Day: September 9, 2013

Hey Apple, don’t forget these Macs need updates, too

An updated iPhone is great, but most of Apple’s Mac laptops and desktops still have outdated processors…….


Report: Twitter buys a mobile ad network for $350M in stock

Rumor has it that the information network has snatched up MoPub to help it serve ads on iOS and Android…….


Watchguard Server Center 11.7.4 Insecure Library Loading

Watchguard Server Center version 11.7.4 suffers from a dll hijacking vulnerability with wgpr.dll…….


Mandriva Linux Security Advisory 2013-227

Mandriva Linux Security Advisory 2013-227 – A vulnerability has been discovered and corrected in easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the…


Ubuntu Security Notice USN-1948-1

Ubuntu Security Notice 1948-1 – It was discovered that httplib2 only validated SSL certificates on the first request to a connection, and didn’t report validation failures on subsequent requests. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could possibly be exploited in certain scenarios to alter or compromise confidential information…


Red Hat Security Advisory 2013-1218-01

Red Hat Security Advisory 2013-1218-01 – Apache Santuario implements the XML Signature Syntax and Processing and XML Encryption Syntax and Processing standards. A flaw was found in the way Apache Santuario XML Security for Java validated XML signatures. Santuario allowed a signature to specify an arbitrary canonicalization algorithm, which would be applied to the SignedInfo…


Red Hat Security Advisory 2013-1219-01

Red Hat Security Advisory 2013-1219-01 – Apache Santuario implements the XML Signature Syntax and Processing and XML Encryption Syntax and Processing standards. A flaw was found in the way Apache Santuario XML Security for Java validated XML signatures. Santuario allowed a signature to specify an arbitrary canonicalization algorithm, which would be applied to the SignedInfo…


Red Hat Security Advisory 2013-1220-01

Red Hat Security Advisory 2013-1220-01 – Apache Santuario implements the XML Signature Syntax and Processing and XML Encryption Syntax and Processing standards. A flaw was found in the way Apache Santuario XML Security for Java validated XML signatures. Santuario allowed a signature to specify an arbitrary canonicalization algorithm, which would be applied to the SignedInfo…


Red Hat Security Advisory 2013-1221-01

Red Hat Security Advisory 2013-1221-01 – Fuse Message Broker is a messaging platform based on Apache ActiveMQ that provides SOA infrastructure to connect processes across heterogeneous systems. It was found that, by default, the Apache ActiveMQ web console did not require authentication. A remote attacker could use this flaw to modify the state of the…


Red Hat Security Advisory 2013-1217-01

Red Hat Security Advisory 2013-1217-01 – Apache Santuario implements the XML Signature Syntax and Processing and XML Encryption Syntax and Processing standards. A flaw was found in the way Apache Santuario XML Security for Java validated XML signatures. Santuario allowed a signature to specify an arbitrary canonicalization algorithm, which would be applied to the SignedInfo…