y Red Hat Security Advisory 2020-1963-01 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 16:04:53 GMT Red Hat Security Advisory 2020-1963-01 - Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Issues addressed include HTTP response splitting and buffer under-read vulnerabilities. Full Article
y Red Hat Security Advisory 2020-1970-01 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 17:22:44 GMT Red Hat Security Advisory 2020-1970-01 - Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 81.0.4044.122. Issues addressed include out of bounds read and use-after-free vulnerabilities. Full Article
y Red Hat Security Advisory 2020-1981-01 By packetstormsecurity.com Published On :: Thu, 30 Apr 2020 14:47:45 GMT Red Hat Security Advisory 2020-1981-01 - Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 81.0.4044.129. Issues addressed include a use-after-free vulnerability. Full Article
y Red Hat Security Advisory 2020-1936-01 By packetstormsecurity.com Published On :: Mon, 04 May 2020 17:06:58 GMT Red Hat Security Advisory 2020-1936-01 - Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Issues addressed include HTTP request smuggling and out of bounds write vulnerabilities. Full Article
y Red Hat Security Advisory 2020-2033-01 By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:38:29 GMT Red Hat Security Advisory 2020-2033-01 - Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 68.8.0 ESR. Issues addressed include buffer overflow and use-after-free vulnerabilities. Full Article
y Red Hat Security Advisory 2020-2032-01 By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:38:46 GMT Red Hat Security Advisory 2020-2032-01 - Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 68.8.0 ESR. Issues addressed include buffer overflow and use-after-free vulnerabilities. Full Article
y Red Hat Security Advisory 2020-2031-01 By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:40:14 GMT Red Hat Security Advisory 2020-2031-01 - Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 68.8.0 ESR. Issues addressed include buffer overflow and use-after-free vulnerabilities. Full Article
y Red Hat Security Advisory 2020-2037-01 By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:42:31 GMT Red Hat Security Advisory 2020-2037-01 - Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 68.8.0 ESR. Issues addressed include buffer overflow and use-after-free vulnerabilities. Full Article
y Red Hat Security Advisory 2020-2036-01 By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:45:03 GMT Red Hat Security Advisory 2020-2036-01 - Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 68.8.0 ESR. Issues addressed include buffer overflow and use-after-free vulnerabilities. Full Article
y Red Hat Security Advisory 2020-2039-01 By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:48:42 GMT Red Hat Security Advisory 2020-2039-01 - Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects. Issues addressed include buffer overflow and code execution vulnerabilities. Full Article
y Red Hat Security Advisory 2020-2038-01 By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:51:01 GMT Red Hat Security Advisory 2020-2038-01 - Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects. Issues addressed include buffer overflow and code execution vulnerabilities. Full Article
y Red Hat Security Advisory 2020-2041-01 By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:51:23 GMT Red Hat Security Advisory 2020-2041-01 - Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects. Issues addressed include buffer overflow and code execution vulnerabilities. Full Article
y Red Hat Security Advisory 2020-2040-01 By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:54:10 GMT Red Hat Security Advisory 2020-2040-01 - Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects. Issues addressed include buffer overflow and code execution vulnerabilities. Full Article
y Red Hat Security Advisory 2020-0431-01 By packetstormsecurity.com Published On :: Wed, 05 Feb 2020 18:50:02 GMT Red Hat Security Advisory 2020-0431-01 - KornShell is a Unix shell developed by AT&T Bell Laboratories, which is backward-compatible with the Bourne shell and includes many features of the C shell. The most recent version is KSH-93. KornShell complies with the POSIX.2 standard. A code injection vulnerability has been addressed. Full Article
