This vulnerability allows remote attackers to execute arbitrary code on affected installations of SAP 3D Visual Enterprise Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Monthly Archives: June 2022
ZDI-22-864: SAP 3D Visual Enterprise Viewer PCX File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SAP 3D Visual Enterprise Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
ZDI-22-865: SAP 3D Visual Enterprise Viewer CGM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SAP 3D Visual Enterprise Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
ZDI-22-853: Trend Micro Proxy One Pro Incorrect Permission Assignment Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Proxy One Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
ZDI-22-854: (Pwn2Own) OPC Foundation UA .NET Standard Resource Exhaustion Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard. Authentication is not required to exploit this vulnerability.
ZDI-22-855: (Pwn2Own) Unified Automation OPC UA C++ Demo Server TranslateBrowsePathsToNodeId Resource Exhaustion Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server. Authentication is not required to exploit this vulnerability.
ZDI-22-856: OPC Foundation UA .NET Standard Improper Input Validation Authentication Bypass Vulnerability
restic-0.13.1-1.el9
FEDORA-EPEL-2022-e3b62a5569
Packages in this update:
restic-0.13.1-1.el9
Update description:
Update to latest upstream release 0.13.1
restic-0.13.1-1.el8
FEDORA-EPEL-2022-8d638fabd8
Packages in this update:
restic-0.13.1-1.el8
Update description:
Upgrade to upstream 0.13.1
Updated Go build dependencies to resolve #2074251, #2084694, and #2084874
Smashing Security podcast #279: Encrypted notes, and a deadly case of AirTag spying
How did a saxophonist sneak sensitive information in and out of the Soviet Union? How might an Apple AirTag have led to murder? And isn’t the world of cryptocurrency and blockchain doing just great?
All this and more is discussed in the latest edition of the award-winning “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault.