Red Hat Security Advisory 2019-3788-01 - The OpenStack Load Balancing service provides a Load Balancing-as-a-Service version 2 implementation for Red Hat OpenStack platform director based installations.
a78df754c97ad92bf546d94dbbefd97cbc0d28a30d5f10b8a574d0509ad1aa43
Red Hat Security Advisory 2019-3787-01 - KVM is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products. Issues addressed include buffer overflow and null pointer vulnerabilities.
8e4d3810598234327ba6d03cc845938b8e95e572a82683c42e164f9272c7e3e8
Red Hat Security Advisory 2019-3789-01 - Ansible is a simple model-driven configuration management, multi-node deployment, and remote-task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically. Issues addressed include information leakage and traversal vulnerabilities.
5fba3daa955457daa792f7cc77f588da395cd01388ca5032d2a072a9b3d02de4
Red Hat Security Advisory 2019-3775-01 - Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 78.0.3904.87. Issues addressed include a use-after-free vulnerability.
ee332ecb82e40270ba3e5c70f160c6ad48517389cb1866d62c579c3f5a4ac692
Red Hat Security Advisory 2019-3722-01 - Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the openshift-enterprise-hypershift container image for Red Hat OpenShift Container Platform 4.1.22. Issues addressed include a cross site scripting vulnerability.
7307cc6d5d7e762f7a4171af37c8cf5394af85f14937ebc7420c137d11ef6293
Ubuntu Security Notice 4177-1 - It was discovered that the Rygel package automatically started the daemon by default in user sessions. In certain environments, this resulted in media being shared contrary to expectations.
4f1e706406b532be2a729166fc0a21fa13745f26e6c195b01ca0fe89d961275e
Ubuntu Security Notice 4176-1 - Thomas Habets discovered that GNU cpio incorrectly handled certain inputs. An attacker could possibly use this issue to access sensitive information.
3a7eb879440e20068b69d3f593d69c28fbb2cefc58912a367f955f6a94bd75dc
Red Hat Security Advisory 2019-3755-01 - The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root. A privilege escalation vulnerability has been addressed.
fecc3ab5bb53a8824d91a6af2607f6a82153b3a57b7d4e5f75046455a08e93b7
This Metasploit module exploits the SNMP write access configuration ability of SNMP-EXTEND-MIB to configure MIB extensions and lead to remote code execution.
702e8fa024af1fdfe52310f0907a43a2e55b297f9be065518dc96428e4d4315e
This Metasploit module exploits CVE-2017-13156 in Android to install a payload into another application. The payload APK will have the same signature and can be installed as an update, preserving the existing data. The vulnerability was fixed in the 5th December 2017 security patch, and was additionally fixed by the APK Signature scheme v2, so only APKs signed with the v1 scheme are vulnerable. Payload handler is disabled, and a multi/handler must be started first.
07dfdc4313d8080e07f5b2661f0494022dcf8b3a5afcb2da795fd921a4b33c84
Red Hat Security Advisory 2019-3756-01 - Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 68.2.0. Issues addressed include buffer overflow, bypass, cross site scripting, and use-after-free vulnerabilities.
59bfe19103b4687534079d95b182dc1f8f3e30930f4ee500b46157a6721ebe55
Red Hat Security Advisory 2019-3758-01 - The patch program applies diff files to originals. The diff command is used to compare an original to a changed file. Diff lists the changes made to the file. A person who has the original file can then use the patch command with the diff file to add the changes to their original file. Issues addressed include a code execution vulnerability.
6bc2a5f7e7d47cab38157a0d41ad815d8be6b27a4760ce1d6c6cf011a3e56b90
Red Hat Security Advisory 2019-3757-01 - The patch program applies diff files to originals. The diff command is used to compare an original to a changed file. Diff lists the changes made to the file. A person who has the original file can then use the patch command with the diff file to add the changes to their original file. Issues addressed include a code execution vulnerability.
1300b7b227229f6bf7638f4bef11b7398c4c690f0979f4e4edeb8d1e84f213ef
This Metasploit module exploits an unauthenticated command injection vulnerability in rConfig versions 3.9.2 and prior. The install directory is not automatically removed after installation, allowing unauthenticated users to execute arbitrary commands via the ajaxServerSettingsChk.php file as the web server user. This module has been tested successfully on rConfig version 3.9.2 on CentOS 7.7.1908 (x64).
c186325528acbfb5de4f3fa7f089b9e55a0ed4689c4440a3e05bf3134759a1f7
Red Hat Security Advisory 2019-3754-01 - The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root. A privilege escalation vulnerability was addressed.
50d042f1c370d63bc0ce1203e16441e4f374b83fd0353d4660e47a52f2b308a1
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication using the RDS component. Due to default settings or misconfiguration, its password can be set to an empty value. This allows an attacker to create a session via the RDS login that can be carried over to the admin web interface even though the passwords might be different, and therefore bypassing authentication on the admin web interface leading to arbitrary code execution. Tested on Windows and Linux with ColdFusion 9.
3d52780df4fd657f5edbff4f1d8f4865fab5e58f3cd48af4352aa3aafdd16a32
Red Hat Security Advisory 2019-3759-01 - Chromium is an open-source web browser, powered by WebKit. This update upgrades Chromium to version 78.0.3904.70. Issues addressed include bypass, file download, and use-after-free vulnerabilities.
1204514d2bf9bebc684e1be07f89564cd886891703251220cc7025b4c08a09a9
Red Hat Security Advisory 2019-3744-01 - Ansible is a simple model-driven configuration management, multi-node deployment, and remote-task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically. Issues addressed include information leakage and traversal vulnerabilities.
19dfbe0b0631d6ee801a6300eacdd4c9c6e7fc627fe06a7837c05d5dc559e07f
Red Hat Security Advisory 2019-3742-01 - KVM is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products. Issues addressed include buffer overflow and null pointer vulnerabilities.
3cde6495f120132649d51a76b5d5f82fc73a657251effbb701fccdb5879aa031
WebKit suffers from an integer overflow in NodeRareData::m_connectedFrameCount that can lead to universal cross site scripting and type confusion.
9569f6db23eb36db6453cff6a1099fc4b733d4c6c9f6c9804237589bef0532d9
Travesty is a tool that can leverage a known directory traversal to assist in identifying interesting directories and files.
293428749e98bd1e7a59e6c0b2f55dd18872c3e73a8ff6357ffbf51cf66d0c37
Adaware Web Companion version 4.8.2078.3950 suffers from an unquoted service path vulnerability.
663516a6179860741e1aa3677ad8cc9b2d3be256f5fd3ef01aa603f466cd0e70