[slackware-security] pidgin (SSA:2017-074-01)

2017-03-15 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] pidgin (SSA:2017-074-01) New pidgin packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog:

Path Traversal Remote File Disclosure

2017-03-15 Thread hyp3rlinx
[+] Credits: John Page AKA hyp3rlinx [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/MOBAXTERM-TFTP-PATH-TRAVERSAL-REMOTE-FILE-ACCESS.txt [+] ISR: ApparitionSec Vendor: = mobaxterm.mobatek.net Product:

CVE-2017-0045 Windows DVD Maker XML External Entity File Disclosure

2017-03-15 Thread hyp3rlinx
[+] Credits: John Page AKA hyp3rlinx [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/MICROSOFT-DVD-MAKER-XML-EXTERNAL-ENTITY-FILE-DISCLOSURE.txt [+] ISR: ApparitionSec Vendor: = www.microsoft.com Product: =

Cisco Security Advisory: Cisco Workload Automation and Tidal Enterprise Scheduler Client Manager Server Arbitrary File Read Vulnerability

2017-03-15 Thread psirt
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Workload Automation and Tidal Enterprise Scheduler Client Manager Server Arbitrary File Read Vulnerability Advisory ID: cisco-sa-20170315-tes Revision: 1.0 For Public Release: 2017 March 15 16:00 GMT Last Updated

Cisco Security Advisory: Cisco Mobility Express 1800 Access Point Series Authentication Bypass Vulnerability

2017-03-15 Thread psirt
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Mobility Express 1800 Access Point Series Authentication Bypass Vulnerability Advisory ID: cisco-sa-20170315-ap1800 Revision: 1.0 For Public Release: 2017 March 15 16:00 GMT Last Updated: 2017 March 15 16:00 GMT

Cisco Security Advisory: Cisco StarOS SSH Privilege Escalation Vulnerability

2017-03-15 Thread psirt
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco StarOS SSH Privilege Escalation Vulnerability Advisory ID: cisco-sa-20170315-asr Revision: 1.0 For Public Release: 2017 March 15 16:00 GMT Last Updated: 2017 March 15 16:00 GMT CVE ID(s): CVE-2017-3819 CVSS Score v