what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 30 RSS Feed

Files Date: 2023-11-28

Proxmark3 4.17511 Custom Firmware
Posted Nov 28, 2023
Authored by Christian Herrmann | Site github.com

This is a custom firmware written for the Proxmark3 device. It extends the currently available firmware. This release is nicknamed Faraday.

Changes: Fixes to iCLASS commands, UDP/TCP connection speedups, Client Ipv6 support, HID SAM support, NTAG424 support, use pm3 as a generic smart card reader.
tags | tool
systems | unix
SHA-256 | f001254f9eb2fcb96df873f0404ffcc4064baf421fbcb926d0eba2c06c2da722
Fortra Digital Guardian Agent Uninstaller Cross Site Scripting / UninstallKey Cached
Posted Nov 28, 2023
Authored by Johannes Kruchem, Daniel Hirschberger, Bernhard Grundling | Site sec-consult.com

The uninstaller in Fortra Digital Guardian Agent versions prior to 7.9.4 suffers from a cross site scripting vulnerability. Additionally, the Agent Uninstaller handles sensitive data insecurely and caches the Uninstall key in memory. This key can be used to stop or uninstall the application. This allows a locally authenticated attacker with administrative privileges to disable the application temporarily or even remove the application from the system completely.

tags | exploit, xss
advisories | CVE-2023-6253
SHA-256 | d393eda92218fb28d4719259401d1db3e0731edb5b930170f2f951494d02fbc7
Debian Security Advisory 5568-1
Posted Nov 28, 2023
Authored by Debian | Site debian.org

Debian Linux Security Advisory 5568-1 - It was discovered that incorrect memory management in Fast DDS, a C++ implementation of the DDS (Data Distribution Service) might result in denial of service.

tags | advisory, denial of service
systems | linux, debian
advisories | CVE-2023-42459
SHA-256 | f98b1127ce5c74663b458fb7d53e20ef0a1319434f99078abbab9c106d3d5590
etcd-browser 87ae63d75260 Directory Traversal
Posted Nov 28, 2023
Authored by Kevin Randall

etcd-browser version 87ae63d75260 suffers from a directory traversal vulnerability.

tags | exploit, file inclusion
SHA-256 | 8456b0b8489b8c480ad32f464fbe163fc1fe87e4a533e2f02fd020993cf98140
Ubuntu Security Notice USN-6513-2
Posted Nov 28, 2023
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 6513-2 - USN-6513-1 fixed vulnerabilities in Python. This update provides the corresponding updates for Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04. It was discovered that Python incorrectly handled certain plist files. If a user or an automated system were tricked into processing a specially crafted plist file, an attacker could possibly use this issue to consume resources, resulting in a denial of service.

tags | advisory, denial of service, vulnerability, python
systems | linux, ubuntu
advisories | CVE-2022-48564, CVE-2023-40217
SHA-256 | 701ececc93d67a78a460f6a43c83e5e9e64992057fec8f161b50e2d8b859fe92
Loytec L-INX Automation Servers Information Disclosure / Cleartext Secrets
Posted Nov 28, 2023
Authored by Chizuru Toyama

Loytec LINX-151 with firmware version 7.2.4 and LINX-212 with firmware version 6.2.4 suffer from file disclosure vulnerabilities that leak secrets as well as issues with stories secrets in the clear.

tags | exploit, vulnerability, info disclosure
advisories | CVE-2023-46386, CVE-2023-46387, CVE-2023-46388, CVE-2023-46389
SHA-256 | c8d887d4717b94c1aee40cf1ff1bea9d76d8c987065fd897b45f142808786003
Loytec LINX Configurator 7.4.10 Insecure Transit / Cleartext Secrets
Posted Nov 28, 2023
Authored by Chizuru Toyama

Loytec LINX Configurator version 7.4.10 suffers from insecure transit and cleartext hardcoded secret vulnerabilities.

tags | exploit, vulnerability
advisories | CVE-2023-46383, CVE-2023-46384, CVE-2023-46385
SHA-256 | 2fb3f8f77e58786a2b8154d7b4ce1ea69b7a9be5791623aa4210e517a66a5857
WebRTC PacketRouter Dangling Entry
Posted Nov 28, 2023
Authored by Google Security Research, nedwill

