Couchbase Server - Remote Code Execution

2018-08-23 Thread x ksi
Hey, Description: Couchbase Server [1] exposes REST API [2] which by default is available on TCP/8091 and/or TCP/18091. Authenticated users can send arbitrary Erlang code to 'diag/eval' endpoint of the API. The code will be subsequently executed in the underlying operating system with privileges

Seagate Media Server multiple SQL injection vulnerabilities

2018-08-23 Thread Summer of Pwnage
Seagate Media Server multiple SQL injection vulnerabilities Yorick Koster, September 2017

[SECURITY] [DSA 4279-2] linux regression update

2018-08-23 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4279-2 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 22, 2018