1526.html
11.
Security Updates in SUSE
(SUSE-SU-2015:1316-1, SUSE-SU-2015:1319-1, SUSE-SU-2015:1320-1,
SUSE-SU-2015:1322-1)
[31/07/2015] SUSE has
released security update packages for fixing the vulnerabilities identified in
the bind and java-1_7_0-openjdk packages of SUSE Linux Enterprise 10, 11 and 12.
Due to multiple errors, an attacker could bypass security restrictions, obtain
sensitive information, gain elevated privileges, execute arbitrary code, cause a
denial of service condition and compromise the
system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00045.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00048.html
12.
Security Updates in Ubuntu GNU/Linux
(USN-2696-1, USN-2697-1, USN-2698-1, USN-2699-1)
[31/07/2015] Ubuntu has released security update packages for fixing the
vulnerabilities identified in the openjdk-7, ghostscript, sqlite3 and hplip
package for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu GNU/Linux. Due to
multiple errors, an attacker could bypass security restrictions, obtain
sensitive information, gain elevated privileges, execute arbitrary code, cause a
denial of service condition and compromise the
system.
URL:www.ubuntu.com/usn/usn-2696-1/
URL:www.ubuntu.com/usn/usn-2697-1/
URL:www.ubuntu.com/usn/usn-2698-1/
URL:www.ubuntu.com/usn/usn-2699-1/
13.
Information Updates on Microsoft Security
Advisory and Bulletins (2755801, 3072630, 3072631,
3079904)
[30/07/2015]
Microsoft has updated information on the
Security Advisory and Security Bulletins for Microsoft Internet Explorer and
Microsoft Windows. (a) KB2755801 added the 3074683 update for Windows 10 systems
to the Current Update section. (b) MS15-069 was revised to correct the Desktop
Experience footnote in the Affected Software section. (c) MS15-074 was
rereleased to announce the availability of an update package for Windows 10
systems. (d) MS15-078 was rereleased to announce the availability of an update
package for Windows 10
systems.
URL:technet.microsoft.com/en-us/library/security/2755801
URL:technet.microsoft.com/en-us/library/security/MS15-069
URL:technet.microsoft.com/en-us/library/security/MS15-074
URL:technet.microsoft.com/en-us/library/security/MS15-078
14.
Vulnerabilities in IBM WebSphere
Application Server
[30/07/2015] Vulnerabilities were identified in the IBM WebSphere
Application Server. An attacker could obtain sensitive information and cause a
denial of service condition. These vulnerabilities affect multiple versions of
the mentioned product. Security patches are available to resolve these
vulnerabilities.
URL:www-01.ibm.com/support/docview.wss?uid=swg21962931
15.
Vulnerabilities in OpenStack Products
(105132, 105198, 105199)
[30/07/2015] Vulnerabilities were identified in the OpenStack Glance and
OpenStack Designate. An attacker could bypass security restrictions and cause a
denial of service condition. These vulnerabilities affect multiple versions of
the mentioned products. Security patches are available to resolve these
vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105132
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105198
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105199
16.
Security Updates in Oracle Linux
(ELSA-2015-1419, ELSA-2015-1471, ELSA-2015-1482, ELSA-2015-1513, ELSA-2015-1514,
ELSA-2015-1515, ELSA-2015-3053)
[30/07/2015] Oracle has
released security update packages for fixing the vulnerabilities identified in
the libxml2, bind, libuser, bind97 and kernel packages for Oracle Linux 5, 6 and
7. Due to multiple errors, an attacker could cause a denial of service
condition, gain elevated privileges and crash the
system.
URL:linux.oracle.com/errata/ELSA-2015-1419.html
URL:linux.oracle.com/errata/ELSA-2015-1471.html
URL:linux.oracle.com/errata/ELSA-2015-1482.html
URL:linux.oracle.com/errata/ELSA-2015-1513.html
URL:linux.oracle.com/errata/ELSA-2015-1514.html
URL:linux.oracle.com/errata/ELSA-2015-1515.html
URL:linux.oracle.com/errata/ELSA-2015-3053.html
17.
Security Updates in Red Hat Gluster
Storage (RHSA-2015:1495-1)
[30/07/2015] Red Hat
has released security update packages for fixing the vulnerabilities identified
in version 3.0 of Red Hat Gluster Storage. Due to multiple errors, an attacker
could bypass security restrictions and execute arbitrary
code.
URL:rhn.redhat.com/errata/RHSA-2015-1495.html
18.
Security Updates in Ubuntu GNU/Linux
(USN-2694-1, USN-2695-1)
[30/07/2015] Ubuntu has
released security update packages for fixing the vulnerabilities identified in
the PCRE and HTML Tidy packages for versions 12.04 LTS, 14.04 LTS and 15.04 of
Ubuntu GNU/Linux. Due to multiple errors, an attacker could crash the system,
cause a denial of service condition and execute arbitrary
code.
URL:www.ubuntu.com/usn/usn-2694-1/
URL:www.ubuntu.com/usn/usn-2695-1/
19.
Vulnerability in BIND
(AA-01272)
[29/07/2015]
Vulnerability was identified in the BIND. An
attacker could bypass security restrictions, cause a denial of service condition
and crash the system. This vulnerability affects versions prior to 9.9.7-P2 or
9.10.2-P3 of the mentioned products. Security patches are available to resolve
this
vulnerability.
URL:kb.isc.org/article/AA-01272
URL:www.us-cert.gov/ncas/current-activity/2015/07/28/Internet-Systems-Consortium-ISC-Releases-Security-Updates-BIND
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105120
20.
Vulnerabilities in Cisco
Products
[29/07/2015]
Vulnerabilities were identified in the Cisco UCS
Central Software and Cisco AnyConnect Secure Mobility Client. An attacker could
bypass security restrictions, obtain sensitive information, execute arbitrary
code, cause a denial of service condition and crash the system. These
vulnerabilities affect multiple firmware versions of the mentioned products.
Security patches are available to resolve these
vulnerabilities.
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40151
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40176
21.
Vulnerabilities in F5 Products (SOL16909,
SOL16912)
[29/07/2015]
Vulnerabilities were identified in the F5 BIG-IP
LTM, BIG-IP AAM, BIG-IP AFM, BIG-IP Analytics, BIG-IP APM, BIG-IP ASM, BIG-IP
Edge Gateway, BIG-IP GTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP PSM, BIG-IP
WebAccelerator, BIG-IP WOM, Enterprise Manager, BIG-IQ Cloud, BIG-IQ Device,
BIG-IQ Security and BIG-IQ ADC. An attacker could bypass security restrictions,
obtain sensitive information, cause a denial of service condition and crash the
system. These vulnerabilities affect multiple versions of the mentioned
products. Security patches are available to resolve these
vulnerabilities.
URL:support.f5.com/kb/en-us/solutions/public/16000/900/sol16909.html
URL:support.f5.com/kb/en-us/solutions/public/16000/900/sol16912.html
22.
Vulnerability in Foxit Reader
(105109)
[29/07/2015]
Vulnerability was identified in the Foxit
Reader. An attacker could bypass security restrictions and execute arbitrary
code. This vulnerability affects versions 7.0.8, 7.0.9 and 7.1.5 of the
mentioned
product.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105109
23.
Vulnerabilities in Android
Stagefright
[29/07/2015] Vulnerabilities were identified in the Android Stagefright
media playback service. An attacker could bypass security restrictions, execute
arbitrary code and compromise the system. These vulnerabilities affect firmware
versions prior to 5.1.1_r5 of the mentioned
products.
URL:www.hkcert.org/my_url/en/alert/15072901
URL:www.kb.cert.org/vuls/id/924951
URL:www.us-cert.gov/ncas/current-activity/2015/07/28/%E2%80%9CStagefright%E2%80%9D-Android-Vulnerability
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105118
24.
