la

Linux Kernel Sendpage Local Privilege Escalation

The Linux kernel failed to properly initialize some entries the proto_ops struct for several protocols, leading to NULL being derefenced and used as a function pointer. By using mmap(2) to map page 0, an attacker can execute arbitrary code in the context of the kernel. Several public exploits exist for this vulnerability, including spender's wunderbar_emporium and rcvalle's ppc port, sock_sendpage.c. All Linux 2.4/2.6 versions since May 2001 are believed to be affected: 2.4.4 up to and including 2.4.37.4; 2.6.0 up to and including 2.6.30.4




la

Were Oslo's Terror Blasts Caused By Car Bombs?





la

Chkrootkit Local Privilege Escalation

Chkrootkit before 0.50 will run any executable file named /tmp/update as root, allowing a trivial privsec. WfsDelay is set to 24h, since this is how often a chkrootkit scan is scheduled by default.





la

Apache ActiveMQ Flaws Leave Servers Open To DoS Attacks





la

Apache Struts 2 Needs Patching, Without Delay. It's Under Attack Now.




la

Yahoo Fixes Email Cross-Site Scripting Flaw




la

XSS Flaws Poke Ridicule At Entertainment Industry




la

Adobe Plagued By 16-Month-Old XSS Bug




la

Mozilla Tackles XSS Vulnerabilities With New Technology




la

MoD Website Outflanked By XSS Flaws




la

RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence





la

XSS Vulnerabilities In 8 Million Flash Files




la

Serious XSS Flaw Haunts Microsoft SharePoint




la

Anti-Virus Vendor Trio Plug Website Flaws




la

Adobe Updates Flash Player To Fix XSS Flaw






la

FreeBSD Intel SYSRET Privilege Escalation

This Metasploit module exploits a vulnerability in the FreeBSD kernel, when running on 64-bit Intel processors. By design, 64-bit processors following the X86-64 specification will trigger a general protection fault (GPF) when executing a SYSRET instruction with a non-canonical address in the RCX register. However, Intel processors check for a non-canonical address prior to dropping privileges, causing a GPF in privileged mode. As a result, the current userland RSP stack pointer is restored and executed, resulting in privileged code execution.




la

FreeBSD rtld execl() Privilege Escalation

This Metasploit module exploits a vulnerability in the FreeBSD run-time link-editor (rtld). The rtld unsetenv() function fails to remove LD_* environment variables if __findenv() fails. This can be abused to load arbitrary shared objects using LD_PRELOAD, resulting in privileged code execution.




la

Hacker Almost Derailed Mandela Election In South Africa





la

Ebola Outbreak Reaches City Of 1 Million Residents





la

JUNOS (Juniper) Flaw Exposes Core Routers To Kernel Crash





la

Juniper Bleeding Data And Money: Slaps Band-Aids All Over JunOS





la

Slackware Security Advisory - mozilla-thunderbird Updates

Slackware Security Advisory - New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.




la

Slackware Security Advisory - expat Updates

Slackware Security Advisory - New expat packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.




la

Slackware Security Advisory - mozilla-thunderbird Updates

Slackware Security Advisory - New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.




la

Slackware Security Advisory - tcpdump Updates

Slackware Security Advisory - New libpcap and tcpdump packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.




la

Slackware Security Advisory - sudo Updates

Slackware Security Advisory - New sudo packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.




la

Slackware Security Advisory - python Updates

Slackware Security Advisory - New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.




la

Slackware Security Advisory - mozilla-firefox Updates

Slackware Security Advisory - New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.




la

Slackware Security Advisory - libtiff Updates

Slackware Security Advisory - New libtiff packages are available for Slackware 14.2 and -current to fix security issues.




la

Slackware Security Advisory - Slackware 14.2 kernel Updates

Slackware Security Advisory - New kernel packages are available for Slackware 14.2 to fix security issues.




la

Slackware Security Advisory - Slackware 14.2 kernel Updates

Slackware Security Advisory - New kernel packages are available for Slackware 14.2 to fix security issues.




la

Slackware Security Advisory - bind Updates

Slackware Security Advisory - New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.




la

Slackware Security Advisory - mozilla-firefox Updates

Slackware Security Advisory - New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.




la

Slackware Security Advisory - wavpack Updates

Slackware Security Advisory - New wavpack packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.




la

Slackware Security Advisory - openssl Updates

Slackware Security Advisory - New openssl packages are available for Slackware 14.2 and -current to fix a security issue.




la

Slackware Security Advisory - tigervnc Updates

Slackware Security Advisory - New tigervnc packages are available for Slackware 14.2 and -current to fix security issues.




la

Slackware Security Advisory - mozilla-firefox Updates

Slackware Security Advisory - New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.




la

Slackware Security Advisory - Slackware 14.2 kernel Updates

Slackware Security Advisory - New kernel packages are available for Slackware 14.2 to fix security issues.




la

Slackware Security Advisory - mozilla-firefox Updates

Slackware Security Advisory - New mozilla-firefox packages are available for Slackware 14.2 and -current to fix a security issue.




la

Slackware Security Advisory - mozilla-thunderbird Updates

Slackware Security Advisory - New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.