[FD] CA20140413-01: Security Notice for OpenSSL Heartbleed Vulnerability

2014-05-16 Thread Williams, James K
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CA20140413-01: Security Notice for OpenSSL Heartbleed Vulnerability Issued: April 13, 2014 Updated: May 12, 2014 CA Technologies is investigating an OpenSSL vulnerability, referred to as the "Heartbleed bug" that was publicly disclosed on April 7

[FD] HP Release Control Authenticated Privilege Escalation and XXE

2014-05-16 Thread Brandon Perry
Hi, Linked is a gist detailing a few vulnerabilities I found in HP Release Control 9.20., Build 395. You can download it on the On-premise software tab here: http://www8.hp.com/us/en/software-solutions/software.html?compURI=1350467#.U3aJWl5-_8s Basically, the first request an admin makes whe

Re: [FD] Beginners error: iTunes for Windows runs rogue program C:\Program.exe when opening associated files

2014-05-16 Thread Stefan Kanthak
Hi @ll, > the current version of iTunes for Windows (and of course older versions > too) associates the following vulnerable command lines with some of the > supported file types/extensions: [...] The just released iTunes 11.2 still has this beginners error. Unpack the iTunesSetup.exe (this is