Last episode for 2018! This week we look at CVEs in lxml, CUPS, pixman, FreeRDP & more, plus we discuss the security of home routers as evaluated by C-ITL.
Show Notes
Overview
Last episode for 2018! This week we look at CVEs in lxml, CUPS, pixman, FreeRDP & more, plus we discuss the security of home routers as evaluated by C-ITL.
Tries to remove clean input document and remove links (to say embedded
javascript code) - but doesn’t account for links containing escaped
characters - so link could persist
Similar to CVE-2014-3146
In this case tried to account for whitespace in links but didn’t include
all possible whitespace characters
Also found Linux kernel on MIPS either has executable stack (until 2016)
due to FP emulation code, or since then has no executable stack but has a
RWX segment at a fixed location, which can be used to bypass DEP / ASLR
Ubuntu does not support MIPS
Final episode for 2018
This is the last episode for 2018, on leave for the next 3 weeks
Next episode will be from Cape Town in 2019 during week of 14th January with some special guests… :)