[security bulletin] HPSBPI03147 rev.1 - Certain HP Color LaserJet Printers, Remote Unauthorized Access, Denial of Service (DoS)

2014-10-31 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04483249 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04483249 Version: 1 HPSBPI03147

[security bulletin] HPSBUX03162 SSRT101767 rev.1 - HP-UX Running OpenSSL, Remote Denial of Service (DoS), Unauthorized Access, Man-in-the-Middle (MitM) Attack

2014-10-31 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04492722 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04492722 Version: 1 HPSBUX03162

[SYSS-2014-008] McAfee File and Removable Media Protection (FRP/EEFF/EERM) - Use of a One-Way Hash with a Predictable Salt (CVE-2014-8565)

2014-10-31 Thread matthias . deeg
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Advisory ID: SYSS-2014-008 Product(s): McAfee Endpoint Encryption for Files and Folders (EEFF) McAfee File and Removable Media Protection (FRP) Vendor:

SEC Consult SA-20141031-0 :: XML External Entity Injection (XXE) and Reflected XSS in Scalix Web Access

2014-10-31 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory 20141031-0 === title: XML External Entity Injection (XXE) and Reflected XSS product: Scalix Web Access vulnerable version: 11.4.6.12377 and 12.2.0.14697

[SE-2014-01] Missing patches / inaccurate information regarding Oracle Oct CPU

2014-10-31 Thread Security Explorations
Hello All, We've been recently informed by a 3rd party that Oracle planned to release fixes for the vulnerabilities covered by our SE-2014-01 [1] project in Nov 2014. We initially thought that someone mistakenly took Oct for Nov (Oracle CPU was released on Oct 14, 2014), but the credibility of

[SECURITY] [DSA 3060-1] linux security update

2014-10-31 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3060-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso October 31, 2014