«
Expand/Collapse
225 items tagged "update"
Related tags:
vmware [+],
software update [+],
os x [+],
denial of service [+],
vulnerability [+],
rpm [+],
package [+],
nss [+],
mac os x [+],
mac os [+],
attribute [+],
security [+],
usn [+],
ubuntu [+],
security advisory [+],
linux [+],
arbitrary code [+],
dsa [+],
user [+],
txt [+],
renegotiation [+],
nspr [+],
manager [+],
directory traversal vulnerability [+],
based buffer overflow [+],
firefox [+],
file [+],
apple software [+],
tv software [+],
security notice [+],
robots [+],
python [+],
morten krakvik [+],
linux security [+],
jetty web [+],
jetty [+],
integer overflow [+],
chromium [+],
apple tv [+],
adobe [+],
x lion [+],
version [+],
trojan [+],
sun patch [+],
solaris [+],
server [+],
proof of concept [+],
postgresql [+],
movabletype [+],
lion [+],
java sandbox [+],
iphone [+],
information disclosure [+],
icq [+],
http [+],
home [+],
exploits [+],
django [+],
defense in depth [+],
default browser [+],
arbitrary files [+],
application crash [+],
android [+],
adobe website [+],
adobe flash player [+],
bugtraq [+],
wordpress [+],
wheeled robots [+],
vcenter [+],
team [+],
tavis ormandy [+],
tackles [+],
symlink [+],
ssl [+],
security vulnerability [+],
rsa [+],
roll ups [+],
robotics [+],
request [+],
qemu [+],
plugs [+],
perl security [+],
pcscd [+],
pcre library [+],
pcre [+],
pattern options [+],
pam [+],
overflow [+],
null pointer [+],
manager. for [+],
manager server [+],
manager appliance [+],
load c [+],
key [+],
java update [+],
irssi [+],
irc proxy [+],
ios [+],
google [+],
ffmpeg [+],
esx [+],
escalation [+],
directory traversal [+],
default version [+],
debian linux [+],
cyrus imapd [+],
critical flaws [+],
component updates [+],
classic [+],
bzip [+],
bof [+],
automated system [+],
authdata [+],
attacker [+],
apple issues [+],
aerial acrobatics [+],
active directory client [+],
acrobatic [+],
zeus [+],
zero day [+],
zero [+],
zenta [+],
your [+],
xprotect [+],
xbox 360 [+],
xbox [+],
x security [+],
x froyo [+],
world [+],
work [+],
wooden shelf [+],
wi fi access point [+],
wheel barrow [+],
webkit [+],
vmware virtualcenter [+],
virus [+],
virtualcenter [+],
virtinst [+],
verison [+],
vacuum tweezers [+],
vacuum head [+],
vacuum [+],
upgrade [+],
type [+],
tv models [+],
tuesday [+],
tryton [+],
traffic redirection [+],
touchscreen interface [+],
time [+],
tim [+],
thunderbird [+],
third party [+],
terminal connection [+],
telepathy [+],
tehtri security [+],
targets [+],
tactic [+],
suspicious [+],
suse security [+],
sun [+],
strikes [+],
strategy tactics [+],
stairmonster [+],
sophos [+],
sony [+],
some [+],
softwareupdateadmin [+],
software development kit [+],
slaps [+],
shawn mccombs [+],
server security [+],
server down [+],
server crash [+],
sensor circuits [+],
security vulnerabilities [+],
security holes [+],
security flaw [+],
security co [+],
security announcement [+],
sebastian steppeler [+],
scriptingobjectmodel [+],
scope [+],
sarnoff [+],
samsung tv [+],
samsung [+],
samba [+],
safari browser [+],
safari [+],
robot [+],
retired [+],
regression [+],
red hat security [+],
red [+],
reading package [+],
reader [+],
rapid fire [+],
rants [+],
proftpd [+],
point in time [+],
playstation 3 [+],
playstation [+],
pixel [+],
piston [+],
piano [+],
pgsql [+],
peer [+],
pdns [+],
patch [+],
party [+],
panda security [+],
panda [+],
oscilloscope [+],
original project [+],
oracle java [+],
optical sensors [+],
openssl [+],
open [+],
ondrej stanek [+],