A dangling pointer vulnerability is present in WebRTC's PacketRouter due to an SDP SIM group SSRC from one track (e.g., video) colliding with an existing SSRC from a different track (e.g., audio). This inconsistency between the send_modules_map_ and the send_modules_list_ can lead to a use after free.

tags | exploit
SHA-256 | 426fe7fd9743d7c7d9ba2167f870968aaad57ccdefafb8bca89ee26333cad8be
m-privacy TightGate-Pro Code Execution / Insecure Permissions
Posted Nov 28, 2023
Authored by Daniel Hirschberger, Marco Schillinger, Steven Kurka | Site sec-consult.com

m-privacy TightGate-Pro suffers from code execution, insecure permissions, deletion mitigation, and outdated server vulnerabilities.

tags | exploit, vulnerability, code execution
advisories | CVE-2023-47250, CVE-2023-47251
SHA-256 | 55d99668e130fe585eb26f5ac98889fe0cb5368f4185842bb3d4346adf9bd24b
Ubuntu Security Notice USN-6402-2
Posted Nov 28, 2023
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 6402-2 - USN-6402-1 fixed vulnerabilities in LibTomMath. This update provides the corresponding updates for Ubuntu 23.10. It was discovered that LibTomMath incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code and cause a denial of service.

tags | advisory, denial of service, arbitrary, vulnerability
systems | linux, ubuntu
advisories | CVE-2023-36328
SHA-256 | bcc649a7c6a092bbffcc80f89e984363dff2d24bfc8e18c3a8fe08eb8f47e8e8
Ubuntu Security Notice USN-6502-2
Posted Nov 28, 2023
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 6502-2 - Ivan D Barrera, Christopher Bednarz, Mustafa Ismail, and Shiraz Saleem discovered that the InfiniBand RDMA driver in the Linux kernel did not properly check for zero-length STAG or MR registration. A remote attacker could possibly use this to execute arbitrary code. Yu Hao discovered that the UBI driver in the Linux kernel did not properly check for MTD with zero erasesize during device attachment. A local privileged attacker could use this to cause a denial of service.

tags | advisory, remote, denial of service, arbitrary, kernel, local
systems | linux, ubuntu
advisories | CVE-2023-25775, CVE-2023-31085, CVE-2023-45871, CVE-2023-5090, CVE-2023-5345
SHA-256 | 3844c5b07f62a7f21e7da4b17678c476911376d85f2c2699a0fd527b28dae8a9
Ubuntu Security Notice USN-6516-1
Posted Nov 28, 2023
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 6516-1 - Ivan D Barrera, Christopher Bednarz, Mustafa Ismail, and Shiraz Saleem discovered that the InfiniBand RDMA driver in the Linux kernel did not properly check for zero-length STAG or MR registration. A remote attacker could possibly use this to execute arbitrary code. Yu Hao and Weiteng Chen discovered that the Bluetooth HCI UART driver in the Linux kernel contained a race condition, leading to a null pointer dereference vulnerability. A local attacker could use this to cause a denial of service.

tags | advisory, remote, denial of service, arbitrary, kernel, local
systems | linux, ubuntu
advisories | CVE-2023-25775, CVE-2023-31083, CVE-2023-31085, CVE-2023-3772, CVE-2023-45871
SHA-256 | e7ba5ff6d6d35068a385124ee99fb4cdf9ca4e686d62ac89918e057c43160a7b
SmartNode SN200 3.21.2-23021 OS Command Injection
Posted Nov 28, 2023
Authored by Maurizio Ruchay | Site syss.de

SmartNode SN200 versions 3.21.2-23021 and below suffer from a remote command execution vulnerability.

tags | exploit, remote
advisories | CVE-2023-41109
SHA-256 | fc0d5c184e0cd12de9f88070f90cdbe9697833c1394af267f9cccc697c7a5470
Red Hat Security Advisory 2023-7517-01
Posted Nov 28, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-7517-01 - An update is now available for Red Hat Ansible Automation Platform 2.4.

