ep's blog

VMware vmrun utility local privilege escalation

https://www.vmware.com/security/advisories/VMSA-2011-0006.html

"The VMware vmrun utility is susceptible to a local privilege escalation
in non-standard configurations."

All users of the vmrun utility should visit the advisory and see if
his/her instance is susceptible. If so, it is critical to update the
software through the links provided in the advisory.

APPLE-SA-2010-11-18-1 Safari 5.0.3 and Safari 4.1.3

http://support.apple.com/kb/HT4455
http://support.apple.com/kb/HT4455

Safari 5.0.3 and Safari 4.1.3 is now available and fix various security
vulnerabilities including: unexpected application termination, arbitrary
code execution, surreptitious user tracking, disclosure of image data,
location bar address spoofing, location bar arbitrary history insertion,
undesired DNS prefetching.

OpenSSL buffer overflow vulnerability

http://www.openssl.org/news/secadv_20101116.txt

"All versions of OpenSSL supporting TLS extensions contain this
vulnerability including OpenSSL 0.9.8f through 0.9.8o, 1.0.0, 1.0.0a
releases.

Any OpenSSL based TLS server is vulnerable if it is multi-threaded and
uses OpenSSL's internal caching mechanism. Servers that are
multi-process and/or disable internal session caching are NOT affected.

Pages