[security bulletin] HPSBHF02821 SSRT100934 rev.1 - HP Integrated Lights-Out iLO3 and iLO4, Remote Disclosure of Information

2012-11-20 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c03515413 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03515413 Version: 1 HPSBHF02821

SonicWALL CDP 5040 v6.x - Multiple Web Vulnerabilities

2012-11-20 Thread Vulnerability Lab
Title: == SonicWALL CDP 5040 v6.x - Multiple Web Vulnerabilities Date: = 2012-11-19 References: === http://www.vulnerability-lab.com/get_content.php?id=549 VL-ID: = 549 Common Vulnerability Scoring System: 3.5 Introduction:

Re: [SE-2012-01] Security vulnerabilities in Java SE (details released)

2012-11-20 Thread Security Explorations
Hello All, We have updated our project details page and added selected Proof of Concept codes to it that have been developed as part of our Java SE security research. They are available for download from SE-2012-01 project details page. Those willing to better understand Reflection API based

OSSIM 4.0.2 open-source SIEM solution does not verify .deb signatures

2012-11-20 Thread roman . fiedler
It seems that OSSIM does not check the signature when running apt updates via network. This would allow MITM attackers to install arbitrary code when updating OSSIM. The issue seems to be already known for some time although there is no confirmation from the company AlienVault behind it. So it

Re: CVE-2012-4366: Insecure default WPA2 passphrase in multiple Belkin wireless routers

2012-11-20 Thread Jakob Lell
Hi! On 19/11/12 17:28, nauty.m...@gmail.com wrote: Jakob whart difference would it make to use a OCLhashcat with rainbow tables for simply cracking the key? The problem with rainbow tables for WPA2-PSK is that a rainbow table can only be created for one specific network name (ESSID). The

n.runs-SA-2012.004 - SPLUNK Unauthenticated remote DoS

2012-11-20 Thread security
n.runs AG http://www.nruns.com/ security(at)nruns.com n.runs-SA-2012.004 19-Nov-2012 Vendors:Splunk Inc., http://www.splunk.com Product:Splunk 4.0 - 4.3.4 Vulnerability: Unauthenticated remote