chromium-112.0.5615.165-1.el9

Read Time:16 Second

FEDORA-EPEL-2023-91a369658f

Packages in this update:

chromium-112.0.5615.165-1.el9

Update description:

update to 112.0.5615.165. Fixes the following security issues:

CVE-2023-2004 CVE-2023-2133 CVE-2023-2134 CVE-2023-2135 CVE-2023-2136 CVE-2023-2137 CVE-2023-2033 CVE-2023-2136

Read More

chromium-112.0.5615.165-1.el7

Read Time:25 Second

FEDORA-EPEL-2023-30f3deb00a

Packages in this update:

chromium-112.0.5615.165-1.el7

Update description:

update to 112.0.5615.165. Fixes the following security issues:

CVE-2023-2004 CVE-2023-2133 CVE-2023-2134 CVE-2023-2135 CVE-2023-2136 CVE-2023-2137 CVE-2023-2033 CVE-2023-2136

update to 112.0.5615.121. Fixes the following security issues:

CVE-2023-2004 CVE-2023-2133 CVE-2023-2134 CVE-2023-2135 CVE-2023-2136 CVE-2023-2137 CVE-2023-2033

Read More

Multiple Vulnerabilities in PaperCut NG/MF Could Allow for Remote Code Execution

Read Time:32 Second

Multiple vulnerabilities have been discovered in PaperCut NG/MF, the most severe of which could allow for remote code execution. PaperCut NG/MF is a comprehensive print management system. Successful exploitation of this vulnerability could allow for unauthenticated remote attackers to execute arbitrary code on the server in the context of the System user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

Read More

Cisco patches high and critical flaws across several products

Read Time:27 Second

Cisco fixed serious vulnerabilities across several of its products this week, including in its Industrial Network Director, Modeling Labs, ASR 5000 Series Routers, and BroadWorks Network Server. The flaws can lead to administrative command injection, authentication bypass, remote privilege escalation and denial of service.

The Cisco Industrial Network Director (IND), a network monitoring and management server for operational technology (OT) networks, received patches for two vulnerabilities rated critical and medium respectively. These were fixed in version 1.11.3 of the software.

To read this article in full, please click here

Read More

Iran cyberespionage group taps SimpleHelp for persistence on victim devices

Read Time:22 Second

Iranian APT hacking group MuddyWater has been observed using SimpleHelp, a legitimate remote device control and management tool, to ensure persistence on victim devices. 

SimpleHelp itself, as used by the threat actors, has not been compromised — instead, the group has found a way to download the tool from the official website and use it in their attacks, according to a Group-IB blog post.

To read this article in full, please click here

Read More

Checking existence of firewalled URLs via javascript’s script.onload

Read Time:21 Second

Posted by Georgi Guninski on Apr 21

There is minor information disclosure vulnerability similar
to nmap in browser.

It is possible to check the existence of firewalled URL U via
the following javascript in a browser:

<script src=”U”
onload=”alert(‘Exists’)”
onerror=”alert(‘Does not exist’)”>

This might have privacy implication on potentially
“semi-blind CSRF” (XXX does this makes sense?).

Works for me in…

Read More

Checking existence of firewalled web servers in Firefox via iframe.onload

Read Time:23 Second

Posted by Georgi Guninski on Apr 21

In short in Firefox 112, it is possible to check existence
of firewalled web servers. This doesn’t work in Chrome and Chromium 112
for me.

If user A has tcp connection to web server B, then in the
following html:

<iframe src=”http://B&quot; onload=”load()” onerror=”alert(‘error’)” id=”i1″ />

the javascript function load() will get executed if B serves
valid document to A’s browser…

Read More