============================================================
=================FreeBSD-SA-15:16.openssh Security Advisory The FreeBSD ProjectTopic: OpenSSH multiple vulnerabilitiesCategory: contribModule: opensshAnnounced: 2015-07-28Affects: All supported versions of FreeBSD.Corrected: 2015-07-28 19:58:44 UTC (stable/10, 10.2-PRERELEASE) 2015-07-28 19:58:44 UTC (stable/10, 10.2-BETA2-p2) 2015-07-28 19:59:04 UTC (releng/10.2, 10.2-RC1-p1) 2015-07-28 19:59:11 UTC (releng/10.1, 10.1-RELEASE-p16) 2015-07-28 19:58:54 UTC (stable/9, 9.3-STABLE) 2015-07-28 19:59:22 UTC (releng/9.3, 9.3-RELEASE-p21) 2015-07-28 19:58:54 UTC (stable/8, 8.4-STABLE) 2015-07-28 19:59:22 UTC (releng/8.4, 8.4-RELEASE-p35)CVE Name: CVE-2014-2653, CVE-2015-5600For general information regarding FreeBSD Security Advisories,including descriptions of the fields above, security branches, and thefollowing sections, please visit <URL:https://security.FreeBSD.org/>.I. BackgroundOpenSSH is an implementation of the SSH protocol suite, providing anencrypted and authenticated transport for a variety of services,including remote shell access.The security of the SSH connection relies on the server authenticatingitself to the client as well as the user authenticating itself to theserver. SSH servers uses host keys to verify their identity.RFC 4255 has defined a method of verifying SSH host keys using DomainName System Security (DNSSEC), by publishing the key fingerprint usingDNS with "SSHFP" resource record. RFC 6187 has defined methods to usea signature by a trusted certification authority to bind a given publickey to a given digital identity with X.509v3 certificates.The PAM (Pluggable Authentication Modules) library provides a flexibleframework for user authentication and session setup / teardown.OpenSSH uses PAM for password authentication by default.
============================================================
=================FreeBSD-SA-15:17.bind Security Advisory The FreeBSD ProjectTopic: BIND remote denial of service vulnerabilityCategory: contribModule: bindAnnounced: 2015-07-28Credits: ISCAffects: FreeBSD 8.x and FreeBSD 9.x.Corrected: 2015-07-28 19:58:54 UTC (stable/9, 9.3-STABLE) 2015-07-28 19:59:22 UTC (releng/9.3, 9.3-RELEASE-p21) 2015-07-28 19:58:54 UTC (stable/8, 8.4-STABLE) 2015-07-28 19:59:22 UTC (releng/8.4, 8.4-RELEASE-p35)CVE Name: CVE-2015-5477For general information regarding FreeBSD Security Advisories,including descriptions of the fields above, security branches, and thefollowing sections, please visit <URL:https://security.FreeBSD.org/>.I. BackgroundBIND 9 is an implementation of the Domain Name System (DNS) protocols.The named(8) daemon is an Internet Domain Name Server.II. Problem DescriptionAn error in the handling of TKEY queries can be exploited by an attackerfor use as a denial-of-service vector, as a constructed packet can usethe defect to trigger a REQUIRE assertion failure, causing BIND to exit.
[+] Credits: John Page ( hyp3rlinx )[+] Domains: hyp3rlinx.altervista.org[+] Source: http://hyp3rlinx.altervista.org/advisories/AS-PHPFILEMANAGER0729.txtVendor:================================phpfm.sourceforge.netProduct:============================phpFileManager version 0.9.8Vulnerability Type:==========================CSRF Remote Backdoor ShellCVE Reference:==============N/AAdvisory Information:==============================
==========CSRF Remote Backdoor Shell Vulnerability
Note: the current version of the following document is available here:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04727082SUPPORT COMMUNICATION - SECURITY BULLETINDocument ID: c04727082Version: 1HPSBGN03367 rev.1 - HP TransactionVision with RC4 Stream Cipher, RemoteDisclosure of InformationNOTICE: The information in this Security Bulletin should be acted upon assoon as possible.Release Date: 2015-07-29Last Updated: 2015-07-29Potential Security Impact: Remote disclosure of informationSource: Hewlett-Packard Company, HP Software Security Response TeamVULNERABILITY SUMMARYA potential security vulnerability has been identified with HPTransactionVision.
Advisory ID: HTB23265Product: qTranslate WordPress pluginVendor: Qian QinVulnerable Version(s): 2.5.39 and probably priorTested Version: 2.5.39Advisory Publication: July 1, 2015 [without technical details]Vendor Notification: July 1, 2015Public Disclosure: July 29, 2015Vulnerability Type: Cross-Site Scripting [CWE-79]CVE Reference: CVE-2015-5535Risk Level: MediumCVSSv2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)Discovered and Provided: High-Tech Bridge Security Research Lab (https://www.htbridge.com/advisory/ )------------------------------------------------------------
-----------------------------------Advisory Details:High-Tech Bridge Security Research Lab discovered vulnerability in qTranslate WordPress plugin, which can be exploited to perform Cross-Site Scripting (XSS) attacks against website administrators. Successful exploitation of this vulnerability may allow a remote attacker to gain complete control over the web application, if the victim visits a malicious page with XSS exploit. This vulnerability can also be used to perform drive-by-download or phishing attacks against website administrators.Input passed via "edit" HTTP GET parameter to "/wp-admin/options-general.php" is not properly sanitised before being returned to the user. A remote attacker can trick a logged-in administrator to open a specially crafted link and execute arbitrary HTML and script code in browser in context of the vulnerable website.A simple exploit below will display a JS popup with "ImmuniWeb" word:http://wordpress/wp-admin/options-general.php?page=qtranslate&edit=%22%3E%3Cscript%3Ealert%28%2FImmuniWeb%2F%29%3B%3C%2Fscript%3E