+44 (0)203 88 020 88

Vulnerabilities

1 million ProFTPD servers vulnerable to RCE

A potential remote code execution vulnerability has been discovered in the popular GPL-licensed FTP server ProFTPD ProFTPD is running on over a million servers exposed to the internet. It is included in several Linux distros including Debian, Suse and Ubuntu. The flaw, tracked under CVE-2019-12815 lives in the mod_copy module. The flaw allows an unauthenticated user to […]

1 million ProFTPD servers vulnerable to RCE Read More »

Critical vulnerability patched in Jira

Atlassian has released new versions of Jira Server and Jira Data Centre that address a critical vulnerability which has lived in the code for almost 8 years. The vulnerability, CVE-2019-11581 is a server-side template injection vulnerability. According to the security advisory from Atlassian: There was a server-side template injection vulnerability in Jira Server and Data Center,

Critical vulnerability patched in Jira Read More »

July patch Tuesday fixes RCE in DHCP

Microsoft’s July Patch Tuesday updates resolve 77 vulnerabilities in Windows software, including two zero-day vulnerabilities which are being actively exploited and remote code execution vulnerabilities in DHCP Server and MS SQL Server. DHCP Server RCE vulnerability If you have your Microsoft DHCP server configured with a failover server, an attacker can send a specially crafted

July patch Tuesday fixes RCE in DHCP Read More »

Exim mail server vulnerable to remote command execution

The world’s most popular mail server is vulnerable to a remote command execution flaw Exim is the world’s most popular mail server, with 57% of the mail servers connected to the web running Exim (as of June 2019). The vulnerability reported by Qualys (CVE-2019-10149) affects Exim versions 4.87 to 4.91 inclusive running on several Linux

Exim mail server vulnerable to remote command execution Read More »

Zombieload – a new class of Intel CPU vulnerability

A team including some of the researchers who discovered the Spectre and Meltdown vulnerabilities in AMD and Intel CPU announced a new class of vulnerability affecting Intel CPU which they called Zombieload. Like Spectre and Meltdown, the Zombieload vulnerability exploits weaknesses in the implementation of speculative execution in Intel CPUs.  The different attack names reflect

Zombieload – a new class of Intel CPU vulnerability Read More »

Scroll to Top