Debian Security Advisory DSA-3149-1 security@debian.orghttp://www.debian.org/security/ Sebastien DelafondFebruary 02, 2015 http://www.debian.org/security/faq- ------------------------------------------------------------
-------------Package : condorCVE ID : CVE-2014-8126Debian Bug : 775276Florian Weimer, of Red Hat Product Security, discovered an issue incondor, a distributed workload management system. Upon job completion,it can optionally notify a user by sending an email; the mailxinvocation used in that process allowed for any authenticated userable to submit jobs, to execute arbitrary code with the privileges ofthe condor user.For the stable distribution (wheezy), this problem has been fixed inversion 7.8.2~dfsg.1-1+deb7u3.For the upcoming stable distribution (jessie) and unstabledistribution (sid), this problem has been fixed in version8.2.3~dfsg.1-6.We recommend that you upgrade your condor packages.Further information about Debian Security Advisories, how to applythese updates to your system and frequently asked questions can befound at: https://www.debian.org/security/Mailing list: debian-security-announce@lists.debian.org
Summary=======The operating system used by Pexip Infinity does not create unique SSHhost keys on deployment of new Management and Conferencing Nodes, usingfixed host keys instead. Host keys are used to verify the identity ofthe remote host when connecting to it over SSH. These keys are containedin the publicly available software image.An attacker with privileged network access may make use of these keys tospoof the identity of a Pexip Infinity installation or conductman-in-the-middle attacks on administrative SSH sessions. This maypermit the attacker access to credentials used to authenticate sessionsover SSH and provide shell access to the affected systems.This issue is resolved in Pexip Infinity version 8.References=========CVE-2014-8779http://pexip.com/security-bulletins
Information------------Advisory by NetsparkerName: XSS Vulnerability in Blubrry PowerPressAffected Software : Blubrry PowerPressAffected Versions: 6.0 and possibly belowVendor Homepage : https://wordpress.org/plugins/powerpress/Vulnerability Type : Cross-site ScriptingSeverity : ImportantCVE-ID: CVE-2015-1385Netsparker Advisory Reference : NS-15-001Description-----------By exploiting a Cross-site scripting vulnerability the attacker canhijack a logged in user?s session. This means that the malicioushacker can change the logged in user?s password and invalidate thesession of the victim while the hacker maintains access. As seen fromthe XSS example in this article, if a web application is vulnerable tocross-site scripting and the administrator?s session is hijacked, themalicious hacker exploiting the vulnerability will have full adminprivileges on that web application.Netsparker finds and reports security issues and vulnerabilities suchas SQL Injection and Cross-site Scripting (XSS) in all websites andweb applications regardless of the platform and the technology theyare built on. Netsparker's unique detection and exploitationtechniques allows it to be dead accurate in reporting hence it's thefirst and the only False Positive Free web application securityscanner.--------------------Proof of Concept URLs for XSS in Blubrry PowerPress WordPress plugin:/wp-admin/admin.php?page=powerpress/powerpressadmin_
categoryfeeds.php&action=powerpress-editcategoryfeed&cat=1';"--></style></scRipt><scRipt>alert(0x014068)</scRipt>For more information on cross-site scripting vulnerabilities read thefollowing article on Cross-site Scripting (XSS) -https://www.netsparker.com/web-vulnerability-scanner/vulnerability-security-checks-index/crosssite-scripting-xss/Advisory Timeline--------------------22/01/2015 - First Contact26/01/2015 - Vulnerability fixed29/01/2015 - Advisory releasedSolution--------------------Download version 6.0.1 which includes fix for this vulnerability.Credits & Authors--------------------These issues have been discovered by Omar Kurt while testingNetsparker Web Application Security Scanner -https://www.netsparker.com/web-vulnerability-scanner/About Netsparker--------------------Netsparker finds and reports security issues and vulnerabilities suchas SQL Injection and Cross-site Scripting (XSS) in all websites andweb applications regardless of the platform and the technology theyare built on. Netsparker's unique detection and exploitationtechniques allows it to be dead accurate in reporting hence it's thefirst and the only False Positive Free web application securityscanner. For more information visit our website onhttps://www.netsparker.com