Security Updates in Oracle Linux
(ELSA-2015-1249, ELSA-2015-1254, ELSA-2015-1272, ELSA-2015-1287, ELSA-2015-1330,
ELSA-2015-1344, ELSA-2015-1347, ELSA-2015-1378, ELSA-2015-1385, ELSA-2015-1409,
ELSA-2015-1417, ELSA-2015-1419, ELSA-2015-1439, ELSA-2015-1447, ELSA-2015-1457,
ELSA-2015-1458, ELSA-2015-1459, ELSA-2015-1460,
ELSA-2015-1462)
[29/07/2015] Oracle has
released security update packages for fixing the vulnerabilities identified in
the httpd, curl, kernel, freeradius, python, autofs, pki-core, hivex, net-snmp,
sudo, mailman, libxml2, wpa_supplicant, grep, gnutls, libreoffice, ntp,
wireshark and ipa packages for Oracle Linux 6. Due to multiple errors, an
attacker could bypass security restriction, obtain sensitive information, gain
elevated privileges, execute arbitrary code, cause a denial of service condition
and compromise the
system.
URL:linux.oracle.com/errata/ELSA-2015-1249.html
URL:linux.oracle.com/errata/ELSA-2015-1254.html
URL:linux.oracle.com/errata/ELSA-2015-1272.html
URL:linux.oracle.com/errata/ELSA-2015-1287.html
URL:linux.oracle.com/errata/ELSA-2015-1330.html
URL:linux.oracle.com/errata/ELSA-2015-1344.html
URL:linux.oracle.com/errata/ELSA-2015-1347.html
URL:linux.oracle.com/errata/ELSA-2015-1378.html
URL:linux.oracle.com/errata/ELSA-2015-1385.html
URL:linux.oracle.com/errata/ELSA-2015-1409.html
URL:linux.oracle.com/errata/ELSA-2015-1417.html
URL:linux.oracle.com/errata/ELSA-2015-1419.html
URL:linux.oracle.com/errata/ELSA-2015-1439.html
URL:linux.oracle.com/errata/ELSA-2015-1447.html
URL:linux.oracle.com/errata/ELSA-2015-1457.html
URL:linux.oracle.com/errata/ELSA-2015-1458.html
URL:linux.oracle.com/errata/ELSA-2015-1459.html
URL:linux.oracle.com/errata/ELSA-2015-1460.html
URL:linux.oracle.com/errata/ELSA-2015-1462.html
25.
Security Updates in Debian
(DSA-3319-1)
[29/07/2015] Debian has
released security update packages for fixing the vulnerability identified in the
bind9 package for multiple versions of Debian GNU/Linux. An attacker could
bypass security restrictions, execute arbitrary code, cause a denial of service
condition and crash the
system.
URL:www.debian.org/security/2015/dsa-3319
26.
Security Updates in FreeBSD
(FreeBSD-SA-15:14.bsdpatch, FreeBSD-SA-15:15.tcp, FreeBSD-SA-15:16.openssh,
FreeBSD-SA-15:17.bind)
[29/07/2015] FreeBSD
has released security update packages for fixing the vulnerability identified in
the patch, inet, openssh and bind packages for multiple versions of FreeBSD
Linux. Due to multiple errors, an attacker could bypass security restriction,
obtain sensitive information, gain elevated privileges, execute arbitrary code,
cause a denial of service condition and compromise the
system.
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:14.bsdpatch.asc
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:15.tcp.asc
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:16.openssh.asc
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:17.bind.asc
27.
Security Updates in Mageia
(MGASA-2015-0291, MGASA-2015-0292, MGASA-2015-0293, MGASA-2015-0294,
MGASA-2015-0295)
[29/07/2015] Mageia has
released security update packages for fixing the vulnerabilities identified in
the freeradius, ansible, python-django14, python-django, springframework and
openssh packages for multiple versions of Mageia. Due to multiple errors, an
attacker could bypass security restrictions, obtain sensitive information, gain
elevated privileges, execute arbitrary code, cause a denial of service condition
and compromise the
system.
URL:advisories.mageia.org/MGASA-2015-0291.html
URL:advisories.mageia.org/MGASA-2015-0292.html
URL:advisories.mageia.org/MGASA-2015-0293.html
URL:advisories.mageia.org/MGASA-2015-0294.html
URL:advisories.mageia.org/MGASA-2015-0295.html
28.
Security Updates in Red Hat Enterprise
Linux (RHSA-2015:1512-1, RHSA-2015:1513-1, RHSA-2015:1514-1,
RHSA-2015:1515-1)
[29/07/2015] Red Hat
has released security update packages for fixing the vulnerabilities identified
in the qemu-kvm-rhev, bind and bind97 packages for Red Hat Enterprise Linux
OpenStack Platform 5 and 6, Red Hat Enterprise Linux 5, 6 and 7. Due to multiple
errors, an attacker could bypass security restrictions, obtain sensitive
information, gain elevated privileges, execute arbitrary code, cause a denial of
service condition and compromise the
system.
URL:rhn.redhat.com/errata/RHSA-2015-1512.html
URL:rhn.redhat.com/errata/RHSA-2015-1513.html
URL:rhn.redhat.com/errata/RHSA-2015-1514.html
URL:rhn.redhat.com/errata/RHSA-2015-1515.html
29.
Security Updates in Slackware
(SSA:2015-209-01)
[29/07/2015] Slackware
has released security update packages for fixing the vulnerability identified in
the bind package for multiple versions of Slackware Linux. An attacker could
bypass security restriction, cause a denial of service condition and crash the
system.
URL:www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.554472
30.
Security Updates in SUSE
(SUSE-SU-2015:1302-1, SUSE-SU-2015:1304-1,
SUSE-SU-2015:1305-1)
[29/07/2015] SUSE has
released security update packages for fixing the vulnerabilities identified in
the xen and bind packages of SUSE Linux Enterprise 11 and 12. Due to multiple
errors, an attacker could bypass security restrictions, gain elevated
privileges, execute arbitrary code, cause a denial of service condition and
crash the
system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00042.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00043.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00044.html
31.
Security Updates in Ubuntu GNU/Linux
(USN-2686-1)
[29/07/2015] Ubuntu has
released security update packages for fixing the vulnerabilities identified in
the apache2 package for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu
GNU/Linux. Due to multiple errors, an attacker could bypass security
restrictions, execute arbitrary code and perform HTTP request smuggling
attacks.
URL:www.ubuntu.com/usn/usn-2687-1/
URL:www.ubuntu.com/usn/usn-2688-1/
URL:www.ubuntu.com/usn/usn-2689-1/
URL:www.ubuntu.com/usn/usn-2690-1/
URL:www.ubuntu.com/usn/usn-2691-1/
URL:www.ubuntu.com/usn/usn-2692-1/
URL:www.ubuntu.com/usn/usn-2693-1/
32.
Vulnerabilities in Microsoft Internet
Explorer Mobile
[28/07/2015] Vulnerabilities were identified in the Microsoft Internet
Explorer Mobile. An attacker could bypass security restrictions and execute
arbitrary code. The affected version was not
specified.
URL:www.hkcert.org/my_url/en/alert/15072701
33.
Vulnerabilities in Cisco
Products
[28/07/2015]
Vulnerabilities were identified in the Cisco
Firepower 9000 Series devices, Cisco Web Security Appliance (WSA), Cisco Email
Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA).
An attacker could bypass security restrictions, obtain sensitive information,
execute arbitrary code and perform cross-site scripting attacks. These
vulnerabilities affect multiple firmware versions of the mentioned
products.
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40136
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40172
34.
