Posted by Stefan Kanthak on Feb 25Hi @ll,

since Microsoft Server 2003 R2, Microsoft dares to ship and install the
abomination known as .NET Framework with every new version of Windows.

Among other components current versions of Windows and .NET Framework
include

C# compiler (C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe, C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe)
J# compiler (C:\Windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe,… …

Posted by Qualys Security Advisory on Feb 25Qualys Security Advisory

Local information disclosure in OpenSMTPD (CVE-2020-8793)

==============================================================================
Contents
==============================================================================

Summary
Analysis
Exploitation
POKE 47196, 201
Acknowledgments

==============================================================================
Summary… …

Posted by Qualys Security Advisory on Feb 25Qualys Security Advisory

LPE and RCE in OpenSMTPD's default install (CVE-2020-8794)

==============================================================================
Contents
==============================================================================

Summary
Analysis

Acknowledgments

==============================================================================
Summary… …

Posted by Alessandro Ghedini on Feb 25————————————————————————-
Debian Security Advisory DSA-4633-1 security () debian org
https://www.debian.org/security/ Alessandro Ghedini
February 22, 2020 https://www.debian.org/security/faq
————————————————————————-

Package : curl
CVE ID : CVE-2019-5436 CVE-2019-5481… …

Posted by Jamie R on Feb 25I've quoted the Cisco summary below as it's pretty accurate.

tl;dr is an admin user on the web console can gain command execution
and then escalate to root. If this is an issue in your environment,
then please patch.

Thanks to Cisco PSIRT who were responsive and professional.

Shouts to Andrew, Dave and Senad, Pedro R – if that's still even a
thing on advisories.

Ref:… …

Posted by Slackware Security Team on Feb 20[slackware-security] proftpd (SSA:2020-051-01)

New proftpd packages are available for Slackware 14.0, 14.1, 14.2, and -current
to fix a security issue.

Here are the details from the Slackware 14.2 ChangeLog:
+————————–+
patches/packages/proftpd-1.3.6c-i586-1_slack14.2.txz: Upgraded. No CVEs assigned, but this sure looks like a security issue: Use-after-free vulnerability in memory pools during data transfer. (* Security… …

Posted by Moritz Muehlenhoff on Feb 19————————————————————————-
Debian Security Advisory DSA-4628-1 security () debian org
https://www.debian.org/security/ Moritz Muehlenhoff
February 18, 2020 https://www.debian.org/security/faq
————————————————————————-

Package : php7.0
CVE ID : CVE-2019-11045 CVE-2019-11046… …

Posted by Sebastien Delafond on Feb 19————————————————————————-
Debian Security Advisory DSA-4629-1 security () debian org
https://www.debian.org/security/ Sebastien Delafond
February 19, 2020 https://www.debian.org/security/faq
————————————————————————-

Package : python-django
CVE ID : CVE-2020-7471
Debian Bug… …

Posted by Moritz Muehlenhoff on Feb 18————————————————————————-
Debian Security Advisory DSA-4626-1 security () debian org
https://www.debian.org/security/ Moritz Muehlenhoff
February 17, 2020 https://www.debian.org/security/faq
————————————————————————-

Package : php7.3
CVE ID : CVE-2019-11045 CVE-2019-11046… …

Posted by Moritz Muehlenhoff on Feb 18————————————————————————-
Debian Security Advisory DSA-4627-1 security () debian org
https://www.debian.org/security/ Alberto Garcia
February 17, 2020 https://www.debian.org/security/faq
————————————————————————-

Package : webkit2gtk
CVE ID : CVE-2020-3862 CVE-2020-3864… …

Posted by RedTimmy Security on Feb 16Hi,
we have published a new post in our blog titled "How to hack a company by circumventing its WAF through the abuse of a
different security appliance and win bug bounties".

We basically have [ab]used a Bluecoat device behaving as a request forwarder to mask our malicious payload, avoid WAF
detection, hit an HTTP endpoint vulnerable to RCE and pop out a shell.

Full story is here:… …

X