CVE-2014-4980 Parameter Tampering in Nessus Web UI - Remote Information Disclosure

2014-07-21 Thread i amroot
Product: Nessus Vendor: Tenable Network Securityā€ˇ Version: Nessus 5.2.3-5.2.7 - Web UI 2.3.4 (potentially lower) Vendor Notified Date: June 24, 2014 Vendor Resolved Date: June 25, 2014 Release Date: July 18, 2014 Risk: Medium Authentication: Not Required Remote: Yes Description: A parameter

[SECURITY] [DSA 2981-1] polarssl security update

2014-07-21 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2981-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso July 18, 2014

CVE-2014-4326 Remote command execution in Logstash zabbix and nagios_nsca outputs.

2014-07-21 Thread Jordan Sissel
Vendor: Elasticsearch Product: Logstash CVE: CVE-2014-4326 Affected versions: Logstash 1.0.14 through 1.4.1 Recommendations: All affected users should upgrade to Logstash 1.4.2. We also provide patch instructions for Logstash 1.3.x at the bottom of this note. The vulnerability impacts

KL-001-2014-002 : Microsoft XP SP3 BthPan.sys Arbitrary Write Privilege Escalation

2014-07-21 Thread KoreLogic Disclosures
Title: Microsoft XP SP3 BthPan.sys Arbitrary Write Privilege Escalation Advisory ID: KL-001-2014-002 Publication Date: 2014-07-18 Publication URL: https://www.korelogic.com/Resources/Advisories/KL-001-2014-002.txt 1. Vulnerability Details Affected Vendor: Microsoft Affected Product:

KL-001-2014-003 : Microsoft XP SP3 MQAC.sys Arbitrary Write Privilege Escalation

2014-07-21 Thread KoreLogic Disclosures
Title: Microsoft XP SP3 MQAC.sys Arbitrary Write Privilege Escalation Advisory ID: KL-001-2014-003 Publication Date: 2014.07.18 Publication URL: https://www.korelogic.com/Resources/Advisories/KL-001-2014-003.txt 1. Vulnerability Details Affected Vendor: Microsoft Affected Product: MQ

[SECURITY] [DSA 2982-1] ruby-activerecord-3.2 security update

2014-07-21 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2982-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff July 19, 2014

[SECURITY] [DSA 2983-1] drupal7 security update

2014-07-21 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2983-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff July 20, 2014