[SECURITY] [DSA 4115-1] quagga security update

2018-02-15 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4115-1 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso February 15, 2018

Re: [FD] Defense in depth -- the Microsoft way (part 51): Skype's home-grown updater allows escalation of privilege to SYSTEM

2018-02-15 Thread Stefan Kanthak
"Jeffrey Walton" wrote: > On Fri, Feb 9, 2018 at 1:01 PM, Stefan Kanthak > wrote: [ http://seclists.org/fulldisclosure/2018/Feb/33 ] > Not sure if this is related, but: > https://winbuzzer.com/2018/02/14/microsoft-just-killed-skype-classic-response-unfixable-security-bug-xcxwbn/ This is of c

Vulnerability Disclosure (Web Apps)-Bravo Tejari Web Portal-Unrestricted File Upload

2018-02-15 Thread Arvind Vishwakarma
-- Vulnerability Type: Unrestricted File Upload Vendor of Product: Tejari Affected Product Code Base: Bravo Solution Affected Component: Web Interface Management. Attack Type: Local - Authenticated Impact: Malicous File Upload

Vulnerability Disclosure (Web Apps)-Bravo Tejari Web Portal-CSRF

2018-02-15 Thread Arvind Vishwakarma
- Vulnerability Type: Cross Site Request Forgery (CSRF) Vendor of Product: Tejari Affected Product Code Base: Bravo Solution Affected Component: Web Interface Management. Attack Type: Local - Authenticated Impact: Unauthorised Access -