Local root exploit for Glibc versions 2.11.3 and 2.12.x utilizing LD_AUDIT libmemusage.so.
dbe0977154f9ed4331b96211af365a5ddd2b1de1c5253179073a44cea5e541e3
Moxiecode File Manager (MCFileManager) versions 3.1.5 and below suffer from a remote shell upload vulnerability. Moxiecode is a commercial plugin for TinyMCE.
d69aae839dcc779cfba73a5bfb9cc79a717869c8399e3bd4c4f76e7dab581afe
Apple Security Advisory 2013-05-16-1 - iTunes 11.0.3 is now available and addresses multiple vulnerabilities. In versions prior to 11.0.3, an attacker in a privileged network position may manipulate HTTPS server certificates, leading to the disclosure of sensitive information and a man-in-the-middle attack is possible while browsing the iTunes Store via iTunes and may lead to an unexpected application termination or arbitrary code execution.
129669243b0bb2df5dce9d7152161d7c442f69bbbdf4f07f334021c9431610e2
Slackware Security Advisory - New ruby packages are available for Slackware 13.1, 13.37, 14.0, and -current to fix a security issue.
97c44b0c5921578ed223dc9e1f8ecc69b707abd56893b0ab5a24e9cbf6ba6b3e
Slackware Security Advisory - New mozilla-thunderbird packages are available for Slackware64 13.37 and 14.0. These were accidentally omitted from the last upload.
6edb722d8113e31c670188ca160b3ee46b13f82a9318c40ab2d6220f664bcd83
Red Hat Security Advisory 2013-0832-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. It was found that the Red Hat Enterprise Linux 6.1 kernel update introduced an integer conversion issue in the Linux kernel's Performance Events implementation. This led to a user-supplied index into the perf_swevent_enabled array not being validated properly, resulting in out-of-bounds kernel memory access. A local, unprivileged user could use this flaw to escalate their privileges.
16ebeb97ba0237baefdabcda52e494ff100d3a172e89cd6d916049e2d170d1a2
Nginx versions 1.3.9 through 1.4.0 suffer from a denial of service vulnerability.
545ee012c3d75d1d38d47e527a614966ce9593fd109eb03f37bdf8105f5b48b0