[security bulletin] HPESBGN03766 rev.1 - HPE Project and Portfolio Management (PPM), Remote Cross-Site Scripting

2017-08-02 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03766en_us SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: hpesbgn03766en_us Version: 1

[security bulletin] HPESBHF03763 rev.1 - HPE Comware 7, IMC, VCX products using OpenSSL, Remote Denial of Service (DoS)

2017-08-02 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03763en_us SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: hpesbhf03763en_us Version: 1

[slackware-security] gnupg (SSA:2017-213-01)

2017-08-02 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] gnupg (SSA:2017-213-01) New gnupg packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog:

CVE-2017-1500 - Relected XSS in IBM WorkLight OAuth Server Web Api

2017-08-02 Thread gabriele . gristina
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Reflected Cross-Site Scripting in IBM Worklight OAuth Server Web Api Table of Contents = 0. Overview 1. Detailed Description 2. Proof Of Concept 3. Solution 4. Disclosure Timeline

[SECURITY] [DSA 3924-1] varnish security update

2017-08-02 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3924-1 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 02, 2017