omnitouch [+],
musical [+],
multitouch [+],
multiple [+],
ms security [+],
minor improvements [+],
microtouch [+],
microprocessor [+],
mhz [+],
memory access [+],
mcafee [+],
matt sarnoff [+],
manager. one [+],
malware [+],
mal [+],
makes [+],
mac os x security [+],
look at the walk [+],
location [+],
local privilege escalation [+],
linux update [+],
linux support [+],
line following robot [+],
line follower [+],
libxml [+],
libvorbis [+],
libvirt [+],
leopard [+],
leaves [+],
leaked [+],
lawnbot [+],
kills [+],
kernel [+],
kenneth geers [+],
kaspersky [+],
iwork [+],
ipv [+],
intel [+],
important security [+],
image [+],
ifupdown [+],
hushing [+],
hpediag [+],
hp software [+],
hospitals [+],
heart rate monitor [+],
hardware upgrade [+],
hardware hacks [+],
handshake message [+],
handhelds [+],
hackers [+],
gpg signature [+],
gnash [+],
glimpse [+],
geers [+],
gameboy [+],
game [+],
gabble [+],
g users [+],
framework [+],
foxit [+],
foomatic [+],
flashback [+],
flash player [+],
firmware update [+],
firmware [+],
fire [+],
fake [+],
evilgrade [+],
esxi [+],
entertainment [+],
enemies [+],
encoding algorithm [+],
electric keyboard [+],
dynamic [+],
droid [+],
driven [+],
dns [+],
dll [+],
disclosure of information [+],
dfsg [+],
debian security [+],
day [+],
david black [+],
cvs [+],
custom libraries [+],
critical security [+],
concept [+],
computer [+],
common security [+],
commenters [+],
coin cells [+],
code execution [+],
code [+],
cnc [+],
clickjacking [+],
chris harrison [+],
cgiirc [+],
cd media [+],
camera enclosure [+],
ca certificates [+],
busy working [+],
buffer overflow [+],
brad [+],
boxes [+],
bonkers [+],
blackberry [+],
black hat [+],
bit computer [+],
bit [+],
bip [+],
bind [+],
bill [+],
bike handlebars [+],
authentication [+],
atom [+],
asia [+],
arp spoofing [+],
archive [+],
april 1 [+],
apple posts [+],
apple mac os x [+],
apple mac os [+],
apple accused [+],
apod [+],
anti virus [+],
announcement [+],
alexander eisen [+],
aes encryption [+],
adsense [+],
activex control [+],
Support [+],
Skype [+],
Issues [+],
hacks [+],
Software [+],
apple security [+],
apple [+],
advisory [+],
man in the middle attack [+],
tls [+],
steve dispensa [+],
sslv3 [+],
marsh ray [+],
java [+]
-
-
10:01
»
Hack a Day
This image should look familiar to regular readers. It’s a concept that [Chris Harrison] has been working on for a while, and this hardware upgrade uses equipment which which we’re all familiar. The newest rendition, which is named the Omnitouch, uses a shoulder-mounted system for both input and output. The functionality is the same as [...]
-
-
15:26
»
Packet Storm Security Advisories
Apple Security Advisory 2012-05-14-2 - This update disables Adobe Flash Player if it is older than 10.1.102.64 by moving its files to a new directory. This update presents the option to install an updated version of Flash Player from the Adobe website.
-
15:26
»
Packet Storm Security Recent Files
Apple Security Advisory 2012-05-14-2 - This update disables Adobe Flash Player if it is older than 10.1.102.64 by moving its files to a new directory. This update presents the option to install an updated version of Flash Player from the Adobe website.
-
15:26
»
Packet Storm Security Misc. Files
Apple Security Advisory 2012-05-14-2 - This update disables Adobe Flash Player if it is older than 10.1.102.64 by moving its files to a new directory. This update presents the option to install an updated version of Flash Player from the Adobe website.