Security Updates in Oracle Linux
(ELSA-2015-1507, ELSA-2015-1510)
[28/07/2015] Oracle has
released security update packages for fixing the vulnerabilities identified in
the qemu-kvm and clutter packages for Oracle Linux 7. Due to multiple errors, an
attacker could bypass security restriction, gain elevated privileges and execute
arbitrary
code.
URL:linux.oracle.com/errata/ELSA-2015-1507.html
URL:linux.oracle.com/errata/ELSA-2015-1510.html
35.
Security Updates in Debian (DSA-3316-1,
DSA-3318-1)
[28/07/2015] Debian has
released security update packages for fixing the vulnerabilities identified in
the openjdk-7 and expat package for multiple versions of Debian GNU/Linux. Due
to multiple errors, an attacker could bypass security restrictions, obtain
sensitive information, gain elevated privileges, execute arbitrary code, cause a
denial of service condition and compromise the
system.
URL:www.debian.org/security/2015/dsa-3316
URL:www.debian.org/security/2015/dsa-3318
36.
Security Updates in Mageia
(MGASA-2015-0279, MGASA-2015-0280, MGASA-2015-0281, MGASA-2015-0282,
MGASA-2015-0283, MGASA-2015-0284, MGASA-2015-0285, MGASA-2015-0286,
MGASA-2015-0287, MGASA-2015-0288, MGASA-2015-0289,
MGASA-2015-0290)
[28/07/2015] Mageia has
released security update packages for fixing the vulnerabilities identified in
the mariadb, java-1.8.0-openjdk, apache, evolution, wesnoth, thunderbird,
thunderbird-l10n, expat, icu, chromium-browser-stable, stunnel and wordpress
packages for multiple versions of Mageia. Due to multiple errors, an attacker
could bypass security restrictions, obtain sensitive information, gain elevated
privileges, execute arbitrary code, cause a denial of service condition and
compromise the
system.
URL:advisories.mageia.org/MGASA-2015-0279.html
URL:advisories.mageia.org/MGASA-2015-0280.html
URL:advisories.mageia.org/MGASA-2015-0281.html
URL:advisories.mageia.org/MGASA-2015-0282.html
URL:advisories.mageia.org/MGASA-2015-0283.html
URL:advisories.mageia.org/MGASA-2015-0284.html
URL:advisories.mageia.org/MGASA-2015-0285.html
URL:advisories.mageia.org/MGASA-2015-0286.html
URL:advisories.mageia.org/MGASA-2015-0287.html
URL:advisories.mageia.org/MGASA-2015-0288.html
URL:advisories.mageia.org/MGASA-2015-0289.html
URL:advisories.mageia.org/MGASA-2015-0290.html
37.
Security Updates in Red Hat Enterprise
Linux (RHSA-2015:1499-1, RHSA-2015:1507-1,
RHSA-2015:1510-1)
[28/07/2015] Red Hat
has released security update packages for fixing the vulnerabilities identified
in the chromium-browser, qemu-kvm and clutter packages for Red Hat Enterprise
Linux 6 and 7. Due to multiple errors, an attacker could bypass security
restrictions, obtain sensitive information, gain elevated privileges, execute
arbitrary code, cause a denial of service condition and compromise the
system.
URL:rhn.redhat.com/errata/RHSA-2015-1499.html
URL:rhn.redhat.com/errata/RHSA-2015-1507.html
URL:rhn.redhat.com/errata/RHSA-2015-1510.html
38.
Security Updates in SUSE
(SUSE-SU-2015:1299-1)
[28/07/2015] SUSE has
released security update packages for fixing the vulnerabilities identified in
the xen package of SUSE Linux Enterprise 11. Due to multiple errors, an attacker
could bypass security restrictions, gain elevated privileges, execute arbitrary
code, cause a denial of service condition and crash the
system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00041.html
39.
Security Updates in Ubuntu GNU/Linux
(USN-2686-1)
[28/07/2015] Ubuntu has
released security update packages for fixing the vulnerabilities identified in
the apache2 package for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu
GNU/Linux. Due to multiple errors, an attacker could bypass security
restrictions, execute arbitrary code and perform HTTP request smuggling
attacks.
URL:www.ubuntu.com/usn/usn-2686-1/
40. Vulnerability in Cisco
Products
[27/07/2015]
Vulnerability was identified in the Cisco Web
Security Appliance (WSA), Cisco Email Security Appliance (ESA) and Cisco Content
Security Management Appliance (SMA). An attacker could bypass security
restrictions and obtain sensitive information. This vulnerability affects
multiple firmware versions of the mentioned
products.
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40137
41.
Vulnerabilities in Honeywell Tuxedo Touch
Controller (VU#857948)
[27/07/2015] Vulnerabilities were identified in the Honeywell Tuxedo Touch
Controller. An attacker could bypass security restrictions, execute arbitrary
code, perform cross-site request forgery attacks. These vulnerabilities affect
firmware versions prior to TUXW_V5.2.19.0_VA of the mentioned product. Security
patches are available to resolve these
vulnerabilities.
URL:www.kb.cert.org/vuls/id/857948
42.
Vulnerability in Fiat-Chrysler Automative
UConnect (VU#819439)
[27/07/2015] Vulnerability was identified in the Fiat-Chrysler Automative
UConnect. An attacker could bypass security restrictions, execute arbitrary code
and compromise the system. This vulnerability affects multiple versions of the
mentioned product. Security patches are available to resolve this
vulnerability.
URL:www.kb.cert.org/vuls/id/819439
43.
Vulnerability in Ghostscript
(105033)
[27/07/2015]
Vulnerability was identified in the Ghostscript.
An attacker could bypass security restrictions and execute arbitrary code. This
vulnerability affects version 9.16 of the mentioned product. Security patches
are available to resolve this
vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105033
44.
Vulnerabilities in libuser (105022,
105023)
[27/07/2015]
Vulnerabilities were identified in the libuser.
An attacker could bypass security restrictions, obtain sensitive information,
gain elevated privileges, execute arbitrary code, cause a denial of service
condition and compromise the system. These vulnerabilities affect versions prior
to 0.62 of the mentioned product. Security patches are available to resolve
these
vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105022
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105023
45.
Security Updates in Debian (DSA-3315-1,
DSA-3317-1)
[27/07/2015] Debian has
released security update packages for fixing the vulnerabilities identified in
the chromium-browser and lxc package for multiple versions of Debian GNU/Linux.
Due to multiple errors, an attacker could bypass security restrictions, obtain
sensitive information, gain elevated privileges, execute arbitrary code, cause a
denial of service condition and compromise the
system.
URL:www.debian.org/security/2015/dsa-3315
URL:www.debian.org/security/2015/dsa-3317
46.
Security Updates in Mageia
(MGASA-2015-0278)
[27/07/2015] Mageia has
released security update packages for fixing the vulnerabilities identified in
the libuser packages for multiple versions of Mageia. Due to multiple errors, an
attacker could bypass security restrictions, obtain sensitive information, gain
elevated privileges, execute arbitrary code, cause a denial of service condition
and compromise the
system.
URL:advisories.mageia.org/MGASA-2015-0278.html
47.
