[FD] SEC Consult SA-20220915-0 :: Local Privilege Escalation im SAP® SAPControl Web Service Interface (sapuxuserchk)

2022-09-15 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20220915-0 > === title: Local privilege escalation product: SAP® SAPControl Web Service Interface (sapuxuserchk) vulnerable version: see s

[FD] SEC Consult SA-20220914-0 :: Improper Access Control in SAP® SAProuter

2022-09-15 Thread SEC Consult Vulnerability Lab, Research via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20220914-0 > === title: Improper Access Control product: SAP® SAProuter vulnerable version: see section "Vulnerable / tested versions" fixed

[FD] over 2000 packages depend on abort()ing libgmp

2022-09-15 Thread Georgi Guninski
ping world libgmp is library about big numbers. it is not a library for very big numbers, because if libgmp meets a very big number, it calls abort() and coredumps. 2442 packages depend on libgmp on ubuntu20. guest3@ubuntu20:~/prim$ apt-cache rdepends libgmp10 | wc -l 2442 gawk crash: