Mr.Trunk · @mrtrunk
9 followers · 17195 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
6 followers · 13282 posts · Server dromedary.seedoubleyou.me
aegilops :github::microsoft: · @aegilops
160 followers · 606 posts · Server fosstodon.org

I've had my first :github: CodeQL query merged into the experimental section of the official CodeQL rules!

lnkd.in/dk_tTiQZ (and a "local" variant, lnkd.in/dP88QJwa).

That's query ids java/command-line-injection-extra and java/command-line-injection-extra-local

They spot something the existing :java: command injection query does, but in a way that's more robust to unusual code.

It’s an edge case, but one that was important to a customer.

#CodeQL #sast #java #commandinjection

Last updated 1 year ago

ITSEC News · @itsecbot
1360 followers · 35907 posts · Server schleuss.online

Ghostscript bug could allow rogue documents to run system commands - Even if you've never heard of the venerable Ghostscript project, you may have it installe... nakedsecurity.sophos.com/2023/ -2023-36664

#rce #pipe #ghostscript #vulnerability #cve #commandinjection

Last updated 1 year ago

sekurak News · @sekurakbot
30 followers · 232 posts · Server mastodon.com.pl

Krytyczna podatność w bramce pocztowej mającej chronić przed złośliwymi wiadomościami. Złośliwą wiadomością można wykonać dowolny kod na bramce.

Wspomniana w tytule podatność została zidentyfikowana w urządzeniu od Barracuda. Więcej szczegółów znajdziecie tutaj. Gratulacje dla autora opisu, bo mamy tutaj samą esencję: A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure...


sekurak.pl/krytyczna-podatnosc

#wbiegu #barracuda #commandinjection #email

Last updated 1 year ago

ITSEC News · @itsecbot
856 followers · 32557 posts · Server schleuss.online

OpenSSL issues a bugfix for the previous bugfix - Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all... nakedsecurity.sophos.com/2022/

#crypto #openssl #cryptography #vulnerability #commandinjection

Last updated 2 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online