Security Updates in SUSE
(openSUSE-SU-2015:1287-1, openSUSE-SU-2015:1288-1,
openSUSE-SU-2015:1289-1)
[27/07/2015] SUSE has
released security update packages for fixing the vulnerabilities identified in
the Chromium, java-1_7_0-openjdk and java-1_8_0-openjdk package of openSUSE 13.1
and 13.2. Due to multiple errors, an attacker could bypass security
restrictions, obtain sensitive information, gain elevated privileges, execute
arbitrary code, cause a denial of service condition and compromise the
system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00038.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.html
Showing posts with label CERT/CC Cisco. Show all posts
Showing posts with label CERT/CC Cisco. Show all posts
Monday, August 3, 2015
Sunday, May 10, 2015
IT Security Alerts Weekly Digest (3 May ~ 9 May 2015)
1. Vulnerability
in Apache Tomcat
[08/05/2015] Vulnerability was identified in the Apache Tomcat. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:www.hkcert.org/my_url/en/alert/15050701
2. Vulnerability in F5 BIG-IQ (102994)
[08/05/2015] Vulnerability was identified in the F5 BIG-IQ. An attacker could bypass security restrictions and obtain sensitive information. This vulnerability affects firmware version 0.0.7028 of the mentioned product.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102994
3. Vulnerability in Novell NetIQ Sentinel (5202070)
[08/05/2015] Vulnerability was identified in the Novell NetIQ Sentinel. An attacker could bypass security restrictions and perform cross-site scripting attacks. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:download.novell.com/Download?buildid=mBuUwDq2kD0~
4. Vulnerabilities in BullGuard Products (103023, 103024, 103025)
[08/05/2015] Vulnerabilities were identified in the BullGuard Internet Security, BullGuard Antivirus and BullGuard Premium Protection. An attacker could bypass security restrictions and obtain sensitive information. These vulnerabilities affect version 15.0.297 of the mentioned products.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/103023
URL:exchange.xforce.ibmcloud.com/vulnerabilities/103024
URL:exchange.xforce.ibmcloud.com/vulnerabilities/103025
5. Vulnerabilities in WordPress
[08/05/2015] Vulnerabilities were identified in the WordPress. An attacker could bypass security restrictions, execute arbitrary code, perform cross-site scripting attacks and compromise the system. These vulnerabilities affect versions prior to 4.2.2 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:wordpress.org/news/2015/05/wordpress-4-2-2/
URL:www.us-cert.gov/ncas/current-activity/2015/05/07/WordPress-Security-and-Maintenance-Release
6. Security Updates in Mandriva (MDVSA-2015:231)
[08/05/2015] Mandriva has released security update packages for fixing the vulnerability identified in the perl-XML-LibXML package for versions MBS1 and MBS2 of Mandriva GNU/Linux. An attacker could bypass security restrictions and obtain sensitive information.
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A231/
7. Security Updates in Mageia (MGASA-2015-0201)
[08/05/2015] Mageia has released security update packages for fixing the vulnerability identified in the tcl-tcllib package for multiple versions of Mageia. An attacker could bypass security restrictions, execute arbitrary code and perform cross-site scripting attacks.
URL:advisories.mageia.org/MGASA-2015-0201.html
8. Security Updates in SUSE (SUSE-SU-2015:0832-1, SUSE-SU-2015:0833-1)
[08/05/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the kgraft-patch-SLE12_Update_1 and kgraft-patch-SLE12_Update_2 packages of SUSE Linux Enterprise Live Patching 12, and java-1_7_0-openjdk package of SUSE Linux Enterprise 11. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-05/msg00001.html
URL:lists.opensuse.org/opensuse-security-announce/2015-05/msg00002.html
9. Vulnerabilities in Apple Safari (HT204826)
[07/05/2015] Vulnerabilities were identified in the Apple Safari. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect multiple versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:support.apple.com/en-hk/HT204826
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102980
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102981
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102982
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102983
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102984
10. Vulnerability in Cisco UCS Central Software (cisco-sa-20150506-ucsc)
[07/05/2015] Vulnerability was identified in the Cisco UCS Central Software. An attacker could bypass security restrictions, obtain sensitive information and execute arbitrary code. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150506-ucsc
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102985
11. Vulnerability in Huawei Products (Huawei-SA-20150506-01-ICMP)
[07/05/2015] Vulnerability was identified in multiple Huawei Products. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. This vulnerability affects multiple firmware versions of the mentioned products. Security patches are available to resolve this vulnerability.
URL:www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-427449.htm
12. Vulnerabilities in Splunk (SP-CAAANZ7)
[07/05/2015] Vulnerabilities were identified in the Splunk. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code and perform cross-site scripting attacks. These vulnerabilities affect multiple versions of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:www.splunk.com/view/SP-CAAANZ7
URL:www.hkcert.org/my_url/en/alert/15050601
13. Vulnerabilities in FreeRADIUS (102971, 102972, 102973)
[07/05/2015] Vulnerabilities were identified in the FreeRADIUS. An attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect versions prior to 3.0.8 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102971
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102972
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102973
14. Security Updates in Debian (DSA-3252-1)
[07/05/2015] Debian has released security update packages for fixing the vulnerabilities identified in the sqlite3 package for multiple versions of Debian GNU/Linux. An attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system.
URL:www.debian.org/security/2015/dsa-3252
15. Security Updates in Mandriva (MDVSA-2015:228, MDVSA-2015:229, MDVSA-2015:230)
[07/05/2015] Mandriva has released security update packages for fixing the vulnerabilities identified in the nodejs, net-snmp and squid packages for versions MBS1 and MBS2 of Mandriva GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system.
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A228/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A229/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A230/
16. Security Updates in Mageia (MGASA-2015-0193, MGASA-2015-0194, MGASA-2015-0195, MGASA-2015-0196, MGASA-2015-0197, MGASA-2015-0198, MGASA-2015-0199, MGASA-2015-0200)
[07/05/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the mariadb, qtwebkit, qtwebkit5, glibc, x11-server, dpkg, qt3, qt4, qtbase5,perl-XML-LibXML and libtasn1 packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0193.html
URL:advisories.mageia.org/MGASA-2015-0194.html
URL:advisories.mageia.org/MGASA-2015-0195.html
URL:advisories.mageia.org/MGASA-2015-0196.html
URL:advisories.mageia.org/MGASA-2015-0197.html
URL:advisories.mageia.org/MGASA-2015-0198.html
URL:advisories.mageia.org/MGASA-2015-0199.html
URL:advisories.mageia.org/MGASA-2015-0200.html
17. Security Updates in Ubuntu GNU/Linux (USN-2582-1)
[07/05/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the oxide-qt packages for versions 14.04 LTS, 14.10 and vivid of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system.
URL:www.ubuntu.com/usn/usn-2582-1/
18. Vulnerabilities in Cisco Products
[06/05/2015] Vulnerabilities were identified in the Cisco Unified Communications Manager and Cisco Unity Connection. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code and perform cross-site scripting and code injection attacks. These vulnerabilities affect multiple firmware versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:tools.cisco.com/security/center/viewAlert.x?alertId=38674
URL:tools.cisco.com/security/center/viewAlert.x?alertId=38675
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102931
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102932
19. Vulnerability in Bomgar Remote Support (VU#978652)
[06/05/2015] Vulnerability was identified in the Bomgar Remote Support. An attacker could bypass security restrictions and execute arbitrary code. This vulnerability affects versions prior to 15.1.1 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:www.kb.cert.org/vuls/id/978652
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102923
20. Vulnerabilities in cURL
[06/05/2015] Vulnerabilities were identified in the cURL. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect versions prior to 7.42.0 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:www.hkcert.org/my_url/en/alert/15050502
21. Vulnerability in OpenStack Keystone (102922)
[06/05/2015] Vulnerability was identified in the OpenStack Keystone. An attacker could bypass security restrictions and obtain sensitive information. This vulnerability affects versions 2014.1, 2014.2 and 2014.2.3 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102922
22. Security Updates in Debian (DSA-3251-1)
[06/05/2015] Debian has released security update packages for fixing the vulnerability identified in the dnsmasq package for multiple versions of Debian GNU/Linux. An attacker could bypass security restrictions, obtain sensitive information, cause a denial of service condition and crash the system.
URL:www.debian.org/security/2015/dsa-3251
23. Security Updates in Mandriva (MDVSA-2015:227)
[06/05/2015] Mandriva has released security update packages for fixing the vulnerabilities identified in the mariadb package for versions MBS1 and MBS2 of Mandriva GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system.
