[FD] APPLE-SA-2017-04-03-1 iOS 10.3.1

2017-04-03 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 APPLE-SA-2017-04-03-1 iOS 10.3.1 iOS 10.3.1 is now available and addresses the following: Wi-Fi Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation and later Impact: Impact: An attacker within range may be a

[FD] Cross-site request forgery (CSRF) vulnerability in the D-Link (DIR 615 ) Wireless Router Firmware:20.09

2017-04-03 Thread pratik shah
*Title:* D-Link DIR 615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability *Credit:* == Name: Pratik S. Shah *Reference:* = CVE Details: CVE-2017-7398. *Date:* 1-04-2017 *Vendor:* == D-Link wireless router *Product:* ==

[FD] CVE Request -- mapr: information disclosure vulnerability

2017-04-03 Thread Mark Felder
Hello, The mapr web frontend component creates an information disclosure vulnerability. During the setup of mapr the configure.sh script calls a function ConfigureWSRole: function ConfigureWSRole() { if [ $clientOnly -eq 0 -a $dontChangeSecurityPermissionsOn -eq 0 ]; then ConfigureRunUse

[FD] CVE-2017-7239: ninka license identification tool: insufficient escaping of external input [vs]

2017-04-03 Thread Dirk-Willem van Gulik
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ninka license identification tool insufficient escaping of external input CVE-2017-7239 / CVSS 9.3 1.06 The ninka license identification tool does not properly escape special characters

[FD] Trend Micro Enterprise Mobile Security Android Application - MITM SSL Certificate Vulnerability (CVE-2016-9319)

2017-04-03 Thread David Coomber
Trend Micro Enterprise Mobile Security Android Application - MITM SSL Certificate Vulnerability (CVE-2016-9319) -- http://www.info-sec.ca/advisories/Trend-Micro-Enterprise-Mobile-Security.html Overview "Trend Micro Mobile Security is the client app for Trend Micro’s enterprise mobility platform.

[FD] SEC Consult SA-20170403-0 :: Misbehavior of PHP fsockopen function

2017-04-03 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20170403-0 > === title: Misbehavior of the "fsockopen" function product: PHP vulnerable version: 7.1.2 fixed version: CVE