-
-
18:14
»
Packet Storm Security Advisories
Apple Security Advisory 2012-04-03-1 - Java for OS X 2012-001 and Java for Mac OS X 10.6 Update 7 is now available. It addresses multiple vulnerabilities that exist in Java 1.6.0_29, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox.
-
18:14
»
Packet Storm Security Recent Files
Apple Security Advisory 2012-04-03-1 - Java for OS X 2012-001 and Java for Mac OS X 10.6 Update 7 is now available. It addresses multiple vulnerabilities that exist in Java 1.6.0_29, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox.
-
18:14
»
Packet Storm Security Misc. Files
Apple Security Advisory 2012-04-03-1 - Java for OS X 2012-001 and Java for Mac OS X 10.6 Update 7 is now available. It addresses multiple vulnerabilities that exist in Java 1.6.0_29, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox.
-
-
18:33
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0139-01 - The Sun 1.6.0 Java release includes the Sun Java 6 Runtime Environment and the Sun Java 6 Software Development Kit. This update fixes several vulnerabilities in the Sun Java 6 Runtime Environment and the Sun Java 6 Software Development Kit. Further information about these flaws can be found on the Oracle Java SE Critical Patch page, listed in the References section. All users of java-1.6.0-sun are advised to upgrade to these updated packages, which provide JDK and JRE 6 Update 31 and resolve these issues. All running instances of Sun Java must be restarted for the update to take effect.
-
18:31
»
Packet Storm Security Advisories
Ubuntu Security Notice 1284-2 - USN-1284-1 fixed vulnerabilities in Update Manager. One of the fixes introduced a regression for Kubuntu users attempting to upgrade to a newer Ubuntu release. This update fixes the problem. David Black discovered that Update Manager incorrectly extracted the downloaded upgrade tarball before verifying its GPG signature. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to replace arbitrary files. David Black discovered that Update Manager created a temporary directory in an insecure fashion. A local attacker could possibly use this flaw to read the XAUTHORITY file of the user performing the upgrade. This update also adds a hotfix to Update Notifier to handle cases where the upgrade is being performed from CD media. Various other issues were also addressed.
-
14:31
»
Hack a Day
[Shawn McCombs] has been spending some time refining his Xbox 360 rapid fire hack. This time around he’s got a lot more features, many of which we haven’t really seen before. When we looked at the original project he had added an ATtiny85 which read a potentiometer to set the rapid fire speed for one [...]
-
-
5:33
»
Packet Storm Security Advisories
SUSE Security Announcement - This is the SUSE-SU-403 Forbidden-1 security update for OpenSSL. This update improves the ClientHello handshake message parsing function. Prior to this update is was possible that this function reads beyond the end of a message leading to invalid memory access and a crash. Under some circumstances it was possible that information from the OCSP extensions was disclosed.
-
-
14:01
»
Hack a Day
This tiny line-following robot is quite impressive. It’s [Ondrej Stanek's] second take on the design, which he calls PocketBot 2. Just like the earlier version, this robot is small enough to fit in a matchbox, but it’s received several upgrades in this iteration. The coin cells that ran the previous version have been replaced by [...]
-
-
20:35
»
Packet Storm Security Advisories
Apple Security Advisory 2011-11-14-1 - iTunes 10.5.1 is now available and addresses a man-in-the-middle vulnerability. iTunes periodically checks for software updates using an HTTP request to Apple. This request may cause iTunes to indicate that an update is available. If Apple Software Update for Windows is not installed, clicking the Download iTunes button may open the URL from the HTTP response in the user's default browser. This issue has been mitigated by using a secured connection when checking for available updates. For OS X systems, the user's default browser is not used because Apple Software Update is included with OS X, however this change adds additional defense-in-depth.
-
20:35
»
Packet Storm Security Recent Files
Apple Security Advisory 2011-11-14-1 - iTunes 10.5.1 is now available and addresses a man-in-the-middle vulnerability. iTunes periodically checks for software updates using an HTTP request to Apple. This request may cause iTunes to indicate that an update is available. If Apple Software Update for Windows is not installed, clicking the Download iTunes button may open the URL from the HTTP response in the user's default browser. This issue has been mitigated by using a secured connection when checking for available updates. For OS X systems, the user's default browser is not used because Apple Software Update is included with OS X, however this change adds additional defense-in-depth.