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A227/
24. Security Updates in Mageia (MGASA-2015-0185, MGASA-2015-0186, MGASA-2015-0187, MGASA-2015-0188, MGASA-2015-0189, MGASA-2015-0190, MGASA-2015-0191, MGASA-2015-0192)
[06/05/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the polarssl, hiawatha, nodejs, net-snmp, gstreamer0.10-plugins-bad, pdns, pdns-recursor, clamav, squid and erlang packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0185.html
URL:advisories.mageia.org/MGASA-2015-0186.html
URL:advisories.mageia.org/MGASA-2015-0187.html
URL:advisories.mageia.org/MGASA-2015-0188.html
URL:advisories.mageia.org/MGASA-2015-0189.html
URL:advisories.mageia.org/MGASA-2015-0190.html
URL:advisories.mageia.org/MGASA-2015-0191.html
URL:advisories.mageia.org/MGASA-2015-0192.html
25. Security Updates in Ubuntu GNU/Linux (USN-2594-1, USN-2595-1, USN-2596-1, USN-2597-1, USN-2598-1, USN-2599-1, USN-2600-1, USN-2601-1)
[06/05/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the clamav, ppp, linux-lts-trusty, linux-lts-utopic and linux packages for versions 12.04 LTS, 14.04 LTS, 14.10 and vivid of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.ubuntu.com/usn/usn-2594-1/
URL:www.ubuntu.com/usn/usn-2595-1/
URL:www.ubuntu.com/usn/usn-2596-1/
URL:www.ubuntu.com/usn/usn-2597-1/
URL:www.ubuntu.com/usn/usn-2598-1/
URL:www.ubuntu.com/usn/usn-2599-1/
URL:www.ubuntu.com/usn/usn-2600-1/
URL:www.ubuntu.com/usn/usn-2601-1/
26. Vulnerability in Cisco Finesse Server
[05/05/2015] Vulnerability was identified in the Cisco Finesse Server. An attacker could bypass security restrictions, obtain sensitive information and perform cross-site scripting attacks. This vulnerability affects multiple firmware versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:tools.cisco.com/security/center/viewAlert.x?alertId=38607
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102845
27. Vulnerability in Dell SonicWALL Secure Remote Access (102844)
[05/05/2015] Vulnerability was identified in the Dell SonicWALL Secure Remote Access. An attacker could bypass security restrictions and perform cross-site scripting attacks. This vulnerability affects version 7.5 and 8.0 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102844
28. Vulnerability in EMC SourceOne Email Management (102877)
[05/05/2015] Vulnerability was identified in the EMC SourceOne Email Management. An attacker could bypass security restrictions and obtain sensitive information. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102877
29. Vulnerability in Huawei MobiConnect (102871)
[05/05/2015] Vulnerability was identified in the Huawei MobiConnect. An attacker could bypass security restrictions and gain elevated privileges. This vulnerability affects firmware version 23.9.17.216 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102871
30. Vulnerabilities in ClamAV (102867, 102868, 102869, 102870)
[05/05/2015] Vulnerabilities were identified in the ClamAV. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. These vulnerabilities affect versions prior to 0.98.7 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102867
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102868
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102869
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102870
31. Vulnerabilities in ICU Project ICU4C library (VU#602540)
[05/05/2015] Vulnerabilities were identified in the ICU Project ICU4C library. An attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect versions 52 through 54 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:www.kb.cert.org/vuls/id/602540
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102875
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102876
32. Vulnerability in Linux Kernel (102873)
[05/05/2015] Vulnerability was identified in the Linux Kernel. An attacker could bypass security restrictions and gain elevated privileges on the system. The affected version was not specified. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102873
33. Security Updates in Debian (DSA-3245-1, DSA-3246-1, DSA-3247-1, DSA-3248-1, DSA-3249-1, DSA-3250-1)
[05/05/2015] Debian has released security update packages for fixing the vulnerabilities identified in the ruby1.8, ruby1.9.1, ruby2.1, libphp-snoopy, jqueryui and wordpress packages for multiple versions of Debian GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.debian.org/security/2015/dsa-3245
URL:www.debian.org/security/2015/dsa-3246
URL:www.debian.org/security/2015/dsa-3247
URL:www.debian.org/security/2015/dsa-3248
URL:www.debian.org/security/2015/dsa-3249
URL:www.debian.org/security/2015/dsa-3250
34. Security Updates in Mandriva (MDVSA-2015:219, MDVSA-2015:220, MDVSA-2015:221, MDVSA-2015:222, MDVSA-2015:223, MDVSA-2015:224, MDVSA-2015:225, MDVSA-2015:226)
[05/05/2015] Mandriva has released security update packages for fixing the vulnerabilities identified in the curl, clamav, ppp, directfb, ruby, cherokee and fcgi packages for versions MBS1 and MBS2 of Mandriva GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A219/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A220/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A221/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A222/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A223/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A224/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A225/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A226/
35. Security Updates in Ubuntu GNU/Linux (USN-2592-1, USN-2593-1)
[05/05/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the libxml-libxml-perl and dnsmasq packages for versions 12.04 LTS, 14.04 LTS, 14.10 and vivid of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, cause a denial of service condition and crash the system.
URL:www.ubuntu.com/usn/usn-2592-1/
URL:www.ubuntu.com/usn/usn-2593-1/
36. Information Updates on Microsoft Security Advisory (3062591)
[04/05/2015] Microsoft has updated information on the Security Advisory for the Local Administrator Password Solution (LAPS) of Windows Server 2003 Active Directory. KB3062591 was published to provide a solution to the issue of using a common local account with an identical password on every computer in a domain.
URL:technet.microsoft.com/en-us/library/security/3062591
37. Vulnerability in Huawei E587 Products (Huawei-SA-20150429-01-E587)
[04/05/2015] Vulnerability was identified in the Huawei E587 products. An attacker could bypass security restrictions, obtain sensitive information and cause a denial of service condition. This vulnerability affects versions prior to 11.203.30.00.00 of the mentioned products. Security patches are available to resolve this vulnerability.
URL:www.huawei.com/en/security/psirt/security-bulletins/security-advisories/archive/hw-425408.htm
38. Vulnerability in EMC AutoStart (VU#581276)
[04/05/2015] Vulnerability was identified in the EMC AutoStart. An attacker could bypass security restrictions, gain elevated privileges and execute arbitrary code. This vulnerability affects version prior to 5.5.0.508 (HF4) of the mentioned product. Security patches are available to resolve this vulnerability.
