2015 m. rugpjūčio 3 d., pirmadienis

FreeBSD Security Advisory FreeBSD-SA-15:16.openssh

============================================================
=================
FreeBSD-SA-15:16.openssh                                    Security Advisory
                                                          The FreeBSD Project

Topic:          OpenSSH multiple vulnerabilities

Category:       contrib
Module:         openssh
Announced:      2015-07-28
Affects:        All supported versions of FreeBSD.
Corrected:      2015-07-28 19:58:44 UTC (stable/10, 10.2-PRERELEASE)
                2015-07-28 19:58:44 UTC (stable/10, 10.2-BETA2-p2)
                2015-07-28 19:59:04 UTC (releng/10.2, 10.2-RC1-p1)
                2015-07-28 19:59:11 UTC (releng/10.1, 10.1-RELEASE-p16)
                2015-07-28 19:58:54 UTC (stable/9, 9.3-STABLE)
                2015-07-28 19:59:22 UTC (releng/9.3, 9.3-RELEASE-p21)
                2015-07-28 19:58:54 UTC (stable/8, 8.4-STABLE)
                2015-07-28 19:59:22 UTC (releng/8.4, 8.4-RELEASE-p35)
CVE Name:       CVE-2014-2653, CVE-2015-5600

For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:https://security.FreeBSD.org/>.

I.   Background

OpenSSH is an implementation of the SSH protocol suite, providing an
encrypted and authenticated transport for a variety of services,
including remote shell access.

The security of the SSH connection relies on the server authenticating
itself to the client as well as the user authenticating itself to the
server.  SSH servers uses host keys to verify their identity.

RFC 4255 has defined a method of verifying SSH host keys using Domain
Name System Security (DNSSEC), by publishing the key fingerprint using
DNS with "SSHFP" resource record.  RFC 6187 has defined methods to use
a signature by a trusted certification authority to bind a given public
key to a given digital identity with X.509v3 certificates.

The PAM (Pluggable Authentication Modules) library provides a flexible
framework for user authentication and session setup / teardown.

OpenSSH uses PAM for password authentication by default.

FreeBSD Security Advisory FreeBSD-SA-15:17.bind

============================================================
=================
FreeBSD-SA-15:17.bind                                       Security Advisory
                                                          The FreeBSD Project

Topic:          BIND remote denial of service vulnerability

Category:       contrib
Module:         bind
Announced:      2015-07-28
Credits:        ISC
Affects:        FreeBSD 8.x and FreeBSD 9.x.
Corrected:      2015-07-28 19:58:54 UTC (stable/9, 9.3-STABLE)
                2015-07-28 19:59:22 UTC (releng/9.3, 9.3-RELEASE-p21)
                2015-07-28 19:58:54 UTC (stable/8, 8.4-STABLE)
                2015-07-28 19:59:22 UTC (releng/8.4, 8.4-RELEASE-p35)
CVE Name:       CVE-2015-5477

For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:https://security.FreeBSD.org/>.

I.   Background

BIND 9 is an implementation of the Domain Name System (DNS) protocols.
The named(8) daemon is an Internet Domain Name Server.

II.  Problem Description

An error in the handling of TKEY queries can be exploited by an attacker
for use as a denial-of-service vector, as a constructed packet can use
the defect to trigger a REQUIRE assertion failure, causing BIND to exit.

phpFileManager 0.9.8 CSRF Backdoor Shell Vulnerability

[+] Credits: John Page ( hyp3rlinx )

[+] Domains: hyp3rlinx.altervista.org

[+] Source:  http://hyp3rlinx.altervista.org/advisories/AS-PHPFILEMANAGER0729.txt



Vendor:
================================
phpfm.sourceforge.net



Product:
============================
phpFileManager version 0.9.8


Vulnerability Type:
==========================
CSRF Remote Backdoor Shell



CVE Reference:
==============
N/A



Advisory Information:
==============================
==========
CSRF Remote Backdoor Shell Vulnerability

[security bulletin] HPSBGN03367 rev.1 - HP TransactionVision with RC4 Stream Cipher, Remote Disclosure of Information

Note: the current version of the following document is available here:
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/
docDisplay?docId=emr_na-c04727082

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c04727082
Version: 1

HPSBGN03367 rev.1 - HP TransactionVision with RC4 Stream Cipher, Remote
Disclosure of Information

NOTICE: The information in this Security Bulletin should be acted upon as
soon as possible.

Release Date: 2015-07-29
Last Updated: 2015-07-29

Potential Security Impact: Remote disclosure of information

Source: Hewlett-Packard Company, HP Software Security Response Team

VULNERABILITY SUMMARY
A potential security vulnerability has been identified with HP
TransactionVision.

2015 m. liepos 31 d., penktadienis

Cross-Site Scripting (XSS) in qTranslate WordPress Plugin

Advisory ID: HTB23265
Product: qTranslate WordPress plugin
Vendor: Qian Qin
Vulnerable Version(s): 2.5.39  and probably prior
Tested Version: 2.5.39
Advisory Publication:  July 1, 2015  [without technical details]
Vendor Notification: July 1, 2015
Public Disclosure: July 29, 2015
Vulnerability Type: Cross-Site Scripting [CWE-79]
CVE Reference: CVE-2015-5535
Risk Level: Medium
CVSSv2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Discovered and Provided: High-Tech Bridge Security Research Lab (https://www.htbridge.com/advisory/ )

------------------------------------------------------------
-----------------------------------

Advisory Details:

High-Tech Bridge Security Research Lab discovered vulnerability in qTranslate WordPress plugin, which can be exploited to perform Cross-Site Scripting (XSS) attacks against website administrators. Successful exploitation of this vulnerability may allow a remote attacker to gain complete control over the web application, if the victim visits a malicious page with XSS exploit. This vulnerability can also be used to perform drive-by-download or phishing attacks against website administrators.

Input passed via "edit" HTTP GET parameter to "/wp-admin/options-general.php" is not properly sanitised before being returned to the user. A remote attacker can trick a logged-in administrator to open a specially crafted link and execute arbitrary HTML and script code in browser in context of the vulnerable website.

A simple exploit below will display a JS popup with "ImmuniWeb" word:

http://wordpress/wp-admin/options-general.php?page=qtranslate&edit=%22%3E%3Cscript%3Ealert%28%2FImmuniWeb%2F%29%3B%3C%2Fscript%3E