(Dec 20) Fraudulent security certificates could allow sensitive information tobe exposed when accessing the Internet.
Archive for December 24th, 2013
Debian: 2826-1: denyhosts: Remote denial of ssh servic
(Dec 22) Helmut Grohne discovered that denyhosts, a tool preventing SSH brute-force attacks, could be used to perform remote denial of service against the SSH daemon. Incorrectly specified regular expressions used to detect brute force attacks in authentication logs could be exploited [More…]
Case 84681 Summary Arbitrary file read for ACL limited reseller accounts via XML-API. Security Rating cPanel has assigned a Security Level of Important to this vulnerability. Description The WHM XML and JSON APIs allowed arbitrary files to be read through the “getpkginfo” API call. By sending a crafted input to …