-
20:35
»
Packet Storm Security Misc. Files
Apple Security Advisory 2011-11-14-1 - iTunes 10.5.1 is now available and addresses a man-in-the-middle vulnerability. iTunes periodically checks for software updates using an HTTP request to Apple. This request may cause iTunes to indicate that an update is available. If Apple Software Update for Windows is not installed, clicking the Download iTunes button may open the URL from the HTTP response in the user's default browser. This issue has been mitigated by using a secured connection when checking for available updates. For OS X systems, the user's default browser is not used because Apple Software Update is included with OS X, however this change adds additional defense-in-depth.
-
-
15:18
»
Packet Storm Security Recent Files
RSA has delivered an update on RSA Key Manager Appliance 2.7 Service Pack1 that includes security related component updates including Oracle Critical Patch Update (CPU) July 2011 and RSA Access Manager Server, security vulnerability fix, hot fix roll-ups and bug fixes.
-
15:18
»
Packet Storm Security Misc. Files
RSA has delivered an update on RSA Key Manager Appliance 2.7 Service Pack1 that includes security related component updates including Oracle Critical Patch Update (CPU) July 2011 and RSA Access Manager Server, security vulnerability fix, hot fix roll-ups and bug fixes.
-
-
19:32
»
Packet Storm Security Advisories
Apple Security Advisory 2011-10-12-2 - An Apple TV software update is now available and addresses credential interception, spoofing, information disclosure, and various other vulnerabilities.
-
19:32
»
Packet Storm Security Recent Files
Apple Security Advisory 2011-10-12-2 - An Apple TV software update is now available and addresses credential interception, spoofing, information disclosure, and various other vulnerabilities.
-
19:32
»
Packet Storm Security Misc. Files
Apple Security Advisory 2011-10-12-2 - An Apple TV software update is now available and addresses credential interception, spoofing, information disclosure, and various other vulnerabilities.
-
-
13:08
»
Hack a Day
[Sebastian Steppeler] has been hard at work on his optical sensors for an electric piano. When we looked in on the project back in October he was testing reflective sensors to increase responsiveness and MIDI data resolution for his electric keyboard. Since then he’s finalized the sensor circuits and produced enough boards to monitor all [...]
-
-
6:08
»
Hack a Day
The “Stairmonster 2” is an updated verison of the hyper speed, home brew stairmaster we covered back in November. It still features most of its original version’s features including a very sturdy construction, heart rate monitor, and 320×240 touchscreen interface. What is new about the Stairmonster 2 is its handlebars. V1 used stationary bike handlebars, [...]
-
-
12:27
»
Hack a Day
[Tim's] been busy moving his pick-and-place build toward completion. We looked in on the first version of the vacuum head back in October. Since then he’s ditched the camera enclosure which allows for more light and better mounting. The tip has been replaced by one from a pair of vacuum tweezers, and the whole thing [...]
-
-
15:00
»
Hack a Day
It looks like [rossum] and [Ladyada] have teamed up and been busy working on the microtouch. Since we covered it last year its had a few minor improvements like an upgrade to the ATmega32u4 microprocessor and some new software. The new and improved microtouch also features an accelerometer as well as some software to go along with it. Plus its now [...]
-
-
8:22
»
Packet Storm Security Exploits
ICQ 7 does not check the identity of the update server or the authenticity of the updates that it downloads through its automatic update mechanism. By impersonating the update server (think DNS spoofing), an attacker can act as an update server of its own and deliver arbitrary files that are executed on the next launch of the ICQ client. Since ICQ is automatically launched right after booting Windows by default and it checks for updates on every start, it can be attacked very reliably.Proof of concept code included.
-
8:22
»
Packet Storm Security Recent Files
ICQ 7 does not check the identity of the update server or the authenticity of the updates that it downloads through its automatic update mechanism. By impersonating the update server (think DNS spoofing), an attacker can act as an update server of its own and deliver arbitrary files that are executed on the next launch of the ICQ client. Since ICQ is automatically launched right after booting Windows by default and it checks for updates on every start, it can be attacked very reliably.Proof of concept code included.
