Stefan Metzmacher discovered a flaw in Samba, a SMB/CIFS file, print,and login server for Unix. Specific combinations of parameters andpermissions can allow user to escape from the share path definition andsee the complete / filesystem. Unix permission checks in the kernelare still enforced.
More info:
https://www.debian.org/security/2019/dsa-4513
Alf-Andre Walla discovered a remotely triggerable assert in the Varnishweb accelerator; sending a malformed HTTP request could result in denialof service.
More info:
https://www.debian.org/security/2019/dsa-4514
Type: Vulnerability. Microsoft ASP.NET Core and .NET Framework are prone to an information disclosure vulnerability; fixes are available.
More info:
http://www.symantec.com/security_response/vulnerability.jsp?bid=106405&om_rssid=sr-advisories
https://wordpress.org/news/2019/09/wordpress-5-2-3-security-and-maintenance-release/WordPress 5.2.3 is now available! This security and maintenance release features 29 fixes and enhancements. Plus, it adds a number of security fixes—see the list below. These bugs affect WordPress versions 5.2.2 and earlier; version 5.2.3 fixes them, so you’ll want to upgrade. If you haven’t yet updated to 5.2, there are also updated versions […]
More info:
https://wordpress.org/news/2019/09/wordpress-5-2-3-security-and-maintenance-release/
Type: Vulnerability. Microsoft ASP.NET Core and .NET Framework are prone to a remote denial-of-service vulnerability; fixes are available.
More info:
http://www.symantec.com/security_response/vulnerability.jsp?bid=108232&om_rssid=sr-advisories
Type: Vulnerability. Microsoft ASP.NET Core and .NET Framework are prone to a remote denial-of-service vulnerability; fixes are available.
More info:
http://www.symantec.com/security_response/vulnerability.jsp?bid=108207&om_rssid=sr-advisories
https://wpvulndb.com/vulnerabilities/9860
More info:
https://wpvulndb.com/vulnerabilities/9860
https://wpvulndb.com/vulnerabilities/9860
More info:
https://wpvulndb.com/vulnerabilities/9860
https://ithemes.com/wordpress-vulnerability-roundup-august-2019-part-2/Several new WordPress plugin and theme vulnerabilities were disclosed during the last half of August, so we want to keep you aware. In this post, we cover recent WordPress plugin and theme vulnerabilities and what to do if you are running one of the vulnerable plugins or themes on your website. We divide the WordPress […]
More info:
https://ithemes.com/wordpress-vulnerability-roundup-august-2019-part-2/
https://wpvulndb.com/vulnerabilities/9858
More info:
https://wpvulndb.com/vulnerabilities/9858