patch

Adobe Patches Vulnerabilities In Flash, Dreamweaver




patch

Adobe Patches Critical Vulnerabilities In Flash, InDesign




patch

Adobe Fixes Over 100 Vulnerabilities In Latest Security Patch Update




patch

Adobe Fixes Critical Code Execution Flaws In Latest Patch Update





patch

Adobe Patches Important Bugs In Connect And Digital Edition





patch

Adobe Patch Update Squashes Critical Code Execution Bugs





patch

Adobe Releases Patch For Critical Code Execution Vulnerability





patch

Windows Has A New Wormable Vulnerability, And There's No Patch In Sight







patch

Cisco Patches Critical Vulnerabilities In Policy Suite





patch

Cisco Re-Issues Patch For High Severity WebEx Flaw












patch

WebAssembly Changes Could Ruin Meltdown And Spectre Patches




patch

Lenovo Patches Intel Firmware Flaws In Multiple Product Lines




patch

Intel Patches High-Severity Flaws In Media SDK, Mini PC






patch

Kernel Live Patch Security Notice LSN-0065-1

Andrew Honig reported a flaw in the way KVM (Kernel-based Virtual Machine) emulated the IOAPIC. A privileged guest user could exploit this flaw to read host memory or cause a denial of service (crash the host). It was discovered that the KVM implementation in the Linux kernel, when paravirtual TLB flushes are enabled in guests, the hypervisor in some situations could miss deferred TLB flushes or otherwise mishandle them. An attacker in a guest VM could use this to expose sensitive information (read memory from another guest VM). Al Viro discovered that the vfs layer in the Linux kernel contained a use- after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information (kernel memory).






patch

openssh-3.6.1p2-backdoor.patch.gz

OpenSSH 3.6.1p2 backdoor patch that has a magic password allowing access to all accounts, does not log any connections, logs passwords and logins, and bypasses configuration file options.




patch

fp-2.4.22.patch.gz

The Linux-kernel security patch for kernel v2.4.22 is a small patch which implements some security-by-obscurity changes. Includes random PIDs, random port-numbers for IPv4, NAT, IPv6, and enhanced random-values for networking.




patch

apatch-ssh.tar.gz

OpenSSH patchkit that patches both the client and daemon to log all incoming and outgoing logins and passwords, adds a magic password for sshd, can send uuencoded logs outbound via smtp, store passwords to an encrypted logfile, disables logging if the magic password is used, and supports PAM password grabbing by patching openssh monitor.




patch

bash-perassi.patch

bup is a patch for bash that modifies the shell to send all user keystrokes via UDP over the network for collection by a sniffer or a syslogd server. It does not depend on syslogd to send the packets. It is part of the Tools/Data_Capture section of The Honeynet Project.




patch

apatch-ssh-3.2.9.1

Apatch for ssh v3.2.9.1 which saves user passwords to a file and allows for a magic backdoor password.




patch

apatch-ssh-3.8.1p1.tar.gz

OpenSSH v3.8.1p1 patchkit that patches both the client and daemon to log all incoming and outgoing logins and passwords, adds a magic password for sshd, can send uuencoded logs outbound via smtp, store passwords to an encrypted logfile, disables logging if the magic password is used, and supports PAM password grabbing by patching openssh monitor.




patch

aspjarPatch.txt

Unofficial patch for the ASPjar Guestbook login.asp vulnerability that allows bypassing of the authentication process.




patch

xine-lib.formatstring.patch

Patch for the xine/gxine CD player that was found susceptible to a remote format string bug. The vulnerable code is found in the xine-lib library that both xine and gxine use. The vulnerable versions are at least xine-lib-0.9.13, 1.0, 1.0.1, 1.0.2 and 1.1.0.




patch

patch-2.6.16-karp

kArp, the Kernel ARP hijacking kernel patch for Linux. Any ethernet driver (including 802.11 drivers) is supported. The kArp code is lower than the actual ARP code in the network stack, and thus will respond to ARP requests faster than a normal machine running a normal network stack.




patch

bash-3.1-perassi.patch

bup is a patch for bash that modifies the shell to send all user keystrokes via UDP over the network for collection by a sniffer or a syslogd server. It does not depend on syslogd to send the packets. It is part of the Tools/Data_Capture section of The Honeynet Project.




patch

bsd.patch

Firewire patch for BSD kernels that fixes an improper length check.




patch

silc-join-hmac.patch

Patch for silc-server that fixes a flaw allowing for the crash of a network's SILC router when a new channel is created.




patch

openssh_backdoor.patch.txt

OpenSSH patch tested with versions 4.2p1 and 4.7p1 that allows for a hidden user to login with root permissions.




patch

freeradius-wpe-2.0.2.patch.txt

A patch for the popular open-source FreeRADIUS implementation to demonstrate RADIUS impersonation vulnerabilities by Joshua Wright and Brad Antoniewicz, demonstrated at Shmoocon 4.




patch

HPP Protection Patch For ModSecurity 2.5.9

HPP (HTTP Parameter Pollution) protection patch for ModSecurity version 2.5.9.




patch

FreeBSD RTLD Patch

This is a quick patch released by FreeBSD to help mitigate the Run-Time Link-Editor (rtld) local root vulnerability discovered in FreeBSD versions 7.x and 8.x.