URL:www.kb.cert.org/vuls/id/581276
39. Vulnerability in GNU Libtasn1 (102782)
[04/05/2015] Vulnerability was identified in the GNU Libtasn1. An attacker could bypass security restrictions, execute arbitrary code and cause a denial of service condition. This vulnerability affects versions prior to 4.5 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102782
40. Vulnerability in Squid (SQUID-2015:1)
[04/05/2015] Vulnerability was identified in the Squid. An attacker could bypass security restrictions, obtain sensitive information and cause a denial of service condition. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:www.squid-cache.org/Advisories/SQUID-2015_1.txt
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102789
41. Security Updates in Debian (DSA-3241-1, DSA-3242-1, DSA-3243-1, DSA-3244-1)
[04/05/2015] Debian has released security update packages for fixing the vulnerabilities identified in the elasticsearch, chromium-browser, libxml-libxml-perl and owncloud packages for multiple versions of Debian GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.debian.org/security/2015/dsa-3241
URL:www.debian.org/security/2015/dsa-3242
URL:www.debian.org/security/2015/dsa-3243
URL:www.debian.org/security/2015/dsa-3244
42. Security Updates in Mandriva (MDVSA-2015:217, MDVSA-2015:218)
[04/05/2015] Mandriva has released security update packages for fixing the vulnerabilities identified in the sqlite3 and glibc packages for versions MBS1 and MBS2 of Mandriva GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A217/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A218/
43. Security Updates in Mageia (MGASA-2015-0171, MGASA-2015-0172, MGASA-2015-0173, MGASA-2015-0174, MGASA-2015-0175, MGASA-2015-0176, MGASA-2015-0177, MGASA-2015-0178, MGASA-2015-0179, MGASA-2015-0180, MGASA-2015-0181, MGASA-2015-0182, MGASA-2015-0183, MGASA-2015-0184)
[04/05/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the kernel, kernel-userspace-headers, kmod-vboxadditions, kmod-virtualbox, kmod-xtables-addons, kmod-broadcom-wl, kmod-fglrx, kmod-nvidia173, kmod-nvidia304, kmod-nvidia-current, kernel-linus, ppp, libreoffice, quassel, directfb, subversion, ruby, curl, python-pip, python-virtualenv, cherokee, chromium-browser-stable, 389-ds-base and fcgi packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0171.html
URL:advisories.mageia.org/MGASA-2015-0172.html
URL:advisories.mageia.org/MGASA-2015-0173.html
URL:advisories.mageia.org/MGASA-2015-0174.html
URL:advisories.mageia.org/MGASA-2015-0175.html
URL:advisories.mageia.org/MGASA-2015-0176.html
URL:advisories.mageia.org/MGASA-2015-0177.html
URL:advisories.mageia.org/MGASA-2015-0178.html
URL:advisories.mageia.org/MGASA-2015-0179.html
URL:advisories.mageia.org/MGASA-2015-0180.html
URL:advisories.mageia.org/MGASA-2015-0181.html
URL:advisories.mageia.org/MGASA-2015-0182.html
URL:advisories.mageia.org/MGASA-2015-0183.html
URL:advisories.mageia.org/MGASA-2015-0184.html
44. Security Updates in SUSE (openSUSE-SU-2015:0807-1, SUSE-SU-2015:0812-1 openSUSE-SU-2015:0813-1)
[04/05/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the DirectFB and wpa_supplicant packages of openSUSE 13.1 and 13.2, and the Linux Kernel package of SUSE Linux Enterprise 10. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-04/msg00019.html
URL:lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html
URL:lists.opensuse.org/opensuse-security-announce/2015-05/msg00000.html
45. Security Updates in Red Hat Enterprise Linux (RHSA-2015:0919-1, RHSA-2015:0921-1)
[04/05/2015] Red Hat has released security update packages for fixing the vulnerabilities identified in the kernel and chromium-browser packages for Red Hat Enterprise Linux 5 and 6. Due to multiple errors, an attacker could bypass security restrictions, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system.
URL:rhn.redhat.com/errata/RHSA-2015-0919.html
URL:rhn.redhat.com/errata/RHSA-2015-0921.html
46. Security Updates in Ubuntu GNU/Linux (USN-2583-1, USN-2584-2, USN-2585-1, USN-2586-1, USN-2587-2, USN-2588-1, USN-2589-1, USN-2590-2, USN-2591-1)
[04/05/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the linux, linux-ec2, linux-ti-omap4, linux-lts-trusty, linux-lts-utopic and curl packages for versions 10.04 LTS, 12.04 LTS, 14.04 LTS, 14.10 and vivid of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.ubuntu.com/usn/usn-2583-1/
URL:www.ubuntu.com/usn/usn-2584-1/
URL:www.ubuntu.com/usn/usn-2585-1/
URL:www.ubuntu.com/usn/usn-2586-1/
URL:www.ubuntu.com/usn/usn-2587-1/
URL:www.ubuntu.com/usn/usn-2588-1/
URL:www.ubuntu.com/usn/usn-2589-1/
URL:www.ubuntu.com/usn/usn-2590-1/
URL:www.ubuntu.com/usn/usn-2591-1/
Source(s) of above information:
[08/05/2015] Vulnerability was identified in the Apache Tomcat. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:www.hkcert.org/my_url/en/alert/15050701
2. Vulnerability in F5 BIG-IQ (102994)
[08/05/2015] Vulnerability was identified in the F5 BIG-IQ. An attacker could bypass security restrictions and obtain sensitive information. This vulnerability affects firmware version 0.0.7028 of the mentioned product.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102994
3. Vulnerability in Novell NetIQ Sentinel (5202070)
[08/05/2015] Vulnerability was identified in the Novell NetIQ Sentinel. An attacker could bypass security restrictions and perform cross-site scripting attacks. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:download.novell.com/Download?buildid=mBuUwDq2kD0~
4. Vulnerabilities in BullGuard Products (103023, 103024, 103025)
[08/05/2015] Vulnerabilities were identified in the BullGuard Internet Security, BullGuard Antivirus and BullGuard Premium Protection. An attacker could bypass security restrictions and obtain sensitive information. These vulnerabilities affect version 15.0.297 of the mentioned products.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/103023
URL:exchange.xforce.ibmcloud.com/vulnerabilities/103024
URL:exchange.xforce.ibmcloud.com/vulnerabilities/103025
5. Vulnerabilities in WordPress
[08/05/2015] Vulnerabilities were identified in the WordPress. An attacker could bypass security restrictions, execute arbitrary code, perform cross-site scripting attacks and compromise the system. These vulnerabilities affect versions prior to 4.2.2 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:wordpress.org/news/2015/05/wordpress-4-2-2/
URL:www.us-cert.gov/ncas/current-activity/2015/05/07/WordPress-Security-and-Maintenance-Release
6. Security Updates in Mandriva (MDVSA-2015:231)
[08/05/2015] Mandriva has released security update packages for fixing the vulnerability identified in the perl-XML-LibXML package for versions MBS1 and MBS2 of Mandriva GNU/Linux. An attacker could bypass security restrictions and obtain sensitive information.
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A231/
7. Security Updates in Mageia (MGASA-2015-0201)
[08/05/2015] Mageia has released security update packages for fixing the vulnerability identified in the tcl-tcllib package for multiple versions of Mageia. An attacker could bypass security restrictions, execute arbitrary code and perform cross-site scripting attacks.
URL:advisories.mageia.org/MGASA-2015-0201.html
8. Security Updates in SUSE (SUSE-SU-2015:0832-1, SUSE-SU-2015:0833-1)
[08/05/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the kgraft-patch-SLE12_Update_1 and kgraft-patch-SLE12_Update_2 packages of SUSE Linux Enterprise Live Patching 12, and java-1_7_0-openjdk package of SUSE Linux Enterprise 11. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-05/msg00001.html
URL:lists.opensuse.org/opensuse-security-announce/2015-05/msg00002.html
9. Vulnerabilities in Apple Safari (HT204826)
[07/05/2015] Vulnerabilities were identified in the Apple Safari. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect multiple versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:support.apple.com/en-hk/HT204826
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102980
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102981
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102982
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102983
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102984
10. Vulnerability in Cisco UCS Central Software (cisco-sa-20150506-ucsc)
[07/05/2015] Vulnerability was identified in the Cisco UCS Central Software. An attacker could bypass security restrictions, obtain sensitive information and execute arbitrary code. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150506-ucsc
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102985
11. Vulnerability in Huawei Products (Huawei-SA-20150506-01-ICMP)
[07/05/2015] Vulnerability was identified in multiple Huawei Products. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. This vulnerability affects multiple firmware versions of the mentioned products. Security patches are available to resolve this vulnerability.
