Monday, September 8, 2014

Vulnerability Summary for the Week of September 1, 2014 | US-CERT

Source: Vulnerability Summary for the Week of September 1, 2014 | US-CERT


The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology(NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cybersecurity and Communications Integration Center (NCCIC) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit theNVD, which contains historical vulnerability information.
The vulnerabilities are based on the CVE vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:
  • High - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0
  • Medium - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9
  • Low - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9
Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.

High Vulnerabilities

Primary
Vendor -- Product
DescriptionPublishedCVSS ScoreSource & Patch Info
arubanetworks -- clearpass_policy_managerThe management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands.2014-08-299.0CVE-2014-2593
MISC
XF
BID
OSVDB
check_mk_project -- check_mkThe wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to an automation URL.2014-09-029.3CVE-2014-5340
BUGTRAQ
MISC
cisco -- ios_xrCisco IOS XR 4.3(.2) and earlier, as used in Cisco Carrier Routing System (CRS), allows remote attackers to cause a denial of service (CPU consumption and IPv6 packet drops) via a malformed IPv6 packet, aka Bug ID CSCuo95165.2014-09-047.1CVE-2014-3353
codeaurora -- android-msmThe device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, enables MSM_CAM_IOCTL_SET_MEM_MAP_INFO ioctl calls for an unrestricted mmap interface, which allows attackers to gain privileges via a crafted application.2014-08-317.2CVE-2013-2595
codeaurora -- android-msmStack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.2014-08-317.2CVE-2013-2597
gnu -- glibcOff-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.2014-08-297.5CVE-2014-5119
CONFIRM
MISC
BID
MLIST
MLIST
FULLDISC
MISC
ibm -- db2Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to execute arbitrary code via a crafted ALTER MODULE statement.2014-09-048.5CVE-2014-3094
XF
AIXAPAR
AIXAPAR
AIXAPAR
AIXAPAR
mozilla -- firefoxMultiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.2014-09-0310.0CVE-2014-1553
CONFIRM
CONFIRM
CONFIRM
CONFIRM
CONFIRM
CONFIRM
CONFIRM
mozilla -- firefoxMultiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.2014-09-0310.0CVE-2014-1554
CONFIRM
CONFIRM
CONFIRM
CONFIRM
mozilla -- firefoxUnspecified vulnerability in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.2014-09-0310.0CVE-2014-1562
CONFIRM
mozilla -- firefoxUse-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG animation with DOM interaction that triggers incorrect cycle collection.2014-09-0310.0CVE-2014-1563
CONFIRM
mozilla -- firefoxUse-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to execute arbitrary code via text that is improperly handled during the interaction between directionality resolution and layout.2014-09-039.3CVE-2014-1567
CONFIRM
novell -- groupwiseThe client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.2014-09-0410.0CVE-2014-0610
CONFIRM
s3ql_project -- s3qlS3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object in (1) common.py or (2) local.py in backends/.2014-09-027.5CVE-2014-0485
MLIST
DEBIAN
solarwinds -- log_and_event_managerSolarWinds Log and Event Manager before 6.0 uses "static" credentials, which makes it easier for remote attackers to obtain access to the database and execute arbitrary code via unspecified vectors, related to HyperSQL.2014-09-047.5CVE-2014-5504
MISC
CONFIRM
tibco -- spotfire_serverUnspecified vulnerability in the Authentication Module in TIBCO Spotfire Server before 4.5.2, 5.0.x before 5.0.3, 5.5.x before 5.5.2, 6.0.x before 6.0.3, and 6.5.x before 6.5.1 allows remote attackers to gain privileges, and obtain sensitive information or modify data, via unknown vectors.2014-09-047.5CVE-2014-5285
vmturbo -- operations_managervmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell metacharacters in the fileDate parameter in a DOWN call.2014-08-297.5CVE-2014-5073
XF
BID
OSVDB
EXPLOIT-DB
MISC
SECUNIA
MISC
MISC
zend -- zend_frameworkThe GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.2014-09-047.5CVE-2014-2685
MANDRIVA
MLIST
CONFIRM
Back to top

