[FD] SEC Consult SA-20170804-1 :: Ubiquiti Networks UniFi Cloud Key authenticated command injection

2017-08-04 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20170804-1 > === title: Authenticated Command Injection product: Ubiquiti Networks UniFi Cloud Key vulnerable version: Firmware v0.6.1

[FD] SEC Consult SA-20170804-0 :: phpBB Server Side Request Forgery (SSRF) vulnerability

2017-08-04 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20170804-0 > === title: Server Side Request Forgery Vulnerability product: phpBB vulnerable version: 3.2.0 fixed version: 3.2.1 CVE

[FD] [CVE-2017-7533] kernel: inotify: a race between inotify_handle_event() and sys_rename()

2017-08-04 Thread Vladis Dronov
Hello, A race condition was found in Linux kernel present since v3.14-rc1 upto v4.12 including. The race happens between threads of inotify_handle_event() and vfs_rename() while running the rename operation against the same file. The next slab data or the slab's free list pointer can be corrupted

[FD] t2'17: Challenge – a break from tradition

2017-08-04 Thread Tomi Tuominen
This year’s pre-conference challenge will be a t2 exclusive bug bounty. For more information on how to participate, please see: https://t2.fi/challenge/t217-challenge/ As we’ve been organizing challenges for over a decade, you might wonder why change now? For several years in a row, the

[FD] Format Factory DLL Hijacking Vulnerability

2017-08-04 Thread kyaw thiha
Format Factory DLL Hijacking Vulnerability Product --- Format Factory is a comprehensive audio, video and photo converter and ripper that will satisfy your every need, all by having simple interface that can be used by everyone. Download Format Factory Offline Installer Setup for