URL:www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-427449.htm
12. Vulnerabilities in Splunk (SP-CAAANZ7)
[07/05/2015] Vulnerabilities were identified in the Splunk. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code and perform cross-site scripting attacks. These vulnerabilities affect multiple versions of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:www.splunk.com/view/SP-CAAANZ7
URL:www.hkcert.org/my_url/en/alert/15050601
13. Vulnerabilities in FreeRADIUS (102971, 102972, 102973)
[07/05/2015] Vulnerabilities were identified in the FreeRADIUS. An attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect versions prior to 3.0.8 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102971
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102972
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102973
14. Security Updates in Debian (DSA-3252-1)
[07/05/2015] Debian has released security update packages for fixing the vulnerabilities identified in the sqlite3 package for multiple versions of Debian GNU/Linux. An attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system.
URL:www.debian.org/security/2015/dsa-3252
15. Security Updates in Mandriva (MDVSA-2015:228, MDVSA-2015:229, MDVSA-2015:230)
[07/05/2015] Mandriva has released security update packages for fixing the vulnerabilities identified in the nodejs, net-snmp and squid packages for versions MBS1 and MBS2 of Mandriva GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system.
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A228/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A229/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A230/
16. Security Updates in Mageia (MGASA-2015-0193, MGASA-2015-0194, MGASA-2015-0195, MGASA-2015-0196, MGASA-2015-0197, MGASA-2015-0198, MGASA-2015-0199, MGASA-2015-0200)
[07/05/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the mariadb, qtwebkit, qtwebkit5, glibc, x11-server, dpkg, qt3, qt4, qtbase5,perl-XML-LibXML and libtasn1 packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0193.html
URL:advisories.mageia.org/MGASA-2015-0194.html
URL:advisories.mageia.org/MGASA-2015-0195.html
URL:advisories.mageia.org/MGASA-2015-0196.html
URL:advisories.mageia.org/MGASA-2015-0197.html
URL:advisories.mageia.org/MGASA-2015-0198.html
URL:advisories.mageia.org/MGASA-2015-0199.html
URL:advisories.mageia.org/MGASA-2015-0200.html
17. Security Updates in Ubuntu GNU/Linux (USN-2582-1)
[07/05/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the oxide-qt packages for versions 14.04 LTS, 14.10 and vivid of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system.
URL:www.ubuntu.com/usn/usn-2582-1/
18. Vulnerabilities in Cisco Products
[06/05/2015] Vulnerabilities were identified in the Cisco Unified Communications Manager and Cisco Unity Connection. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code and perform cross-site scripting and code injection attacks. These vulnerabilities affect multiple firmware versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:tools.cisco.com/security/center/viewAlert.x?alertId=38674
URL:tools.cisco.com/security/center/viewAlert.x?alertId=38675
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102931
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102932
19. Vulnerability in Bomgar Remote Support (VU#978652)
[06/05/2015] Vulnerability was identified in the Bomgar Remote Support. An attacker could bypass security restrictions and execute arbitrary code. This vulnerability affects versions prior to 15.1.1 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:www.kb.cert.org/vuls/id/978652
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102923
20. Vulnerabilities in cURL
[06/05/2015] Vulnerabilities were identified in the cURL. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect versions prior to 7.42.0 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:www.hkcert.org/my_url/en/alert/15050502
21. Vulnerability in OpenStack Keystone (102922)
[06/05/2015] Vulnerability was identified in the OpenStack Keystone. An attacker could bypass security restrictions and obtain sensitive information. This vulnerability affects versions 2014.1, 2014.2 and 2014.2.3 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102922
22. Security Updates in Debian (DSA-3251-1)
[06/05/2015] Debian has released security update packages for fixing the vulnerability identified in the dnsmasq package for multiple versions of Debian GNU/Linux. An attacker could bypass security restrictions, obtain sensitive information, cause a denial of service condition and crash the system.
URL:www.debian.org/security/2015/dsa-3251
23. Security Updates in Mandriva (MDVSA-2015:227)
[06/05/2015] Mandriva has released security update packages for fixing the vulnerabilities identified in the mariadb package for versions MBS1 and MBS2 of Mandriva GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system.
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A227/
24. Security Updates in Mageia (MGASA-2015-0185, MGASA-2015-0186, MGASA-2015-0187, MGASA-2015-0188, MGASA-2015-0189, MGASA-2015-0190, MGASA-2015-0191, MGASA-2015-0192)
[06/05/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the polarssl, hiawatha, nodejs, net-snmp, gstreamer0.10-plugins-bad, pdns, pdns-recursor, clamav, squid and erlang packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0185.html
URL:advisories.mageia.org/MGASA-2015-0186.html
URL:advisories.mageia.org/MGASA-2015-0187.html
URL:advisories.mageia.org/MGASA-2015-0188.html
URL:advisories.mageia.org/MGASA-2015-0189.html
URL:advisories.mageia.org/MGASA-2015-0190.html
URL:advisories.mageia.org/MGASA-2015-0191.html
URL:advisories.mageia.org/MGASA-2015-0192.html
25. Security Updates in Ubuntu GNU/Linux (USN-2594-1, USN-2595-1, USN-2596-1, USN-2597-1, USN-2598-1, USN-2599-1, USN-2600-1, USN-2601-1)
[06/05/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the clamav, ppp, linux-lts-trusty, linux-lts-utopic and linux packages for versions 12.04 LTS, 14.04 LTS, 14.10 and vivid of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.ubuntu.com/usn/usn-2594-1/
URL:www.ubuntu.com/usn/usn-2595-1/
URL:www.ubuntu.com/usn/usn-2596-1/
URL:www.ubuntu.com/usn/usn-2597-1/
URL:www.ubuntu.com/usn/usn-2598-1/
URL:www.ubuntu.com/usn/usn-2599-1/
URL:www.ubuntu.com/usn/usn-2600-1/
URL:www.ubuntu.com/usn/usn-2601-1/
26. Vulnerability in Cisco Finesse Server
[05/05/2015] Vulnerability was identified in the Cisco Finesse Server. An attacker could bypass security restrictions, obtain sensitive information and perform cross-site scripting attacks. This vulnerability affects multiple firmware versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:tools.cisco.com/security/center/viewAlert.x?alertId=38607
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102845
27. Vulnerability in Dell SonicWALL Secure Remote Access (102844)
[05/05/2015] Vulnerability was identified in the Dell SonicWALL Secure Remote Access. An attacker could bypass security restrictions and perform cross-site scripting attacks. This vulnerability affects version 7.5 and 8.0 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102844
28. Vulnerability in EMC SourceOne Email Management (102877)
[05/05/2015] Vulnerability was identified in the EMC SourceOne Email Management. An attacker could bypass security restrictions and obtain sensitive information. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102877
29. Vulnerability in Huawei MobiConnect (102871)
[05/05/2015] Vulnerability was identified in the Huawei MobiConnect. An attacker could bypass security restrictions and gain elevated privileges. This vulnerability affects firmware version 23.9.17.216 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102871
30. Vulnerabilities in ClamAV (102867, 102868, 102869, 102870)
[05/05/2015] Vulnerabilities were identified in the ClamAV. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. These vulnerabilities affect versions prior to 0.98.7 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102867
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102868
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102869
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102870
31. Vulnerabilities in ICU Project ICU4C library (VU#602540)
[05/05/2015] Vulnerabilities were identified in the ICU Project ICU4C library. An attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect versions 52 through 54 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:www.kb.cert.org/vuls/id/602540
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102875
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102876
32. Vulnerability in Linux Kernel (102873)
[05/05/2015] Vulnerability was identified in the Linux Kernel. An attacker could bypass security restrictions and gain elevated privileges on the system. The affected version was not specified. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102873
33. Security Updates in Debian (DSA-3245-1, DSA-3246-1, DSA-3247-1, DSA-3248-1, DSA-3249-1, DSA-3250-1)
[05/05/2015] Debian has released security update packages for fixing the vulnerabilities identified in the ruby1.8, ruby1.9.1, ruby2.1, libphp-snoopy, jqueryui and wordpress packages for multiple versions of Debian GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.debian.org/security/2015/dsa-3245
URL:www.debian.org/security/2015/dsa-3246
URL:www.debian.org/security/2015/dsa-3247
URL:www.debian.org/security/2015/dsa-3248
URL:www.debian.org/security/2015/dsa-3249
URL:www.debian.org/security/2015/dsa-3250
34. Security Updates in Mandriva (MDVSA-2015:219, MDVSA-2015:220, MDVSA-2015:221, MDVSA-2015:222, MDVSA-2015:223, MDVSA-2015:224, MDVSA-2015:225, MDVSA-2015:226)
[05/05/2015] Mandriva has released security update packages for fixing the vulnerabilities identified in the curl, clamav, ppp, directfb, ruby, cherokee and fcgi packages for versions MBS1 and MBS2 of Mandriva GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A219/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A220/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A221/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A222/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A223/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A224/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A225/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A226/
35. Security Updates in Ubuntu GNU/Linux (USN-2592-1, USN-2593-1)
[05/05/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the libxml-libxml-perl and dnsmasq packages for versions 12.04 LTS, 14.04 LTS, 14.10 and vivid of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, cause a denial of service condition and crash the system.