-
8:22
»
Packet Storm Security Misc. Files
ICQ 7 does not check the identity of the update server or the authenticity of the updates that it downloads through its automatic update mechanism. By impersonating the update server (think DNS spoofing), an attacker can act as an update server of its own and deliver arbitrary files that are executed on the next launch of the ICQ client. Since ICQ is automatically launched right after booting Windows by default and it checks for updates on every start, it can be attacked very reliably.Proof of concept code included.
-
5:00
»
Hack a Day
[Matt Sarnoff] is designing his own 8-bit computer from scratch. This means not only designing the hardware but also writing his own kernel and custom libraries. Since we last saw this 8-bit machine hes added both video and sound output which has allowed him to start developing some software for his computer (see it play Conways game [...]
-
-
12:45
»
SecuriTeam
Potential vulnerabilities have been identified with the HPeDiag ActiveX control which is a component of HP Software Update running under windows.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
20:01
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2010-202 - The merge_authdata function in kdc_authdata.c in the Key Distribution Center 1.8.x before 1.8.4 does not properly manage an index into an authorization-data list, which allows remote attackers to cause a denial of service , or possibly obtain sensitive information, spoof authorization, or execute arbitrary code, via a TGS request, as demonstrated by a request from a Windows Active Directory client. The updated packages have been patched to correct this issue. Update packages for MES5 were missing with the MDVSA-2010:202 advisory. This advisory provides the update packages.
-
20:01
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2010-202 - The merge_authdata function in kdc_authdata.c in the Key Distribution Center 1.8.x before 1.8.4 does not properly manage an index into an authorization-data list, which allows remote attackers to cause a denial of service , or possibly obtain sensitive information, spoof authorization, or execute arbitrary code, via a TGS request, as demonstrated by a request from a Windows Active Directory client. The updated packages have been patched to correct this issue. Update packages for MES5 were missing with the MDVSA-2010:202 advisory. This advisory provides the update packages.
-
-
14:46
»
Packet Storm Security Tools
Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates. This framework comes into play when the attacker is able to make traffic redirection, and such thing can be done in several ways such as: DNS tampering, DNS Cache Poisoning, ARP spoofing Wi-Fi Access Point impersonation, DHCP hijacking with your favorite tools. This way you can easy take control of a fully patched machine during a penetration test in a clean and easy way. The main idea behind the is to show the amount of trivial errors in the update process of mainstream applications.
-
-
10:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1011-3 - USN-1011-1 fixed a vulnerability in Firefox. This update provides the corresponding update for Xulrunner. Morten Krakvik discovered a heap-based buffer overflow in Firefox. If a user were tricked into navigating to a malicious site, an attacker could cause a denial of service or possibly execute arbitrary code as the user invoking the program.
-
10:01
»
Packet Storm Security Advisories
Ubuntu Security Notice 1011-3 - USN-1011-1 fixed a vulnerability in Firefox. This update provides the corresponding update for Xulrunner. Morten Krakvik discovered a heap-based buffer overflow in Firefox. If a user were tricked into navigating to a malicious site, an attacker could cause a denial of service or possibly execute arbitrary code as the user invoking the program.
-
9:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1011-2 - USN-1011-1 fixed a vulnerability in Firefox. This update provides the corresponding update for Thunderbird. Morten Krakvik discovered a heap-based buffer overflow in Firefox. If a user were tricked into navigating to a malicious site, an attacker could cause a denial of service or possibly execute arbitrary code as the user invoking the program.
-
9:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 1011-2 - USN-1011-1 fixed a vulnerability in Firefox. This update provides the corresponding update for Thunderbird. Morten Krakvik discovered a heap-based buffer overflow in Firefox. If a user were tricked into navigating to a malicious site, an attacker could cause a denial of service or possibly execute arbitrary code as the user invoking the program.
