Ubuntu Security Notice 3340-1 - Emmanuel Dreyfus discovered that third-party modules using the ap_get_basic_auth_pw function outside of the authentication phase may lead to authentication requirements being bypassed. This update adds a new ap_get_basic_auth_components function for use by third-party modules. Vasileios Panopoulos discovered that the Apache mod_ssl module may crash when third-party modules call ap_hook_process_connection during an HTTP request to an HTTPS port. Various other issues were also addressed.
4fbb0cd5128e4b23de1949c019dde3ebd97609ecd0bfa2b4a8e88c05d3455098
IBM DB2 versions 9.7, 10.1, 10.5, and 11.1 suffer from a command line process buffer overflow vulnerability.
9fcbc5360bbab3d3d0d5f91e96ba944fd77fa77b62d50735a37991cb02aa1f1f
Microsoft Skype versions 7.2, 7.35 and 7.36 suffer from a stack buffer overflow vulnerability.
0e0544408b08435e8c9b2a3021530969e5be446fa97e97008d000530d1c7c8ad
JAD version 1.5.8e-1kali1 suffers from a buffer overflow vulnerability.
802114a05907d65bb9ed538820a7f40a9bb461fc90ea763cdd2ae06a674e7c36
75 bytes small Linux/x86 shellcode that binds a shell to port 4444. Contains no NULLs.
d53564a1b5086ca9438ce3b8d47f4ecf791f83665b4a94bb8208f3045bba4d87
LAME version 3.99.5 suffers from a II_step_one buffer overflow vulnerability.
c0d47bb7301f022f6f4bca87c719e9d35f43e22feb39a4162f5c1684559fbe46
LAME version 3.99.5 suffers from a III_dequantize_sample stack buffer overflow vulnerability.
adb0e16c8d53d98759bcd81531a4dde6b96e3e0af1359518a613652b71bfdd37
NTFS version 3.1 master file table denial of service exploit.
023ff239fff9f7065185a583b55580bf454882eb7fde9dbcd03bd0550c46debe
D-Link DIR-100 suffers from brute force and cross site request forgery vulnerabilities.
386fd93a4422b5c30c240c4eb2594da9d9779d096bf555c60db8d9a08d208dae
Whitepaper called Fully Undetectable Malware. Translated to English.
a265b29ba1e3f7e24e1530963506da2733ed4e5a624e5dcab390f90cdf6911ae