Medium Vulnerabilities

Primary
Vendor -- Product
DescriptionPublishedCVSS ScoreSource & Patch Info
amazon -- kindleThe Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.2014-08-305.8CVE-2014-3908
JVNDB
JVN
apache -- commons-httpclienthttp/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.2014-09-044.3CVE-2012-6153
CONFIRM
BID
CONFIRM
REDHAT
apache -- poiThe OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.2014-09-044.3CVE-2014-3529
CONFIRM
SECUNIA
CONFIRM
apache -- poiApache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.2014-09-044.3CVE-2014-3574
SECUNIA
CONFIRM
check_mk_project -- check_mkCheck_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remote authenticated users to write check_mk config files (.mk files) to arbitrary locations via vectors related to row selections.2014-09-024.9CVE-2014-5339
BUGTRAQ
MISC
cisco -- cloud_portalCisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, related to an "iFrame vulnerability," aka Bug ID CSCuh84801.2014-08-304.3CVE-2014-3352
codeaurora -- android-msmapp/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to overwrite signature-verification code via crafted boot-image load-destination header values that specify memory locations within bootloader memory.2014-08-316.6CVE-2013-2598
codeaurora -- android-msmA certain Qualcomm Innovation Center (QuIC) patch to the NativeDaemonConnector class in services/java/com/android/server/NativeDaemonConnector.java in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.3.x enables debug logging, which allows attackers to obtain sensitive disk-encryption passwords via a logcat call.2014-08-315.0CVE-2013-2599
exim -- eximThe dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.2014-09-046.8CVE-2014-2957
CONFIRM
exim -- eximexpand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.2014-09-044.6CVE-2014-2972
CONFIRM
FEDORA
FEDORA
CONFIRM
freedesktop -- popplerDCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file.2014-08-294.3CVE-2010-5110
SUSE
CONFIRM
SECUNIA
MLIST
google -- android_browserThe Android Browser application 4.2.1 on Android allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\u0000javascript: sequence.2014-09-025.8CVE-2014-6041
MISC
hl7 -- c-cdaCross-site scripting (XSS) vulnerability in CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted reference element within a nonXMLBody element.2014-09-024.3CVE-2014-3861
MISC
hl7 -- c-cdaCDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, leading to information disclosure in a Referer log.2014-09-024.3CVE-2014-3862
MISC
hl7 -- c-cdaCDA.xsl in HL7 C-CDA 1.1 and earlier does not anticipate the possibility of invalid C-CDA documents with crafted XML attributes, which allows remote attackers to conduct XSS attacks via a document containing a table that is improperly handled during unrestricted xsl:copy operations.2014-09-024.3CVE-2014-5452
MISC
ibm -- cognos_tm1The client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 stores obfuscated passwords in memory, which allows remote authenticated users to obtain sensitive cleartext information via an unspecified security tool.2014-09-044.0CVE-2014-0863
XF
ibm -- business_process_managerIBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.2014-09-044.0CVE-2014-4758
XF
AIXAPAR
ibm -- business_process_managerAn unspecified Ajax service in the Content Management toolkit in IBM Business Process Manager (BPM) 8.5.x through 8.5.5 allows remote authenticated users to obtain sensitive information by performing a document-attachment search and then reading document properties in the search results.2014-09-044.0CVE-2014-4759
XF
iii -- encore_discovery_solutionOpen redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.2014-08-295.8CVE-2014-5127
BID
BUGTRAQ
iii -- encore_discovery_solutionInnovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitive information via unspecified vectors.2014-08-295.0CVE-2014-5128
BID
BUGTRAQ
iii -- sierraCross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.2014-09-024.3CVE-2014-5136
BUGTRAQ
iii -- sierraInnovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of login requests, possibly related to the Webpac Pro submodule.2014-09-025.0CVE-2014-5137
BUGTRAQ
labanquepostale -- labanquepostaleThe La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework.2014-09-024.3CVE-2014-5076
MISC
linux -- linux_kernelThe kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.2014-08-314.3CVE-2014-3601
CONFIRM
linux -- linux_kernelStack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted iso9660 image with a CL entry referring to a directory entry that has a CL entry.2014-08-314.0CVE-2014-5471
MISC
CONFIRM
MLIST
linux -- linux_kernelThe parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry.2014-08-314.0CVE-2014-5472
MISC
CONFIRM
MLIST
