Re "Intel responds to security research findings"

2018-01-03 Thread Ed Maste
With respect to https://newsroom.intel.com/news/intel-responds-to-security-research-findings/ The FreeBSD Security Team recently learned of the details of these issues that affect certain CPUs. Details could not be discussed publicly, but mitigation work is in progress. Work is ongoing to

[security bulletin] HPESBHF03803 rev.1 - Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance, Remote Denial of Service and Execution of Code

2018-01-03 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03803en_us SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: hpesbhf03803en_us Version: 1

Intel CPU bug forcing page table switch during syscalls?

2018-01-03 Thread Pavel Machek
Hi! It looks like there's Intel CPU bug, allowing prefetch from kernel memory. It seems to be reason KASLR patches are pushed so fast to Linux. https://mobile.twitter.com/brainsmoke/status/948561799875502080/photo/1 https://forums.freebsd.org/threads/63955/page-2#post-371276 Hmm. Does that

[security bulletin] MFSBGN03793 rev.2 - Project and Portfolio Management Center, Multiple vulnerabilities

2018-01-03 Thread cyber-psrt
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Note: the current version of the following document is available here: https://softwaresupport.hpe.com/document/-/facetsearch/document/KM03014426 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: KM03014426 Version: 2 MFSBGN03793 rev.2 -

CVE-2017-6094 - Genexis GAPS Access Control Vulnerability

2018-01-03 Thread Antoine Neuenschwander
# # # CVE-2017-6094 - Genexis GAPS Access Control Vulnerability# #