y Red Hat Security Advisory 2020-0515-01 By packetstormsecurity.com Published On :: Mon, 17 Feb 2020 17:26:14 GMT Red Hat Security Advisory 2020-0515-01 - KornShell is a Unix shell developed by AT&T Bell Laboratories, which is backward-compatible with the Bourne shell and includes many features of the C shell. The most recent version is KSH-93. KornShell complies with the POSIX.2 standard. A code injection vulnerability has been addressed. Full Article
y Red Hat Security Advisory 2020-0559-01 By packetstormsecurity.com Published On :: Thu, 20 Feb 2020 21:13:20 GMT Red Hat Security Advisory 2020-0559-01 - KornShell is a Unix shell developed by AT&T Bell Laboratories, which is backward-compatible with the Bourne shell and includes many features of the C shell. The most recent version is KSH-93. KornShell complies with the POSIX.2 standard. A code injection vulnerability was addressed. Full Article
y Red Hat Security Advisory 2020-0568-01 By packetstormsecurity.com Published On :: Tue, 25 Feb 2020 15:06:40 GMT Red Hat Security Advisory 2020-0568-01 - KornShell is a Unix shell developed by AT&T Bell Laboratories, which is backward-compatible with the Bourne shell and includes many features of the C shell. The most recent version is KSH-93. KornShell complies with the POSIX.2 standard. A code injection vulnerability was addressed. Full Article
y Ubuntu Security Notice USN-4294-1 By packetstormsecurity.com Published On :: Mon, 02 Mar 2020 19:16:40 GMT Ubuntu Security Notice 4294-1 - It was discovered that OpenSMTPD mishandled certain input. A remote, unauthenticated attacker could use this vulnerability to execute arbitrary shell commands as any non-root user. It was discovered that OpenSMTPD did not properly handle hardlinks under certain conditions. An unprivileged local attacker could read the first line of any file on the filesystem. Full Article
y Apache ActiveMQ 5.11.1 Directory Traversal / Shell Upload By packetstormsecurity.com Published On :: Thu, 05 Mar 2020 21:05:37 GMT This Metasploit module exploits a directory traversal vulnerability (CVE-2015-1830) in Apache ActiveMQ versions 5.x before 5.11.2 for Windows. The module tries to upload a JSP payload to the /admin directory via the traversal path /fileserver/..\admin\ using an HTTP PUT request with the default ActiveMQ credentials admin:admin (or other credentials provided by the user). It then issues an HTTP GET request to /admin/.jsp on the target in order to trigger the payload and obtain a shell. Full Article
y Red Hat Security Advisory 2020-0853-01 By packetstormsecurity.com Published On :: Wed, 18 Mar 2020 15:00:12 GMT Red Hat Security Advisory 2020-0853-01 - The zsh shell is a command interpreter usable as an interactive login shell and as a shell script command processor. Zsh resembles the ksh shell, but includes many enhancements. Zsh supports command-line editing, built-in spelling correction, programmable command completion, shell functions, a history mechanism, and more. An issue with insecure dropping of privileges when unsetting PRIVILEGED option was addressed. Full Article
y Red Hat Security Advisory 2020-0892-01 By packetstormsecurity.com Published On :: Wed, 18 Mar 2020 15:21:53 GMT Red Hat Security Advisory 2020-0892-01 - The zsh shell is a command interpreter usable as an interactive login shell and as a shell script command processor. Zsh resembles the ksh shell, but includes many enhancements. Zsh supports command-line editing, built-in spelling correction, programmable command completion, shell functions, a history mechanism, and more. An issue with insecure dropping of privileges when unsetting PRIVILEGED option was addressed. Full Article
y Red Hat Security Advisory 2020-0903-01 By packetstormsecurity.com Published On :: Thu, 19 Mar 2020 15:22:41 GMT Red Hat Security Advisory 2020-0903-01 - The zsh shell is a command interpreter usable as an interactive login shell and as a shell script command processor. Zsh resembles the ksh shell, but includes many enhancements. Zsh supports command-line editing, built-in spelling correction, programmable command completion, shell functions, a history mechanism, and more. An issue with insecure dropping of privileges when unsetting PRIVILEGED option was addressed. Full Article
y Red Hat Security Advisory 2020-0978-01 By packetstormsecurity.com Published On :: Thu, 26 Mar 2020 14:48:50 GMT Red Hat Security Advisory 2020-0978-01 - The zsh shell is a command interpreter usable as an interactive login shell and as a shell script command processor. Zsh resembles the ksh shell, but includes many enhancements. Zsh supports command-line editing, built-in spelling correction, programmable command completion, shell functions, a history mechanism, and more. An issue with insecure dropping of privileges when unsetting PRIVILEGED option was addressed. Full Article