lua -- luaBuffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.2014-09-045.0CVE-2014-5461
BID
MLIST
DEBIAN
DEBIAN
manageengine -- device_expertReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.2014-09-045.0CVE-2014-5377
MISC
XF
BID
BUGTRAQ
EXPLOIT-DB
FULLDISC
FULLDISC
FULLDISC
MISC
mcafee -- network_security_managerCross-site request forgery (CSRF) vulnerability in the User Management module in McAfee Network Security Manager (NSM) before 6.1.15.39 7.1.5.x before 7.1.5.15, 7.1.15.x before 7.1.15.7, 7.5.x before 7.5.5.9, and 8.x before 8.1.7.3 allows remote attackers to hijack the authentication of users for requests that modify user accounts via unspecified vectors.2014-08-296.8CVE-2014-2390
SECTRACK
mcafee -- web_gatewayThe Accounts tab in the administrative user interface in McAfee Web Gateway (MWG) before 7.3.2.9 and 7.4.x before 7.4.2 allows remote authenticated users to obtain the hashed user passwords via unspecified vectors.2014-09-024.0CVE-2014-6064
SECTRACK
mikejolley -- download_monitorCross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.2014-09-044.3CVE-2012-4768
CONFIRM
SECUNIA
MISC
OSVDB
BUGTRAQ
mozilla -- firefoxMozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image.2014-09-034.3CVE-2014-1564
CONFIRM
mozilla -- firefoxThe mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 does not properly create audio timelines, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via crafted API calls.2014-09-035.0CVE-2014-1565
CONFIRM
mozilla -- firefoxMozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD card during processing of file: URLs, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1515.2014-09-034.3CVE-2014-1566
CONFIRM
phorum -- phorumCross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via the group parameter.2014-09-044.3CVE-2012-4234
MISC
XF
BID
SECUNIA
MISC
BUGTRAQ
plack_project -- plackPlack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to bypass the whitelist of generated files and obtain sensitive information via a crafted path, related to Plack::Middleware::Static.2014-09-045.0CVE-2014-5269
OSVDB
MLIST
FEDORA
FEDORA
CONFIRM
qpw.famvanakkeren -- quick_post_widgetMultiple cross-site scripting (XSS) vulnerabilities in Quick Post Widget plugin 1.9.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Title, (2) Content, or (3) New category field to wordpress/ or (4) query string to wordpress/.2014-09-034.3CVE-2012-4226
XF
BID
MISC
MISC
BUGTRAQ
sap -- crystal_reportsStack-based buffer overflow in SAP Crystal Reports allows remote attackers to execute arbitrary code via a crafted data source string in an RPT file.2014-09-046.8CVE-2014-5505
CONFIRM
MISC
CONFIRM
sap -- crystal_reportsDouble free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connection string record in an RPT file.2014-09-046.8CVE-2014-5506
CONFIRM
MISC
CONFIRM
sap -- netweaverBuffer overflow in disp+work.exe 7000.52.12.34966 and 7200.117.19.50294 in the Dispatcher in SAP NetWeaver 7.00 and 7.20 allows remote authenticated users to cause a denial of service or execute arbitrary code via unspecified vectors.2014-09-056.5CVE-2014-6252
CONFIRM
SECUNIA
CONFIRM
MISC
sixapart -- movable_typeCross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.2014-08-294.3CVE-2012-1503
XF
BID
EXPLOIT-DB
MISC
MISC
OSVDB
torrentflux -- torrentfluxTorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.2014-09-054.0CVE-2014-6028
MISC
SECTRACK
MLIST
MLIST
torrentflux -- torrentfluxTorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an editCookies action to profile.php.2014-09-054.9CVE-2014-6029
MISC
SECTRACK
MLIST
MLIST
werdswords -- download_shortcodeDirectory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.2014-09-035.0CVE-2014-5465
BID
EXPLOIT-DB
CONFIRM
wordpress_mobile_pack_project -- wordpress_mobile_packThe WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected posts, which allows remote attackers to obtain sensitive information via an exportarticles action to export/content.php.2014-08-295.0CVE-2014-5337
MISC
BID
SECUNIA
xen -- xenXen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use a different address width, which allows local guest users to cause a denial of service (host crash) via a crafted 32-bit process.2014-08-294.3CVE-2014-5147
xrms_crm_project -- xrms_crmplugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.2014-09-026.5CVE-2014-5521
MLIST
MLIST
EXPLOIT-DB
FULLDISC
MISC
zohocorp -- manageengine_eventlog_analyzerMultiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 build 9002 allow remote attackers to inject arbitrary web script or HTML via the (1) width, (2) height, (3) url, (4) helpP, (5) tab, (6) module, (7) completeData, (8) RBBNAME, (9) TC, (10) rtype, (11) eventCriteria, (12) q, (13) flushCache, or (14) product parameter.2014-08-294.3CVE-2014-4930
BID
FULLDISC
Back to top