-
-
18:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1002-2 - USN-1002-1 fixed vulnerabilities in PostgreSQL. This update provides the corresponding update for Ubuntu 10.10. It was discovered that PostgreSQL did not properly enforce permissions within sessions when PL/Perl and PL/Tcl functions or operators were redefined. A remote authenticated attacker could exploit this to execute arbitrary code with permissions of a different user, possibly leading to privilege escalation.
-
18:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 1002-2 - USN-1002-1 fixed vulnerabilities in PostgreSQL. This update provides the corresponding update for Ubuntu 10.10. It was discovered that PostgreSQL did not properly enforce permissions within sessions when PL/Perl and PL/Tcl functions or operators were redefined. A remote authenticated attacker could exploit this to execute arbitrary code with permissions of a different user, possibly leading to privilege escalation.
-
-
19:01
»
Packet Storm Security Recent Files
Ubuntu Security Notice 986-2 - USN-986-1 fixed a vulnerability in bzip2. This update provides the corresponding update for ClamAV. An integer overflow was discovered in bzip2. If a user or automated system were tricked into decompressing a crafted bz2 file, an attacker could cause bzip2 or any application linked against libbz2 to crash or possibly execute code as the user running the program.
-
19:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 986-2 - USN-986-1 fixed a vulnerability in bzip2. This update provides the corresponding update for ClamAV. An integer overflow was discovered in bzip2. If a user or automated system were tricked into decompressing a crafted bz2 file, an attacker could cause bzip2 or any application linked against libbz2 to crash or possibly execute code as the user running the program.
-
-
13:36
»
Packet Storm Security Recent Files
Ubuntu Security Notice 927-8 - USN-927-1 fixed vulnerabilities in NSS. This update provides the Thunderbird update to use the new NSS. Original advisory details: Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user's session. This update adds support for the new new renegotiation extension and will use it when the server supports it.
-
13:34
»
Packet Storm Security Advisories
Ubuntu Security Notice 927-8 - USN-927-1 fixed vulnerabilities in NSS. This update provides the Thunderbird update to use the new NSS. Original advisory details: Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user's session. This update adds support for the new new renegotiation extension and will use it when the server supports it.
-
12:03
»
Packet Storm Security Recent Files
Ubuntu Security Notice 927-6 - USN-927-1 fixed vulnerabilities in NSS on Ubuntu 9.10. This update provides the corresponding updates for Ubuntu 9.04. Original advisory details: Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user's session. This update adds support for the new new renegotiation extension and will use it when the server supports it.
-
12:03
»
Packet Storm Security Recent Files
Ubuntu Security Notice 927-7 - USN-927-4 fixed vulnerabilities in NSS. This update provides the NSPR needed to use the new NSS. Original advisory details: Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user's session. This update adds support for the new new renegotiation extension and will use it when the server supports it.
-
12:03
»
Packet Storm Security Advisories
Ubuntu Security Notice 927-6 - USN-927-1 fixed vulnerabilities in NSS on Ubuntu 9.10. This update provides the corresponding updates for Ubuntu 9.04. Original advisory details: Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user's session. This update adds support for the new new renegotiation extension and will use it when the server supports it.
-
12:03
»
Packet Storm Security Advisories
Ubuntu Security Notice 927-7 - USN-927-4 fixed vulnerabilities in NSS. This update provides the NSPR needed to use the new NSS. Original advisory details: Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user's session. This update adds support for the new new renegotiation extension and will use it when the server supports it.
-
-
19:02
»
Packet Storm Security Recent Files
VMware Security Advisory - The default version of the Jetty Web server in Update Manager is version 6.1.6 for which the following relevant vulnerabilities are reported. A directory traversal vulnerability in Jetty allows for obtaining files from the system where Update Manager is installed by a remote, unauthenticated attacker. The attacker would need to be on the same network as the system where Update Manager is installed. A cross-site scripting vulnerability in Jetty allows for running JavaScript in the browser of the user who clicks a URL containing a malicious request to Update Manager. For an attack to be successful the attacker would need to lure the user into clicking the malicious URL.
