[security bulletin] HPSBHF03088 rev.1 - HP Integrity SD2 CB900s i2 and i4 Servers running OpenSSL, Remote Unauthorized Access or Disclosure of Information

2014-08-13 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04397114 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04397114 Version: 1 HPSBHF03088

Reflected Cross-Site Scripting (XSS) in Jamroom

2014-08-13 Thread High-Tech Bridge Security Research
Advisory ID: HTB23224 Product: Jamroom Vendor: Talldude Networks, LLC Vulnerable Version(s): 5.2.6 and probably prior Tested Version: 5.2.6 Advisory Publication: July 23, 2014 [without technical details] Vendor Notification: July 23, 2014 Vendor Patch: July 23, 2014 Public Disclosure: August 13

[oCERT-2014-006] Ganeti insecure archive permission

2014-08-13 Thread Andrea Barisani
#2014-006 Ganeti insecure archive permission Description: Ganeti, an open source virtualisation manager, suffers from an insecure file permission vulnerability that leads to sensitive information disclosure. The Ganeti upgrade command 'gnt-cluster upgrade' creates an archive of the current conf

BlackBerry Z 10 - Storage and Access File-Exchange Authentication By-Pass [MZ-13-04]

2014-08-13 Thread security
- modzero  Security Advisory:  BlackBerry  Z 10  -  Storage and  Access File-Exchange Authentication By-Pass [MZ-13-04] - --