Low Vulnerabilities

Primary
Vendor -- Product
DescriptionPublishedCVSS ScoreSource & Patch Info
codeaurora -- android-msmThe Qualcomm Innovation Center (QuIC) init scripts in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.4.x allow local users to modify file metadata via a symlink attack on a file accessed by a (1) chown or (2) chmod command, as demonstrated by changing the permissions of an arbitrary file via an attack on the sensor-settings file.2014-08-313.3CVE-2013-6124
dhcpcd_project -- dhcpcdThe get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again.2014-09-043.3CVE-2014-6060
BID
MLIST
MLIST
MANDRIVA
CONFIRM
CONFIRM
eucalyptus -- eucalyptusThe Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading the logs.2014-09-052.1CVE-2014-5036
SECUNIA
SECUNIA
ganeti_project -- ganetiThe _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 before 2.10.7 and 2.11.0 before 2.11.5 uses world-readable permissions for the configuration backup file, which allows local users to obtain SSL keys, remote API credentials, and other sensitive information by reading the file, related to the upgrade command.2014-08-292.1CVE-2014-5247
MISC
XF
BID
BUGTRAQ
MLIST
MISC
ibm -- business_process_managerCross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.0.x allows remote authenticated users to inject arbitrary web script or HTML via an uploaded file.2014-09-043.5CVE-2014-3075
XF
ibm -- db2The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subquery of a SELECT statement.2014-09-043.5CVE-2014-3095
XF
AIXAPAR
AIXAPAR
AIXAPAR
AIXAPAR
ibm -- db2IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, which allows local users to obtain sensitive information by reading a file while a LOAD is occurring.2014-09-042.1CVE-2014-4805
CONFIRM
opensuse -- srvxMultiple integer overflows in the HelpServ module (mod-helpserv.c) in srvx 1.3.1 allow remote authenticated IRCops or HelpServ bot managers to cause a denial of service (infinite loop) via a large value in the EmptyInterval parameter or certain other interval configurations.2014-09-053.5CVE-2014-5508
BID
MLIST
MLIST

Sunday, September 7, 2014

Stock-picking gains traction as volatility looms - MarketWatch

Source:   Stock-picking gains traction as volatility looms - MarketWatch

Published: Sept 7, 2014 6:01 a.m. ET




By WALLACE WITKOWSKI

REPORTER


SAN FRANCISCO (MarketWatch) — As the S&P 500 continues to move higher into uncharted territory, strategists are suggesting a less broad-based approach when it comes to stocks — some as a cautionary measure, others out of a sense that returns are growing stale.

Even though the S&P 500 closed at a record high Friday, gains across the board were slight with both the Dow Jones Industrial Average DJIA, +0.40% and S&P 500 Index SPX, +0.50% up 0.2%, and the Nasdaq Composite Index COMP, +0.45% finishing up less than 0.1%.

If those gains are already showing signs of fatigue, then upcoming headwinds may blow the broader stock market off course. In October, the Fed will end its bond purchase program. Not only will that increase speculation of when in 2015 the Fed will hike interest rates but this will all happen around the midterm elections, when markets are traditionally volatile.




Nature: Seals at Cape Cod

Network Vulnerabilities IT Admins Can Use to Protect Their Network | Security Intelligence Blog | Trend Micro

Source:   Network Vulnerabilities IT Admins Can Use to Protect Their Network | Security Intelligence Blog | Trend Micro


Sep4
1:23 am (UTC-7)   |    by 

Being able to adapt to change is one of the most important abilities in security today, mostly because attacks to defend against are able to do the same. The sophistication of current threats is mainly seen in their skill to adjust based on the weaknesses of the environment they are targeting.

In this post, we will try to see networks the way attackers see them — through their vulnerabilities — and turn these around into guides for how IT administrators should protect their network.

