[security bulletin] HPSBGN03434 rev.1 - HP Continuous Delivery Automation using Java Deserialization, Remote Arbitrary Code Execution

2016-02-07 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_n a-c04958567 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04958567 Version: 1 HPSBGN03434

[CVE-2016-0602, CVE-2016-0603] Executable installers are vulnerable^WEVIL (case 24): Oracle Java 6/7/8 SE and VirtualBox

2016-02-07 Thread Stefan Kanthak
Hi @ll, the installers or Oracle's Java 6/7/8 for Windows and VirtualBox for Windows load and execute several DLLs from their "application directory". * The online installer jxpiinstall.exe: UXTheme.dll and RASAdHlp.dll plus (on Windows XP) SetupAPI.dll, HNetCfg.dll and XPSP2Res.dll (on

[security bulletin] HPSBGN03430 rev.3 - HP ArcSight products, Local Elevation of Privilege

2016-02-07 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_n a-c04872416 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04872416 Version: 3 HPSBGN03430

[SECURITY] [DSA 3468-1] polarssl security update

2016-02-07 Thread Sebastien Delafond
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3468-1 secur...@debian.org https://www.debian.org/security/ Sebastien Delafond February 06, 2016

WordPress User Meta Manager Plugin [Information Disclosure]

2016-02-07 Thread Panagiotis Vagenas
* Exploit Title: WordPress User Meta Manager Plugin [Information Disclosure] * Discovery Date: 2015-12-28 * Public Disclosure Date: 2016-02-01 * Exploit Author: Panagiotis Vagenas * Contact: https://twitter.com/panVagenas * Vendor Homepage: http://jasonlau.biz/home/ * Software Link:

[security bulletin] HPSBHF03431 rev.2 - HPE Network Switches, local Bypass of Security Restrictions, Indirect Vulnerabilities

2016-02-07 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_n a-c04920918 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04920918 Version: 2 HPSBHF03431

Multiple vulnerabilities in Open Real Estate v 1.15.1

2016-02-07 Thread Simon Waters (Surevine)
Introduction: Open Real Estate is an open source CMS for managing estate agent websites. It is written in PHP and uses the YII CMF. It supports multiple languages. It is supported by MonoRay.net The product has a number of commercial support offerings available and an internal market for

[SECURITY] [DSA 3467-1] tiff security update

2016-02-07 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3467-1 secur...@debian.org https://www.debian.org/security/ Laszlo Boszormenyi (GCS) February 06, 2016

CFP: SIN 2016 - 9th International Conference on Security of Information and Networks

2016-02-07 Thread Hossain Shahriar
= Please accept our apologies if you receive multiple copies of this CFP = CALL FOR CONTRIBUTIONS == 9th International Conference on