y Gentoo Linux Security Advisory 202003-57 By packetstormsecurity.com Published On :: Fri, 27 Mar 2020 13:06:15 GMT Gentoo Linux Security Advisory 202003-57 - Multiple vulnerabilities have been found in PHP, the worst of which could result in the execution of arbitrary shell commands. Versions less than 7.4.4 are affected. Full Article
y Red Hat Security Advisory 2020-1113-01 By packetstormsecurity.com Published On :: Wed, 01 Apr 2020 15:16:42 GMT Red Hat Security Advisory 2020-1113-01 - The bash packages provide Bash, which is the default shell for Red Hat Enterprise Linux. Full Article
y Red Hat Security Advisory 2020-1332-01 By packetstormsecurity.com Published On :: Mon, 06 Apr 2020 19:18:02 GMT Red Hat Security Advisory 2020-1332-01 - KornShell is a Unix shell developed by AT+T Bell Laboratories, which is backward-compatible with the Bourne shell and includes many features of the C shell. The most recent version is KSH-93. KornShell complies with the POSIX.2 standard. A code injection vulnerability has been addressed. Full Article
y Red Hat Security Advisory 2020-1333-01 By packetstormsecurity.com Published On :: Mon, 06 Apr 2020 19:18:52 GMT Red Hat Security Advisory 2020-1333-01 - KornShell is a Unix shell developed by AT+T Bell Laboratories, which is backward-compatible with the Bourne shell and includes many features of the C shell. The most recent version is KSH-93. KornShell complies with the POSIX.2 standard. A code injection vulnerability has been addressed. Full Article
y Metasploit Libnotify Arbitrary Command Execution By packetstormsecurity.com Published On :: Fri, 17 Apr 2020 15:36:46 GMT This Metasploit module exploits a shell command injection vulnerability in the libnotify plugin. This vulnerability affects Metasploit versions 5.0.79 and earlier. Full Article
y Red Hat Security Advisory 2020-1933-01 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:44:21 GMT Red Hat Security Advisory 2020-1933-01 - The targetcli package contains an administration shell for configuring Internet Small Computer System Interface, Fibre Channel over Ethernet, and other SCSI targets, using the Target Core Mod/Linux-IO kernel target subsystem. FCoE users also need to install and use the fcoe-utils package. A command execution vulnerability was addressed. Full Article
y American Cities of the Future 2019/20 – FDI strategy By www.fdiintelligence.com Published On :: Mon, 10 Jun 2019 07:25:52 +0000 A more detailed look at fDi's judges’ top five American Cities of the Future 2019/20 for FDI strategy. Naomi Davies reports. Full Article
y Russia most diversified commodity economy for the fourth year By www.fdiintelligence.com Published On :: Thu, 15 Aug 2019 11:00:45 +0000 Russia remains fDi’s most diversified commodity economy, while second ranked Brazil has displaced Ukraine into third place. Cathy Mullan reports. Full Article
y fDi’s Global Free Zones of the Year 2019 – the winners By www.fdiintelligence.com Published On :: Mon, 14 Oct 2019 08:40:15 +0000 The UAE's DMCC takes home the top prize in fDi’s Global Free Zones of the Year for a fifth consecutive year. Full Article
y Tourism Locations of the Future 2019/20 – FDI Strategy By www.fdiintelligence.com Published On :: Mon, 09 Dec 2019 08:33:03 +0000 Australia tops the FDI Strategy category of fDi's Tourism Locations of the Future 2019/20 rankings, followed by Costa Rica and Azerbaijan. Full Article
y fDi Strategy Awards 2019 – the winners By www.fdiintelligence.com Published On :: Mon, 09 Dec 2019 08:32:42 +0000 Lithuania's Go Vilnius has been named fDi’s IPA of the Year for 2019, and organisations from across the globe are commended for their investment promotion and economic development activities. Full Article
y Linux Kernel Quickly Patched To Mitigate New Vuln By packetstormsecurity.com Published On :: Tue, 08 Jan 2019 15:08:31 GMT Full Article headline linux data loss flaw patch
y Nasty Security Bug Found And Fixed In Linux apt By packetstormsecurity.com Published On :: Wed, 23 Jan 2019 15:12:03 GMT Full Article headline linux flaw patch
y Linux Command-Line Editors Vulnerable To High Severity Bug By packetstormsecurity.com Published On :: Wed, 12 Jun 2019 15:27:56 GMT Full Article headline linux flaw
y Researchers Find Security Flaws In 40 Kernel Drivers From 20 Vendors By packetstormsecurity.com Published On :: Sun, 11 Aug 2019 18:14:44 GMT Full Article headline linux flaw conference
