[SECURITY] [DSA 3083-1] mutt security update

2014-12-01 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3083-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso November 30, 2014

[SECURITY] [DSA 3082-1] flac security update

2014-12-01 Thread Sebastien Delafond
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 - - Debian Security Advisory DSA-3082-1 secur...@debian.org http://www.debian.org/security/Sebastien Delafond November 30, 2014

[The ManageOwnage Series, part IX]: 0-day arbitrary file download in NetFlow Analyzer and IT360

2014-12-01 Thread Pedro Ribeiro
Hi, This is part 9 of the ManageOwnage series. For previous parts see [1]. Today we have yet another 0 day - an arbitrary file download vulnerability that be exploited unauthenticated in NetFlow Analyzer and authenticated in IT360. I'm releasing this as a 0 day because ManageEngine have been

[SECURITY] [DSA 3081-1] libvncserver security update

2014-12-01 Thread Luciano Bello
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 - - Debian Security Advisory DSA-3081-1 secur...@debian.org http://www.debian.org/security/ Luciano Bello November 29, 2014

CVE-2014-3809: Reflected XSS in Alcatel Lucent 1830 PSS-32/16/4

2014-12-01 Thread Stephan.Rickauer
# # # SWISSCOM CSIRT ADVISORY - http://www.swisscom.com/security # # # # CVE ID: CVE-2014-3809 # Product: 1830 Photonic Service Switch PSS-32/16/4 # Vendor: Alcatel-Lucent #

[RT-SA-2014-009] Information Disclosure in TYPO3 Extension ke_questionnaire

2014-12-01 Thread RedTeam Pentesting GmbH
Advisory: Information Disclosure in TYPO3 Extension ke_questionnaire The TYPO3 extension ke_questionnaire stores answered questionnaires in a publicly reachable directory on the webserver with filenames that are easily guessable. Details === Product: ke_questionnaire Affected Versions:

[RT-SA-2014-007] Remote Code Execution in TYPO3 Extension ke_dompdf

2014-12-01 Thread RedTeam Pentesting GmbH
Advisory: Remote Code Execution in TYPO3 Extension ke_dompdf During a penetration test RedTeam Pentesting discovered a remote code execution vulnerability in the TYPO3 extension ke_dompdf, which allows attackers to execute arbitrary PHP commands in the context of the webserver. Details ===

[RT-SA-2014-011] EntryPass N5200 Credentials Disclosure

2014-12-01 Thread RedTeam Pentesting GmbH
Advisory: EntryPass N5200 Credentials Disclosure EntryPass N5200 Active Network Control Panels allow the unauthenticated downloading of information that includes the current administrative username and password. Details === Product: EntryPass N5200 Active Network Control Panel Affected

[SECURITY] [DSA 3084-1] openvpn security update

2014-12-01 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-3084-1 secur...@debian.org http://www.debian.org/security/Florian Weimer December 01, 2014