[SECURITY] [DSA 4620-1] firefox-esr security update

2020-02-16 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4620-1 secur...@debian.org https://www.debian.org/security/ Moritz Muehlenhoff February 12, 2020

Web Application Firewall bypass via Bluecoat device

2020-02-16 Thread RedTimmy Security
Hi, we have published a new post in our blog titled "How to hack a company by circumventing its WAF through the abuse of a different security appliance and win bug bounties". We basically have [ab]used a Bluecoat device behaving as a request forwarder to mask our malicious payload, avoid WAF

[slackware-security] libarchive (SSA:2020-043-01)

2020-02-16 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] libarchive (SSA:2020-043-01) New libarchive packages are available for Slackware 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +--+

[SECURITY] [DSA 4621-1] openjdk-8 security update

2020-02-16 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4621-1 secur...@debian.org https://www.debian.org/security/ Moritz Muehlenhoff February 12, 2020

[TZO-15-2020] - F-SECURE Generic Malformed Container bypass (RAR)

2020-02-16 Thread Thierry Zoller
From the low-hanging-fruit-department F-SECURE Generic Malformed Container bypass (RAR) Ref : [TZO-15-2020] -

WebKitGTK and WPE WebKit Security Advisory WSA-2020-0002

2020-02-16 Thread Carlos Alberto Lopez Perez
WebKitGTK and WPE WebKit Security Advisory WSA-2020-0002 Date reported : February 14, 2020 Advisory ID :

CVE-2020-0728: Windows Modules Installer Service Information Disclosure Vulnerability

2020-02-16 Thread Imre Rad
The TrustedInstaller service running on the Windows operating system hosts a COM service called Sxs Store Class; its ISxsStore interface provides methods to install/uninstall assemblies via application manifests files into the WinSxS store. These API methods were meant to be available for users

[SECURITY] [DSA 4624-1] evince security update

2020-02-16 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4624-1 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso February 14, 2020

[SECURITY] [DSA 4625-1] thunderbird security update

2020-02-16 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4625-1 secur...@debian.org https://www.debian.org/security/ Moritz Muehlenhoff February 15, 2020