Should You Send Your Pen Test Report to the MSRC?

2018-11-13 KENNETH 0

Should You Send Your Pen Test Report to the MSRC? Every day, the Microsoft Security Response Center (MSRC) receives vulnerability reports from security researchers, technology/industry partners, and customers. We want those reports, because they help us make our products and services more secure. High-quality reports that include proof of concept, details of an attack or demonstration of a vulnerability, and a detailed writeup of the issue are extremely helpful and actionable. If you send these reports to us, thank you! Customers seeking to evaluate and harden their environments may ask penetration testers to probe their deployment and report on the findings. These reports can help that customer find and correct security risk(s) in their deployment. The catch is that the pen test report findings need to be evaluated in the context of that customer’s group policy objects, mitigations, tools, and [ more… ]

No Image

USN-3816-1: systemd vulnerabilities

2018-11-13 KENNETH 0

USN-3816-1: systemd vulnerabilities systemd vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in systemd. Software Description systemd – system and service manager Details Jann Horn discovered that unit_deserialize incorrectly handled status messages above a certain length. A local attacker could potentially exploit this via NotifyAccess to inject arbitrary state across re-execution and obtain root privileges. (CVE-2018-15686) Jann Horn discovered a race condition in chown_one(). A local attacker could potentially exploit this by setting arbitrary permissions on certain files to obtain root privileges. This issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-15687) It was discovered that systemd-tmpfiles mishandled symlinks in non-terminal path components. A local attacker could potentially exploit this by gaining ownership of certain files to obtain root privileges. This [ more… ]

No Image

USN-3815-2: gettext vulnerability

2018-11-12 KENNETH 0

USN-3815-2: gettext vulnerability gettext vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 ESM Summary gettext could be made to execute arbitrary code if it received a specially crafted message. Software Description gettext – GNU Internationalization utilities Details USN-3815-1 fixed a vulnerability in gettext. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that gettext incorrectly handled certain messages. An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM gettext – 0.18.1.1-5ubuntu3.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References USN-3815-1 CVE-2018-18751 Source: USN-3815-2: gettext vulnerability

No Image

USN-3815-1: gettext vulnerability

2018-11-12 KENNETH 0

USN-3815-1: gettext vulnerability gettext vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary gettext could be made to execute arbitrary code if it received a specially crafted message. Software Description gettext – GNU Internationalization utilities Details It was discovered that gettext incorrectly handled certain messages. An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10 gettext – 0.19.8.1-8ubuntu0.1 Ubuntu 18.04 LTS gettext – 0.19.8.1-6ubuntu0.1 Ubuntu 16.04 LTS gettext – 0.19.7-2ubuntu3.1 Ubuntu 14.04 LTS gettext – 0.18.3.1-1ubuntu3.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2018-18751 Source: USN-3815-1: gettext vulnerability