[Full-disclosure] CVE-2013-3666 - LG Optimus G command injection (as system user) vulnerability

2013-05-25 Thread Justin Case
Device: LG Optimus G E973 (Others affected) Firmware: Android 4.1.2 JZO54k (Others affected) Evidence: http://youtu.be/ZfbDIpTY-t4 A vulnerability in LG's "HiddenMenu" allows you to execute shell commands as the system, with a large array of additional permissions (Groups). This vulnerability open

Re: [Full-disclosure] Sony PS3 Firmware v4.31 - Code Execution Vulnerability

2013-05-25 Thread Julius Kivimäki
I went and dug out my PS3 and tested this. Results: particularly crappy HTML execution, useless. I don't know what world you live in, but calling this a security vulnerability would be a wild exaggeration. 2013/5/21 Vulnerability Lab > Title: > == > Sony PS3 Firmware v4.31 - Code Execution

[Full-disclosure] [SECURITY] [DSA 2693-1] libx11 security update

2013-05-25 Thread Raphael Geissert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2693-1 secur...@debian.org http://www.debian.org/security/ Raphael Geissert May 24, 2013

[Full-disclosure] [SECURITY] [DSA 2675-2] libxvmc regression update

2013-05-25 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2675-2 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst May 24, 2013