[security bulletin] HPSBMU03074 rev.1 - HP Insight Control server migration on Linux and Windows running OpenSSL, Remote Denial of Service (DoS), Code Execution, Unauthorized Access, Disclosure of Inf

2014-07-24 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04378799 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04378799 Version: 1 HPSBMU03074

Beginner's error: import function of Windows Mail executes rogue program C:\Program.exe with credentials of other account

2014-07-24 Thread Stefan Kanthak
Hi @ll, the import function of Windows Mail executes a rogue program C:\Program.exe with the credentials of another account, resulting in a privilege escalation! 1. Fetch http://home.arcor.de/skanthak/download/SENTINEL.EXE and save it as C:\Program.exe 2. Start Windows Mail (part of Windows

[SECURITY] [DSA 2986-1] iceweasel security update

2014-07-24 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2986-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff July 23, 2014

[security bulletin] HPSBMU03076 rev.1 - HP Systems Insight Manager (SIM) on Linux and Windows running OpenSSL, Multiple Vulnerabilities

2014-07-24 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04379485 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04379485 Version: 1 HPSBMU03076

[slackware-security] httpd (SSA:2014-204-01)

2014-07-24 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] httpd (SSA:2014-204-01) New httpd packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +--+

[SECURITY] [DSA 2987-1] openjdk-7 security update

2014-07-24 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2987-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff July 23, 2014

[slackware-security] mozilla-firefox (SSA:2014-204-02)

2014-07-24 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] mozilla-firefox (SSA:2014-204-02) New mozilla-firefox packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +--+

Barracuda Networks Firewall 6.1.2 #36 - Filter Bypass Exception Handling Vulnerability + PoC Video BNSEC-2398

2014-07-24 Thread Vulnerability Lab
Document Title: === Barracuda Networks Firewall 6.1.2 #36 - Filter Bypass Exception Handling Vulnerability + PoC Video References (Source): http://www.vulnerability-lab.com/get_content.php?id=1102 Barracuda Networks Security ID (BNSEC): BNSEC-2398

[slackware-security] mozilla-thunderbird (SSA:2014-204-03)

2014-07-24 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] mozilla-thunderbird (SSA:2014-204-03) New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +--+