Securiteam

IndependentSecuriteam

SSD Advisory – Serviio Media Server Multiple Vulnerabilities

Credit to Author: Maor Schwartz| Date: Tue, 02 May 2017 10:58:33 +0000

Vulnerabilities Summary The following advisory describes a five (5) vulnerabilities found in Serviio Media Server. Affected version: 1.8.0.0 PRO, 1.7.1, 1.7.0, 1.6.1. Serviio is a free media server. It allows you to stream your media files (music, video or images) to renderer devices (e.g. a TV set, Bluray player, games console or mobile phone) on … Continue reading SSD Advisory – Serviio Media Server Multiple Vulnerabilities

Read More
IndependentSecuriteam

SSD Advisory – CloudBees Jenkins Unauthenticated Code Execution

Credit to Author: Maor Schwartz| Date: Mon, 01 May 2017 06:28:11 +0000

Vulnerability Summary The following advisory describes Java deserialization vulnerability found in CloudBees Jenkins version 2.32.1 that leads to a Remote Code Execution. Jenkins helps to automate the non-human part of the whole software development process with now common things like continuous integration and by empowering teams to implement the technical aspects of continuous delivery. It … Continue reading SSD Advisory – CloudBees Jenkins Unauthenticated Code Execution

Read More
IndependentSecuriteam

SSD Advisory – SquirrelMail Remote Code Execution

Credit to Author: Maor Schwartz| Date: Tue, 25 Apr 2017 05:24:06 +0000

Vulnerability Summary The following advisory describes Remote Code Execution found in SquirrelMail version 1.4.22. SquirrelMail is a standards-based webmail package written in PHP. It includes built-in pure PHP support for the IMAP and SMTP protocols, and all pages render in pure HTML 4.0 (with no JavaScript required) for maximum compatibility across browsers. It has very … Continue reading SSD Advisory – SquirrelMail Remote Code Execution

Read More
IndependentSecuriteam

SSD Advisory – Emby Media Server Multiple Vulnerabilities

Credit to Author: Maor Schwartz| Date: Tue, 25 Apr 2017 05:03:48 +0000

Vulnerabilities Summary The following advisory describes three (3) vulnerabilities found in Emby Media Server. Affected versions are: 3.1.5, 3.1.2, 3.1.1, 3.1.0 and 3.0.0. Emby Media Server (formerly Media Browser) is a media server designed to organize, play, and stream audio and video to a variety of devices. Emby is open-source, and uses a client server model. … Continue reading SSD Advisory – Emby Media Server Multiple Vulnerabilities

Read More
IndependentSecuriteam

SSD Advisory – HPE OpenCall Media Platform (OCMP) Multiple Vulnerabilities

Credit to Author: Maor Schwartz| Date: Mon, 24 Apr 2017 05:57:39 +0000

Vulnerabilities Summary The following advisory describes Reflected Cross-Site Scripting (XSS) vulnerabilities and a Remote File Inclusion vulnerability that when combined can lead to arbitrary Javascript code execution, were found in HP OpenCall Media Platform (OCMP), version 4.3.2. HPE OpenCall Media Platform (OCMP) is a suite of software and hardware applications which allow implementation of common … Continue reading SSD Advisory – HPE OpenCall Media Platform (OCMP) Multiple Vulnerabilities

Read More
IndependentSecuriteam

Security conferences – Survival guide 2017 Q3

Credit to Author: Maor Schwartz| Date: Thu, 20 Apr 2017 07:10:46 +0000

The security conferences “Survival guide” for 2017 Q3 is here! We have gathered the following information for you for each conference: Dates Place Link to official conference website Ticket price Lectures Workshops So let’s get started: Security conferences – Survival guide part 3 Camp++ Dates: 6 – 9 July 2017 Place: Fort Monostor, Komárom, Hungary … Continue reading Security conferences – Survival guide 2017 Q3

Read More
IndependentSecuriteam

SSD Advisory – Linksys PPPoE Multiple Vulnerabilities

Credit to Author: Maor Schwartz| Date: Wed, 19 Apr 2017 13:52:33 +0000

Vulnerabilities Summary The following advisory describes two (2) vulnerabilities found in Linksys EA, XAC and AC series devices. The vulnerabilities has been found in the way the Linksys devices (EA, XAC and AC series) handle the Point-to-point protocol over Ethernet (PPPoE) Discovery (PPPoED) process allowing an unprivileged active attacker on the same network segment (layer2) … Continue reading SSD Advisory – Linksys PPPoE Multiple Vulnerabilities

Read More
IndependentSecuriteam

SSD Advisory – Ubuntu LightDM Guest Account Local Privilege Escalation

Credit to Author: Maor Schwartz| Date: Tue, 18 Apr 2017 10:00:24 +0000

Vulnerability Summary The following advisory describes a local privilege escalation via LightDM found in Ubuntu versions 16.10 / 16.04 LTS. Ubuntu is an open source software platform that runs everywhere from IoT devices, the smartphone, the tablet and the PC to the server and the cloud. LightDM is an X display manager that aims to be lightweight, … Continue reading SSD Advisory – Ubuntu LightDM Guest Account Local Privilege Escalation

Read More