[SECURITY] [DSA 3008-2] php5 regression update

2014-08-22 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3008-2 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso August 21, 2014

[CVE-2014-5335] CSRF in Innovaphone PBX

2014-08-22 Thread rg
Title: Innovaphone PBX Admin-GUI CSRF Impact: High CVSS2 Score: 7.8 (AV:N/AC:M/Au:S/C:P/I:C/A:C/E:F/RL:U/RC:C) Announced: August 21, 2014 Reporter: Rainer Giedat (NSIDE ATTACK LOGIC GmbH, www.nsideattacklogic.de) Products: Innovaphone PBX Administration GUI Affected Versions: all known versions

CVE-2014-3575:OpenOffice Targeted Data Exposure Using Crafted OLE Objects

2014-08-22 Thread Herbert Duerr
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2014-3575 OpenOffice Targeted Data Exposure Using Crafted OLE Objects Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache OpenOffice 4.1.0 and older on Windows. OpenOffice.org versions are also

CVE-2014-3524: Apache OpenOffice Calc Command Injection Vulnerability

2014-08-22 Thread Herbert Duerr
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2014-3524 OpenOffice Calc Command Injection Vulnerability Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache OpenOffice 4.1.0 and older on Windows. OpenOffice.org versions may also be affected.

[SECURITY] [DSA 3009-1] python-imaging security update

2014-08-22 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-3009-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff August 21, 2014

[security bulletin] HPSBST03098 rev.1 - HP StoreEver MSL6480 Tape Library running OpenSSL, Remote Unauthorized Access or Disclosure of Information

2014-08-22 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04406535 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04406535 Version: 1 HPSBST03098

DoS attacks (ICMPv6-based) resulting from IPv6 EH drops

2014-08-22 Thread Fernando Gont
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Folks, Ten days ago or so we published this I-D: http://www.ietf.org/internet-drafts/draft-gont-v6ops-ipv6-ehs-in-real-world-00.txt Section 5.2 of the I-D discusses a possible attack vector based on a combination of forged ICMPv6 PTB messages and