People are the weakest link

People will always remain vulnerable to external stimuli, especially those that trigger strong emotions. This is whysocial engineering will always be a part of attacks — there are a lot of techniques to be used, and a high probability of effectiveness. Embracing the assumption that people will always fall victim to social engineering attacks is important for IT admins simply because it is true. Network security needs to be designed with this in mind, regardless of how oriented the employees are. IT administrators can:

1. Configure the network to not only prevent attackers from getting into the network, but also from getting data out of it. This way, even if an attacker is able to gain control of a machine in the network, exfiltrating any stolen data will be difficult. A properly managed firewall and network access control would greatly help achieve this. Threat intelligence will also play a big part here, also, such as of IPs used as C&Cs in attacks.

2. Segment the network based on the level of security the systems need. Critical systems need to be isolated from the “normal” ones, either physically or through the network segment they are connected to.

On top of these, however, employee education is still important and should be done regularly.

The safest place is the most dangerous

Even the smallest of security gaps within the network can lead to the biggest of breaches. Attackers know this well, and it is important for IT admins to keep it in mind. The network should be audited on a regular basis to make sure that all areas are properly secured.

For example, IT admins may not take into consideration that they themselves are potential targets, or that certain devices within the network can also be infection points such as the network printer or even the router.

The same goes for web administrators. Attackers might not directly breach highly-secured sites such as banking websites, instead checking for other sites in the same DMZ (demilitarized zone), compromise them, and leverage the trust-relationship to conduct a side-channel attack against the banking website.

People use weak passwords

It is no secret that password management is a challenge for most users, so working on the assumption that all members of the network have secure passwords is simply not an option. To secure the network under the assumption that users have insecure passwords would require the implementation of other authentication measures such as two-factor authentication or even biometrics.

The network is haunted by ghost machines

All networks have ghost machines in them. These are the machines that are not found in the network topology map but are connected to the network. These may consist of employees’ personal devices, external partners’ devices, or machines that should be retired but aren’t. Attackers leverage on these machines because they provide both access to the network and stealth.

In order to counter this, IT administrators need to be keen on monitoring the systems that are connected to the network. They need to implement a Network Access Control mechanism to monitor and control the level of access these ghost machines are entitled to in the network.

Old vulnerabilities are reliable and can still be used

Assessing and addressing software vulnerabilities is a critical process for every IT administrator, and should always cover all bugs — both new and old. IT administrators need to keep in mind that a vulnerability will remain a threat to a network if not addressed, regardless of how long its been since it was discovered.



Saturday, September 6, 2014

Mystery in the Ozone Layer - NASA Science

Source:  Mystery in the Ozone Layer - NASA Science







Sept. 5, 2014:  High above Earth, more than 20 miles above sea level, a diaphanous layer of ozone surrounds our planet, absorbing energetic UV rays from the sun.  It is, essentially, sunscreen for planet Earth. Without the ozone layer, we would be bathed in dangerous radiation on a daily basis, with side effects ranging from cataracts to cancer.
People were understandably alarmed, then, in the 1980s when scientists noticed that manmade chemicals in the atmosphere were destroying this layer. Governments quickly enacted an international treaty, called the Montreal Protocol, to ban ozone-destroying gases such as CFCs then found in aerosol cans and air conditioners.  On September 16, 1987, the first 24 nations signed the treaty; 173 more have signed on in the years since.
Fast forward 27 years.  Ozone-depleting chemicals have declined and the ozone hole appears to be on the mend. The United Nations has called the Montreal Protocol "the most successful treaty in UN history." Yet, despite Montreal's success, something is not … quite … right.
splash
A new ScienceCast video looks into the surprising abundance of carbon tetrachloride in the ozone layer.  Where is it coming from?
A new study by NASA researchers shows that a key ozone-depleting compound named carbon tetrachloride (CCl4) is surprisingly abundant in the ozone layer.
"We are not supposed to be seeing this at all," says NASA atmospheric scientist Qing Liang.
Auroras Underfoot (signup)
Between 2007 and 2012, countries around the world reported zero emissions of CCl4, yet measurements by satellites, weather balloons, aircraft, and surface-based sensors tell a different story.  A study led by Liang shows worldwide emissions of CCl4 average 39 kilotons per year, approximately 30 percent of peak emissions prior to the international treaty going into effect.
In the 1980s, chlorofluorocarbons became well-known to the general public.  As the ozone hole widened, "CFC" became a household word.  Fewer people, however, have heard of CCl4, once used in applications such as dry cleaning and fire-extinguishers.
"Nevertheless," says Liang, "CCl4 is a major ozone-depleting substance. It is the 3rd most important anthropogenic ozone-depleting compound behind CFC-11 and CFC-12."
image
Click to learn about the chemistry of ozone depletion from the US Environmental Protection Agency.Web link
Levels of CCl4 have been declining since the Montreal Protocol was signed, just not as rapidly as expected.  With zero emissions, abundances should have dropped by 4% per year.  Instead, the decline has been closer to 1% per year.
To investigate the discrepancy, Liang and colleagues took CCl4 data gathered by NOAA and NASA and plugged it into a NASA computer program, the 3-D GEOS Chemistry Climate Model.  This sophisticated program takes into account the way CCl4 is broken apart by solar radiation in the stratosphere as well as how the compound can be absorbed and degraded by contact with soil and ocean waters.  Model simulations pointed to an unidentified ongoing current source of CCl4.
"It is now apparent there are either unidentified industrial leakages, large emissions from contaminated sites, or unknown CCl4 sources," says Liang.
Another possibility is that the chemistry of CCl4 might not be fully understood. Tellingly, the model showed that CCl4 is lingering in the atmosphere 40% longer than previously thought. "Is there something about the physical CCl4 loss process that we don't understand?" she wonders.
It all adds up to a mystery in the ozone layer.
Liang's research was published online in the Aug. 18th issue of Geophysical Research Letters. More information about the extra CCl4 may be found there.
Credits:
Author: Dr. Tony Phillips |  Production editor: Dr. Tony Phillips | Credit: Science@NASA

