Still beginner's errors (and outdated 3rd party components) in QuickTime 7.7.6 and iTunes 12.0.1

2014-10-27 Thread Stefan Kanthak
Hi @ll, the just released QuickTime 7.7.6 and iTunes 12.0.1 for Windows still have quite some of the beginners errors I documented in http://seclists.org/fulldisclosure/2014/Aug/33 and http://seclists.org/fulldisclosure/2014/Aug/44 QuickTime 7.7.6:

iTunes 12.0.1 for Windows: still COMPLETELY outdated and VULNERABLE 3rd party libraries

2014-10-27 Thread Stefan Kanthak
Hi @ll, the just released iTunes 12.0.1 for Windows still (cf. http://seclists.org/fulldisclosure/2014/Jul/30) comes with COMPLETELY outdated and VULNERAEBLE 3rd party libraries (as part of AppleMobileDeviceSupport.msi): * libeay32.dll and ssleay32.dll 0.9.8d are more than SEVEN years old

NEW VMSA-2014-0011 VMware vSphere Data Protection product update addresses a critical information disclosure vulnerability

2014-10-27 Thread VMware Security Response Center
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - VMware Security Advisory Advisory ID: VMSA-2014-0011 Synopsis:VMware vSphere Data Protection product update addresses a critical

[CVE-2014-8347] Filemaker Login Bypass and Privilege Escalation

2014-10-27 Thread g-damore
Filemaker Login Bypass and Privilege Escalation === [ADVISORY INFORMATION] Title: Filemaker Login Bypass and Privilege Escalation Discovery date: 19/10/2014 Release date: 19/10/2014 Vendor

Call for Papers - WorldCIST'15 - Azores, 1 - 3 April 2015

2014-10-27 Thread ML
-- WorldCIST'15 - 3rd World Conference on Information Systems and Technologies Ponta Delgada, Azores *, Portugal 1 - 3 April 2015 http://www.aisti.eu/worldcist15/ -- * Azores is ranked as the second most beautiful archipelago in the world by National Geographic. SCOPE The

[SECURITY] [DSA 3056-1] libtasn1-3 security update

2014-10-27 Thread Sebastien Delafond
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-3056-1 secur...@debian.org http://www.debian.org/security/Sebastien Delafond October 26, 2014

[SECURITY] [DSA 3057-1] libxml2 security update

2014-10-27 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-3057-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst October 26, 2014