tags | advisory
systems | linux, redhat
advisories | CVE-2023-39321
SHA-256 | de7b0f96a923f2caf3e1e7d190a824bc7c8627b600ce1073db80524062296b39
Red Hat Security Advisory 2023-7515-01
Posted Nov 28, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-7515-01 - The components for Red Hat OpenShift for Windows Containers 9.0.0 are now available. This product release includes bug fixes and security updates for the following packages: windows-machine-config-operator and windows-machine-config-operator-bundle. Issues addressed include a privilege escalation vulnerability.

tags | advisory
systems | linux, redhat, windows
advisories | CVE-2023-3676
SHA-256 | 22fd27567fa73b0487fa3e141834c87327890531494fe84f9dc73b1c9657ef21
Red Hat Security Advisory 2023-7513-01
Posted Nov 28, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-7513-01 - An update for linux-firmware is now available for Red Hat Enterprise Linux 7. Issues addressed include an information leakage vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2023-20569
SHA-256 | 9c216e9b5238e40f6cf5f3130d80a00445fbd2853deb6b8a2641a5eef9159a00
Red Hat Security Advisory 2023-7512-01
Posted Nov 28, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-7512-01 - An update for firefox is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Issues addressed include a use-after-free vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2023-6204
SHA-256 | be4158093bb9088477b66e1540394213060dfa104bba7f2ba16882f5035d8f9e
Red Hat Security Advisory 2023-7511-01
Posted Nov 28, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-7511-01 - An update for firefox is now available for Red Hat Enterprise Linux 8.8 Extended Update Support. Issues addressed include a use-after-free vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2023-6204
SHA-256 | 67d39304e371fa957ff2fac527917f5e03094285e37aaad83775be71a2b58b9f
Red Hat Security Advisory 2023-7510-01
Posted Nov 28, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-7510-01 - An update for firefox is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Issues addressed include a use-after-free vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2023-6204
SHA-256 | f115f1a94ffcbe172ec34c6665df9a9e2ae659b3ba16de99fa1d948b3942d8df
Red Hat Security Advisory 2023-7509-01
Posted Nov 28, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-7509-01 - An update for firefox is now available for Red Hat Enterprise Linux 7. Issues addressed include a use-after-free vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2023-6204
SHA-256 | a6165a273ac21cbd889dfcdef59ea69689fac3283316aa04714a31192e88f2a4
Red Hat Security Advisory 2023-7508-01
Posted Nov 28, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-7508-01 - An update for firefox is now available for Red Hat Enterprise Linux 8. Issues addressed include a use-after-free vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2023-6204
SHA-256 | f3e1ee4494e42a7f4fa6fd10aa12b82d6c4e9352177c1cf3ed5d1b8a908209a8
Red Hat Security Advisory 2023-7507-01
Posted Nov 28, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-7507-01 - An update for firefox is now available for Red Hat Enterprise Linux 9. Issues addressed include a use-after-free vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2023-6204
SHA-256 | 7edb92aaef680a780d8ca591a1f843f9e2e3762c2ec2773012f50a3ccbbb13d7
Red Hat Security Advisory 2023-7506-01
Posted Nov 28, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-7506-01 - An update for thunderbird is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Issues addressed include a use-after-free vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2023-6204
SHA-256 | b379358c72f62f083f678995c0db0b52013b72431cf7c43bc590bf9d8cfbde6b
Red Hat Security Advisory 2023-7505-01
Posted Nov 28, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-7505-01 - An update for thunderbird is now available for Red Hat Enterprise Linux 7. Issues addressed include a use-after-free vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2023-6204
SHA-256 | a68be71ee76d32248f220827b605e39ae2d94af397c9d695e5522809d4ee2cb1
Red Hat Security Advisory 2023-7504-01
Posted Nov 28, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-7504-01 - An update for thunderbird is now available for Red Hat Enterprise Linux 8.8 Extended Update Support. Issues addressed include a use-after-free vulnerability.

tags | advisory
systems | linux, redhat
advisories | CVE-2023-6204
SHA-256 | 66578075e360e832f27694d7b2effe808d5c74951c1ebb88c9764fccd314e446
Page 1 of 2
Back12Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close