Sophos researchers highlight a highly sophisticated operation utilizing fake trading pools of cryptocurrency from DeFi trading applications
Daily Archives: September 18, 2023
USN-6379-1: vsftpd vulnerability
It was discovered that vsftpd was vulnerable to the ALPACA TLS protocol
content confusion attack. A remote attacker could possibly use this issue
to redirect traffic from one subdomain to another.
USN-6378-1: Django vulnerability
It was discovered that Django incorrectly handled certain URIs with a very
large number of Unicode characters. A remote attacker could possibly use
this issue to cause Django to consume resources or crash, leading to a
denial of service.
USN-6377-1: LibRaw vulnerability
It was discovered that LibRaw incorrectly handled certain photo files. If a
user o automated system were tricked into processing a specially crafted
photo file, a remote attacker could possibly cause applications linked
against LibRaw to crash, resulting in a denial of service.
USN-6376-1: c-ares vulnerability
It was discovered that c-ares incorrectly parsed certain SOA replies. A
remote attacker could possibly use this issue to cause c-res to crash,
resulting in a denial of service.
Using Hacked LastPass Keys to Steal Cryptocurrency
Remember last November, when hackers broke into the network for LastPass—a password database—and stole password vaults with both encrypted and plaintext data for over 25 million users?
Well, they’re now using that data break into crypto wallets and drain them: $35 million and counting, all going into a single wallet.
That’s a really profitable hack. (It’s also bad opsec. The hackers need to move and launder all that money quickly.)
Look, I know that online password databases are more convenient. But they’re also risky. This is why my Password Safe is local only. (I know this sounds like a commercial, but Password Safe is not a commercial product.)
SEC Consult SA-20230918-0 :: Authenticated Remote Code Execution and Missing Authentication in Atos Unify OpenScape
Posted by SEC Consult Vulnerability Lab, Research via Fulldisclosure on Sep 18
SEC Consult Vulnerability Lab Security Advisory < 20230918-0 >
=======================================================================
title: Authenticated Remote Code Execution and
Missing Authentication
product: Atos Unify OpenScape Session Border Controller
Atos Unify OpenScape Branch
Atos Unify OpenScape BCF
vulnerable version: OpenScape SBC…
SEC Consult SA-20230829-0 :: Reflected Cross-Site Scripting (XSS) in PTC – Codebeamer (ALM Solution)
Posted by SEC Consult Vulnerability Lab, Research via Fulldisclosure on Sep 18
SEC Consult Vulnerability Lab Security Advisory < 20230829-0 >
=======================================================================
title: Reflected Cross-Site Scripting (XSS)
product: PTC – Codebeamer (ALM Solution)
vulnerable version: <=22.10-SP7, <=22.04-SP5, <=21.09-SP13
fixed version: >=22.10-SP8, >=22.04-SP6, >=21.09-SP14
CVE number: CVE-2023-4296…
APPLE-SA-2023-09-11-3 macOS Big Sur 11.7.10
Posted by Apple Product Security via Fulldisclosure on Sep 18
APPLE-SA-2023-09-11-3 macOS Big Sur 11.7.10
macOS Big Sur 11.7.10 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/kb/HT213915.
Apple maintains a Security Updates page at
https://support.apple.com/HT201222 which lists recent
software updates with security advisories.
ImageIO
Available for: macOS Big Sur
Impact: Processing a maliciously crafted image may lead to arbitrary
code…
APPLE-SA-2023-09-11-2 macOS Monterey 12.6.9
Posted by Apple Product Security via Fulldisclosure on Sep 18
APPLE-SA-2023-09-11-2 macOS Monterey 12.6.9
macOS Monterey 12.6.9 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/kb/HT213914.
Apple maintains a Security Updates page at
https://support.apple.com/HT201222 which lists recent
software updates with security advisories.
ImageIO
Available for: macOS Monterey
Impact: Processing a maliciously crafted image may lead to arbitrary…