y Critical Linux Wi-Fi Bug Allows System Compromise By packetstormsecurity.com Published On :: Sat, 19 Oct 2019 15:36:59 GMT Full Article headline linux wireless flaw
y OpenSMTPD Library RCE Impacts BSD And Linux By packetstormsecurity.com Published On :: Wed, 29 Jan 2020 15:36:06 GMT Full Article headline linux flaw bsd
y Hackers Have Been Quietly Targeting Linux Servers By packetstormsecurity.com Published On :: Tue, 07 Apr 2020 16:36:08 GMT Full Article headline hacker linux
y Wi-fEye Wireless Pentesting Tool 1.0 Beta By packetstormsecurity.com Published On :: Mon, 26 Aug 2013 14:43:33 GMT Wi-fEye is designed to help with network penetration testing. It allows the user to perform a number of powerful attack automatically including WEP/WPA cracking, session hijacking and more. Full Article
y SkyJack Drone Hijacker By packetstormsecurity.com Published On :: Wed, 04 Dec 2013 03:19:46 GMT Skyjack takes over Parrot drones, deauthenticating their true owner and taking over control, turning them into zombie drones under your own control. Full Article
y Pytacle Alpha2 By packetstormsecurity.com Published On :: Thu, 05 Dec 2013 01:11:11 GMT pytacle is a tool inspired by tentacle. It automates the task of sniffing GSM frames of the air, extracting the key exchange, feeding kraken with the key material and finally decode/decrypt the voice data. All You need is a USRP (or similar) to capture the GSM band and a kraken instance with the berlin tables (only about 2TB). Full Article
y FLIR Systems FLIR Brickstream 3D+ Unauthenticated Config Download File Disclosure By packetstormsecurity.com Published On :: Mon, 15 Oct 2018 16:58:29 GMT The FLIR Brickstream 3D+ sensor is vulnerable to unauthenticated config download and file disclosure vulnerability when calling the ExportConfig REST API (getConfigExportFile.cgi). This will enable the attacker to disclose sensitive information and help her in authentication bypass, privilege escalation and/or full system access. Full Article
y Synaccess netBooter NP-02x / NP-08x 6.8 Authentication Bypass By packetstormsecurity.com Published On :: Mon, 19 Nov 2018 19:09:21 GMT Synaccess netBooter NP-02x and NP-08x version 6.8 suffer from an authentication bypass vulnerability due to a missing control check when calling the webNewAcct.cgi script while creating users. This allows an unauthenticated attacker to create an admin user account and bypass authentication giving her the power to turn off a power supply to a resource. Full Article
y ABB IDAL HTTP Server Authentication Bypass By packetstormsecurity.com Published On :: Fri, 21 Jun 2019 20:32:22 GMT The IDAL HTTP server CGI interface contains a URL, which allows an unauthenticated attacker to bypass authentication and gain access to privileged functions. In the IDAL CGI interface, there is a URL (/cgi/loginDefaultUser), which will create a session in an authenticated state and return the session ID along with the username and plaintext password of the user. An attacker can then login with the provided credentials or supply the string 'IDALToken=......' in a cookie which will allow them to perform privileged operations such as restarting the service with /cgi/restart. Full Article
y Ubuntu Security Notice USN-4059-1 By packetstormsecurity.com Published On :: Tue, 16 Jul 2019 20:09:51 GMT Ubuntu Security Notice 4059-1 - It was discovered that Squid incorrectly handled certain SNMP packets. A remote attacker could possibly use this issue to cause memory consumption, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. It was discovered that Squid incorrectly handled the cachemgr.cgi web module. A remote attacker could possibly use this issue to conduct cross-site scripting attacks. Various other issues were also addressed. Full Article
y Debian Security Advisory 4507-1 By packetstormsecurity.com Published On :: Mon, 26 Aug 2019 15:54:12 GMT Debian Linux Security Advisory 4507-1 - Several vulnerabilities were discovered in Squid, a fully featured web proxy cache. The flaws in the HTTP Digest Authentication processing, the HTTP Basic Authentication processing and in the cachemgr.cgi allowed remote attackers to perform denial of service and cross-site scripting attacks, and potentially the execution of arbitrary code. Full Article
y Rifatron Intelligent Digital Security System (animate.cgi) Stream Disclosure By packetstormsecurity.com Published On :: Mon, 09 Sep 2019 23:46:02 GMT The Rifatron Intelligent Digital Security System DVR suffers from an unauthenticated and unauthorized live stream disclosure when animate.cgi script is called through Mobile Web Viewer module. Full Article