No Image

USN-5956-2: PHPMailer vulnerability

2023-03-16 KENNETH 0

USN-5956-2: PHPMailer vulnerability USN-5956-1 fixed vulnerabilities in PHPMailer. It was discovered that the fix for CVE-2017-11503 was incomplete. This update fixes the problem. Original advisory details: Dawid Golunski discovered that PHPMailer was not properly escaping user input data used as arguments to functions executed by the system shell. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 ESM. (CVE-2016-10033, CVE-2016-10045) It was discovered that PHPMailer was not properly escaping characters in certain fields of the code_generator.php example code. An attacker could possibly use this issue to conduct cross-site scripting (XSS) attacks. This issue was only fixed in Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2017-11503) Yongxiang Li discovered that PHPMailer was not properly converting relative paths provided as user input when adding attachments to messages, which could lead to relative image URLs [ more… ]

No Image

Microsoft Store App Awards 2023 nominations are now open!

2023-03-16 KENNETH 0

Microsoft Store App Awards 2023 nominations are now open! Microsoft Store App Awards is back this year! Nominations are now open through March 29, 2023, and the form is located here. For more information, keep reading. Attention Windows users, developers, and app enthusiasts! We are excited to announce the upcoming Microsoft Store App Awards 2023, the most anticipated event for the Microsoft Store community! After the incredible success of last year’s awards, we are eager to celebrate the achievements of the brightest and most innovative minds in the industry. The 2022 award recipients brought forward an impressive lineup of apps that showcased the limitless possibilities of the Windows platform. From productivity to entertainment, from creativity to social networks, the array of apps  demonstrated excellence in their user experience, design, app quality, and most of all, customer value. Check out last [ more… ]

No Image

USN-5957-1: LibreCAD vulnerabilities

2023-03-16 KENNETH 0

USN-5957-1: LibreCAD vulnerabilities Cody Sixteen discovered that LibreCAD incorrectly handled memory when parsing DXF files. An attacker could use this issue to cause LibreCAD to crash, leading to a denial of service. This issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-19105) Lilith of Cisco Talos discovered that LibreCAD incorrectly handled memory when parsing DWG files. An attacker could use this issue to cause LibreCAD to crash, leading to a denial of service, or possibly execute arbitrary code. (CVE-2021-21898, CVE-2021-21899) Lilith of Cisco Talos discovered that LibreCAD incorrectly handled memory when parsing DRW files. An attacker could use this issue to cause LibreCAD to crash, leading to a denial of service, or possibly execute arbitrary code. (CVE-2021-21900) Albin Eldstål-Ahrens discovered that LibreCAD incorrectly handled memory when parsing JWW files. An attacker could use this issue to cause LibreCAD [ more… ]

No Image

USN-5956-1: PHPMailer vulnerabilities

2023-03-15 KENNETH 0

USN-5956-1: PHPMailer vulnerabilities Dawid Golunski discovered that PHPMailer was not properly escaping user input data used as arguments to functions executed by the system shell. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 ESM. (CVE-2016-10033, CVE-2016-10045) It was discovered that PHPMailer was not properly escaping characters in certain fields of the code_generator.php example code. An attacker could possibly use this issue to conduct cross-site scripting (XSS) attacks. This issue was only fixed in Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2017-11503) Yongxiang Li discovered that PHPMailer was not properly converting relative paths provided as user input when adding attachments to messages, which could lead to relative image URLs being treated as absolute local file paths and added as attachments. An attacker could possibly use this issue to access unauthorized resources and [ more… ]

No Image

USN-5955-1: Emacs vulnerability

2023-03-15 KENNETH 0

USN-5955-1: Emacs vulnerability It was discovered that Emacs did not properly manage certain files when using htmlfontify functionality. A local attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary commands. Source: USN-5955-1: Emacs vulnerability