-
19:01
»
Packet Storm Security Advisories
VMware Security Advisory - The default version of the Jetty Web server in Update Manager is version 6.1.6 for which the following relevant vulnerabilities are reported. A directory traversal vulnerability in Jetty allows for obtaining files from the system where Update Manager is installed by a remote, unauthenticated attacker. The attacker would need to be on the same network as the system where Update Manager is installed. A cross-site scripting vulnerability in Jetty allows for running JavaScript in the browser of the user who clicks a URL containing a malicious request to Update Manager. For an attack to be successful the attacker would need to lure the user into clicking the malicious URL.
-
-
14:00
»
Hack a Day
We usually envision small wheeled robots when we thing about swarm robotics but these cooperative quadcopters make us think again. This is an extension of the same project that produced those impressive aerial acrobatics. It may not be as flashy, but watching groups of the four-rotored flyers grab onto and lift loads is quite impressive. [...]
-
14:00
»
Hack a Day
We usually envision small wheeled robots when we thing about swamp robotics but these cooperative quadcopters make us think again. This is an extension of the same project that produced those impressive aerial acrobatics. It may not be as flashy, but watching groups of the four-rotored flyers grab onto and lift loads is quite impressive. [...]
-
-
9:03
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2059-2 - It was discovered that PCSCD, a daemon to access smart cards, was vulnerable to a buffer overflow allowing a local attacker to elevate his privileges to root. The update for PCSCD caused a regression with some card readers. This update corrects that regression.
-
-
21:05
»
Packet Storm Security Recent Files
Ubuntu Security Notice 927-4 - USN-927-1 fixed vulnerabilities in nss in Ubuntu 9.10. This update provides the corresponding updates for Ubuntu 8.04 LTS. Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user's session. This update adds support for the new new renegotiation extension and will use it when the server supports it.
-
21:05
»
Packet Storm Security Recent Files
Ubuntu Security Notice 927-5 - USN-927-4 fixed vulnerabilities in NSS. This update provides the NSPR needed to use the new NSS. Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user's session. This update adds support for the new new renegotiation extension and will use it when the server supports it.
-
21:02
»
Packet Storm Security Advisories
Ubuntu Security Notice 927-4 - USN-927-1 fixed vulnerabilities in nss in Ubuntu 9.10. This update provides the corresponding updates for Ubuntu 8.04 LTS. Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user's session. This update adds support for the new new renegotiation extension and will use it when the server supports it.
-
21:02
»
Packet Storm Security Advisories
Ubuntu Security Notice 927-5 - USN-927-4 fixed vulnerabilities in NSS. This update provides the NSPR needed to use the new NSS. Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user's session. This update adds support for the new new renegotiation extension and will use it when the server supports it.
-
-
0:00
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2054-2 - This update restores the PID file location for bind to the location before the last security update. Several cache-poisoning vulnerabilities have been discovered in BIND. These vulnerabilities are apply only if DNSSEC validation is enabled and trust anchors have been installed, which is not the default.
-
-
13:58
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2009-332 - Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a crafted PSD file that triggers a heap-based buffer overflow. Additionally the patch for in MDVSA-2009:296 was incomplete, this update corrects this as well. This update provides a solution to this vulnerability. Packages for 2009.0 are provided due to the Extended Maintenance Program.
-
13:58
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2009-332 - Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a crafted PSD file that triggers a heap-based buffer overflow. Additionally the patch for in MDVSA-2009:296 was incomplete, this update corrects this as well. This update provides a solution to this vulnerability. Packages for 2009.0 are provided due to the Extended Maintenance Program.
-
-
12:06
»
Hack a Day
Apod walks! If you recall, last year we discovered Apod, the creepy lifelike hexapod creation made by [Zenta]. At that point in time, it basically just shifted around nicely but didn’t do much walking. Well, [Zenta] has been hard at work since then and now Apod is fully active, walking, running, and serving drinks with [...]
-
0:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 931-2 - USN-931-1 fixed vulnerabilities in FFmpeg. The update introduced a regression when trying to play certain multimedia files. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that FFmpeg contained multiple security issues when handling certain multimedia files. If a user were tricked into opening a crafted multimedia file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program.
