Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
– File systems infrastructure;
– Network traffic control;
(CVE-2024-46800, CVE-2024-43882)
Category Archives: Advisories
APPLE-SA-11-19-2024-5 macOS Sequoia 15.1.1
Posted by Apple Product Security via Fulldisclosure on Nov 21
APPLE-SA-11-19-2024-5 macOS Sequoia 15.1.1
macOS Sequoia 15.1.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/121753.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
JavaScriptCore
Available for: macOS Sequoia
Impact: Processing maliciously crafted web content may lead to arbitrary…
Local Privilege Escalations in needrestart
Posted by Qualys Security Advisory via Fulldisclosure on Nov 21
Qualys Security Advisory
LPEs in needrestart (CVE-2024-48990, CVE-2024-48991, CVE-2024-48992,
CVE-2024-10224, and CVE-2024-11003)
========================================================================
Contents
========================================================================
Summary
Background
CVE-2024-48990 (and CVE-2024-48992)
CVE-2024-48991
CVE-2024-10224 (and CVE-2024-11003)
Mitigation
Acknowledgments
Timeline
I got bugs…
APPLE-SA-11-19-2024-4 iOS 17.7.2 and iPadOS 17.7.2
Posted by Apple Product Security via Fulldisclosure on Nov 21
APPLE-SA-11-19-2024-4 iOS 17.7.2 and iPadOS 17.7.2
iOS 17.7.2 and iPadOS 17.7.2 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/121754.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
JavaScriptCore
Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch
2nd generation…
APPLE-SA-11-19-2024-3 iOS 18.1.1 and iPadOS 18.1.1
Posted by Apple Product Security via Fulldisclosure on Nov 21
APPLE-SA-11-19-2024-3 iOS 18.1.1 and iPadOS 18.1.1
iOS 18.1.1 and iPadOS 18.1.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/121752.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
JavaScriptCore
Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch
3rd generation…
APPLE-SA-11-19-2024-2 visionOS 2.1.1
Posted by Apple Product Security via Fulldisclosure on Nov 21
APPLE-SA-11-19-2024-2 visionOS 2.1.1
visionOS 2.1.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/121755.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
JavaScriptCore
Available for: Apple Vision Pro
Impact: Processing maliciously crafted web content may lead to arbitrary
code…
APPLE-SA-11-19-2024-1 Safari 18.1.1
Posted by Apple Product Security via Fulldisclosure on Nov 21
APPLE-SA-11-19-2024-1 Safari 18.1.1
Safari 18.1.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/121756.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
JavaScriptCore
Available for: macOS Ventura and macOS Sonoma
Impact: Processing maliciously crafted web content may lead to…
Reflected XSS – fronsetiav1.1
Posted by Andrey Stoykov on Nov 21
# Exploit Title: Reflected XSS – fronsetiav1.1
# Date: 11/2024
# Exploit Author: Andrey Stoykov
# Version: 1.1
# Tested on: Debian 12
# Blog:
https://msecureltd.blogspot.com/2024/11/friday-fun-pentest-series-14-reflected.html
Reflected XSS #1 – “show_operations.jsp”
Steps to Reproduce:
1. Visit main page of the application.
2. In the input field of “WSDL Location” enter the following payload “><img
src=x…
XXE OOB – fronsetiav1.1
Posted by Andrey Stoykov on Nov 21
# Exploit Title: XXE OOB – fronsetiav1.1
# Date: 11/2024
# Exploit Author: Andrey Stoykov
# Version: 1.1
# Tested on: Debian 12
# Blog:
https://msecureltd.blogspot.com/2024/11/friday-fun-pentest-series-15-oob-xxe.html
XXE OOB
Description:
– It was found that the application was vulnerable XXE (XML External Entity
Injection)
Steps to Reproduce:
1. Add Python3 server to serve malicious XXE payload
2. Add a file on the file system to be read…
St. Poelten UAS | Path Traversal in Korenix JetPort 5601
Posted by Weber Thomas via Fulldisclosure on Nov 21
St. Pölten UAS 20241118-1
——————————————————————————-
title| Path Traversal
product| Korenix JetPort 5601
vulnerable version| 1.2
fixed version| –
CVE number| CVE-2024-11303
impact| High
homepage| https://www.korenix.com/
found| 2024-05-24
by| P. Oberndorfer, B. Tösch, M….