URL:www.ubuntu.com/usn/usn-2592-1/
URL:www.ubuntu.com/usn/usn-2593-1/
36. Information Updates on Microsoft Security Advisory (3062591)
[04/05/2015] Microsoft has updated information on the Security Advisory for the Local Administrator Password Solution (LAPS) of Windows Server 2003 Active Directory. KB3062591 was published to provide a solution to the issue of using a common local account with an identical password on every computer in a domain.
URL:technet.microsoft.com/en-us/library/security/3062591
37. Vulnerability in Huawei E587 Products (Huawei-SA-20150429-01-E587)
[04/05/2015] Vulnerability was identified in the Huawei E587 products. An attacker could bypass security restrictions, obtain sensitive information and cause a denial of service condition. This vulnerability affects versions prior to 11.203.30.00.00 of the mentioned products. Security patches are available to resolve this vulnerability.
URL:www.huawei.com/en/security/psirt/security-bulletins/security-advisories/archive/hw-425408.htm
38. Vulnerability in EMC AutoStart (VU#581276)
[04/05/2015] Vulnerability was identified in the EMC AutoStart. An attacker could bypass security restrictions, gain elevated privileges and execute arbitrary code. This vulnerability affects version prior to 5.5.0.508 (HF4) of the mentioned product. Security patches are available to resolve this vulnerability.
URL:www.kb.cert.org/vuls/id/581276
39. Vulnerability in GNU Libtasn1 (102782)
[04/05/2015] Vulnerability was identified in the GNU Libtasn1. An attacker could bypass security restrictions, execute arbitrary code and cause a denial of service condition. This vulnerability affects versions prior to 4.5 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102782
40. Vulnerability in Squid (SQUID-2015:1)
[04/05/2015] Vulnerability was identified in the Squid. An attacker could bypass security restrictions, obtain sensitive information and cause a denial of service condition. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:www.squid-cache.org/Advisories/SQUID-2015_1.txt
URL:exchange.xforce.ibmcloud.com/vulnerabilities/102789
41. Security Updates in Debian (DSA-3241-1, DSA-3242-1, DSA-3243-1, DSA-3244-1)
[04/05/2015] Debian has released security update packages for fixing the vulnerabilities identified in the elasticsearch, chromium-browser, libxml-libxml-perl and owncloud packages for multiple versions of Debian GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.debian.org/security/2015/dsa-3241
URL:www.debian.org/security/2015/dsa-3242
URL:www.debian.org/security/2015/dsa-3243
URL:www.debian.org/security/2015/dsa-3244
42. Security Updates in Mandriva (MDVSA-2015:217, MDVSA-2015:218)
[04/05/2015] Mandriva has released security update packages for fixing the vulnerabilities identified in the sqlite3 and glibc packages for versions MBS1 and MBS2 of Mandriva GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A217/
URL:www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015%3A218/
43. Security Updates in Mageia (MGASA-2015-0171, MGASA-2015-0172, MGASA-2015-0173, MGASA-2015-0174, MGASA-2015-0175, MGASA-2015-0176, MGASA-2015-0177, MGASA-2015-0178, MGASA-2015-0179, MGASA-2015-0180, MGASA-2015-0181, MGASA-2015-0182, MGASA-2015-0183, MGASA-2015-0184)
[04/05/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the kernel, kernel-userspace-headers, kmod-vboxadditions, kmod-virtualbox, kmod-xtables-addons, kmod-broadcom-wl, kmod-fglrx, kmod-nvidia173, kmod-nvidia304, kmod-nvidia-current, kernel-linus, ppp, libreoffice, quassel, directfb, subversion, ruby, curl, python-pip, python-virtualenv, cherokee, chromium-browser-stable, 389-ds-base and fcgi packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0171.html
URL:advisories.mageia.org/MGASA-2015-0172.html
URL:advisories.mageia.org/MGASA-2015-0173.html
URL:advisories.mageia.org/MGASA-2015-0174.html
URL:advisories.mageia.org/MGASA-2015-0175.html
URL:advisories.mageia.org/MGASA-2015-0176.html
URL:advisories.mageia.org/MGASA-2015-0177.html
URL:advisories.mageia.org/MGASA-2015-0178.html
URL:advisories.mageia.org/MGASA-2015-0179.html
URL:advisories.mageia.org/MGASA-2015-0180.html
URL:advisories.mageia.org/MGASA-2015-0181.html
URL:advisories.mageia.org/MGASA-2015-0182.html
URL:advisories.mageia.org/MGASA-2015-0183.html
URL:advisories.mageia.org/MGASA-2015-0184.html
44. Security Updates in SUSE (openSUSE-SU-2015:0807-1, SUSE-SU-2015:0812-1 openSUSE-SU-2015:0813-1)
[04/05/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the DirectFB and wpa_supplicant packages of openSUSE 13.1 and 13.2, and the Linux Kernel package of SUSE Linux Enterprise 10. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-04/msg00019.html
URL:lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html
URL:lists.opensuse.org/opensuse-security-announce/2015-05/msg00000.html
45. Security Updates in Red Hat Enterprise Linux (RHSA-2015:0919-1, RHSA-2015:0921-1)
[04/05/2015] Red Hat has released security update packages for fixing the vulnerabilities identified in the kernel and chromium-browser packages for Red Hat Enterprise Linux 5 and 6. Due to multiple errors, an attacker could bypass security restrictions, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system.
URL:rhn.redhat.com/errata/RHSA-2015-0919.html
URL:rhn.redhat.com/errata/RHSA-2015-0921.html
46. Security Updates in Ubuntu GNU/Linux (USN-2583-1, USN-2584-2, USN-2585-1, USN-2586-1, USN-2587-2, USN-2588-1, USN-2589-1, USN-2590-2, USN-2591-1)
[04/05/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the linux, linux-ec2, linux-ti-omap4, linux-lts-trusty, linux-lts-utopic and curl packages for versions 10.04 LTS, 12.04 LTS, 14.04 LTS, 14.10 and vivid of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.ubuntu.com/usn/usn-2583-1/
URL:www.ubuntu.com/usn/usn-2584-1/
URL:www.ubuntu.com/usn/usn-2585-1/
URL:www.ubuntu.com/usn/usn-2586-1/
URL:www.ubuntu.com/usn/usn-2587-1/
URL:www.ubuntu.com/usn/usn-2588-1/
URL:www.ubuntu.com/usn/usn-2589-1/
URL:www.ubuntu.com/usn/usn-2590-1/
URL:www.ubuntu.com/usn/usn-2591-1/
Source(s) of above information:
Subscribe to:
Posts (Atom)