-
-
17:00
»
Packet Storm Security Recent Files
Ubuntu Security Notice 929-2 - USN-929-1 fixed vulnerabilities in irssi. The upstream changes introduced a regression when using irssi with SSL and an IRC proxy. This update fixes the problem. It was discovered that irssi did not perform certificate host validation when using SSL connections. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. Aurelien Delaitre discovered that irssi could be made to dereference a NULL pointer when a user left the channel. A remote attacker could cause a denial of service via application crash. This update also adds SSLv3 and TLSv1 support, while disabling the old, insecure SSLv2 protocol.
-
17:00
»
Packet Storm Security Advisories
Ubuntu Security Notice 929-2 - USN-929-1 fixed vulnerabilities in irssi. The upstream changes introduced a regression when using irssi with SSL and an IRC proxy. This update fixes the problem. It was discovered that irssi did not perform certificate host validation when using SSL connections. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. Aurelien Delaitre discovered that irssi could be made to dereference a NULL pointer when a user left the channel. A remote attacker could cause a denial of service via application crash. This update also adds SSLv3 and TLSv1 support, while disabling the old, insecure SSLv2 protocol.
-
-
15:06
»
Packet Storm Security Recent Files
Ubuntu Security Notice 624-2 - USN-624-1 fixed a vulnerability in PCRE. This update provides the corresponding update for Erlang. Original advisory details: Tavis Ormandy discovered that the PCRE library did not correctly handle certain in-pattern options. An attacker could cause applications linked against pcre3 to crash, leading to a denial of service.
-
15:06
»
Packet Storm Security Advisories
Ubuntu Security Notice 624-2 - USN-624-1 fixed a vulnerability in PCRE. This update provides the corresponding update for Erlang. Original advisory details: Tavis Ormandy discovered that the PCRE library did not correctly handle certain in-pattern options. An attacker could cause applications linked against pcre3 to crash, leading to a denial of service.
-
-
15:00
»
Hack a Day
Sony is rolling out a firmware update for the PS3 on April 1 but we’re pretty sure it’s not a joke. What we’re not sure about is that you can call it an update. It removes features rather than fixing or adding them. In this case, it is removing the “Install Other OS” option that [...]
-
12:12
»
Hack a Day
Changing this 50MHz Rigol oscilloscope into its larger, more expensive brother just became quite a bit easier. When we originally looked at this hack it required pulling some capacitors off of the board. Now all it takes is three commands over a serial terminal connection.
Take a look at the walk through video after the break. [...]
-
-
7:30
»
Hack a Day
Driven by the relentless nagging encouragement of the Hackaday commenters, [Johndavid400] has improved the Lawnbot 400. No longer does it just sport a makeshift wooden shelf. he now has a wheel barrow attachment. It looks quite sturdy as long as that front hinge holds out. There is an actuator coming in the near future for [...]
-
-
11:09
»
Hack a Day
[Erdem] sent us an update on his work with the SamyGO project. You may remember this Samsung TV firmware hacking initiative from our post back in October. Since then many more TV models have been added to the compatible list. They have also worked out a way to defeat the AES encryption and RSA signature [...]
-
-
14:30
»
remote-exploit & backtrack
naja wollte huet mal ein apt-get update machen und bekam folgende meldung
Quote:
root@bt:~# apt-get update
Err SUN Backtrack Linux Repository pwnsauce Release.gpg
Could not resolve 'archive.offensive-security.com'
Reading package lists... Done
W: Failed to fetch http://archive.offensive-security.co...ce/Release.gpg Could not resolve 'archive.offensive-security.com'
W: Some index files failed to download, they have been ignored, or old ones used instead.
W: You may want to run apt-get update to correct these problems
|
sry für die frühe veröffentlichung
ich nehme mal an das die server down sind zu wartungszwecken
ok war noch nicht mim inet verbunden
aber trotzdem harte lösung um das problem zu beheben
-
-
10:35
»
Hack a Day
[Brad] has continued working on the Super Pixel Bros game. We saw a glimpse of this a few months ago but he’s added a lot since then. The game now has enemies; one type is similar to Bullet Bill, another type drops from the sky and walks toward you, kind of like a Goomba. Game [...]