Friday, September 5, 2014

Retail stocks were all strong today -- but here is the long and short term view of JCPenney (JCP) (September 04, 2014)

Source: Retail stocks were all strong today -- but here is the long and short term view of JCPenney (JCP) (September 04, 2014)






In this video I want to look at JC Penney ( NYSE:JCP ). This is a stock that I’ve been bullish on for a while; we’ll take a brief look at this. Inverse head and shoulder, left shoulder, head, right shoulder somewhere around there, neckline, you connect this peak, which is in between this low and this one, and then you look at this peak and it’s a little loosey-goosey, but this peaks somewhere around here, which is in between the head here and the right shoulder, so you connect this, and here’s what you get, it’s about $5.00 between the low here of 5.00 and around 10.00 or so; so you add that to the breakout and my price target is about $15.00 or so. That’s something you probably know about because I’ve talked about it several times with “Cramer” a time or two.

My point for mentioning this is this, the stock is working it’s way higher and that’s great, but what I want to point out to you, if you’re long, I want to point out to you that this is not going to go up like this every day. It hit a new high here, not a 52-week high, but we’ll call it a pattern high; it hadn’t been up this high since it was on it’s way down in a big hurry, so it hit a new high here at 11.24, that was the high. Today the stock eclipsed it a little bit, basically the same, 11.28 is the high. This is resistance right now. What you have to do is just understand that this is a little box here; don’t be looking at this saying, “Oh, five or six days of consolidation, now the stock’s going to move higher from here.” It may very well do that, but only if somebody’s really in trouble here on their shorts and they’re trying to push, they’ve got to get in.
There’s a little bullish chatter on JC Penney ( NYSE:JCP ), but generally speaking retail stocks were just up, it had a lot to do with Costco ( NASDAQ:COST ). Look for this to kind of trickle sideways for a while, if it does go up. fine, that’s why I’m already long and that’s why you are too and if you’re not, why not? Did you just hear about this stock? This is really what you’ve got to look for, the slope of the 50-day moving average. This can be trading sideways for a while, all the while the 50-day moving average gets closer, the 20-day moving average gets closer, and it sure seems like every time this stock hits the 20 and the 50 for that matter, the next move is higher.
So look for the potential for this stock to just trickle sideways for a while, I mean it could go sideways for a couple weeks; you mange risk, you don’t predict. I think the stock’s going higher; it could breakout tomorrow, again, it will only be is somebody’s behind the eight ball and they’ve got to cover some stock or they’ve got to buy a bunch. The stock at 30 million shares traded today, there’s plenty of liquidity out here, so patient with this stock; but also be bullish on it, because I think it’s going to work. Ultimately I do think that price target is going to be hit.

BookMark