VU#856152: NUUO and Netgear Network Video Recorder (NVR) products web interfaces contain multiple vulnerabilities

NUUO NVRmini 2,NVRsolo,Crystal,and Netgear ReadyNAS Surveillance products have web management interfaces containing multiple vulnerabilities that can be leveraged to gain complete control of affected devices. Continue reading VU#856152: NUUO and Netgear Network Video Recorder (NVR) products web interfaces contain multiple vulnerabilities

Patched libarchive Vulnerabilities Have Big Reach

Libarchive was patched against three memory-related vulnerabilities, putting pressure on admins to ensure third-party software that also uses the library is patched. Continue reading Patched libarchive Vulnerabilities Have Big Reach

Stop doing input validation

“Buffer overflows Injection attacks DoS attacks Memory leakage Information disclosure Compromised systems” What is the common factor between all of those vulnerability classes? If you have heard advice on how to prevent or fix them, chances are that advice prescribed input validation. It’s a glib and common answer, especially to address most web application vulnerabilities: […] Continue reading Stop doing input validation