Handler on Duty: Jan Kopriva
Threat Level: green
Podcast Detail
#IPv6 Fragments; #Apple Updates Everything; #WebEx Backdoor
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/5343.mp3
Interested in Internet Storm Center stickers? Check here if there are still some available for today.
Experimenting With IPv6 Fragments
https://isc.sans.edu/forums/diary/How+to+Have+Fun+With+IPv6+Fragments+and+Scapy/21963/
Apple Updates Everything
https://support.apple.com/en-us/HT201222
WebEx Secret Install URL
https://bugs.chromium.org/p/project-zero/issues/detail?id=1096
Vulnerability in Symantec Norton Download Manager
https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2017&suid=20170117_00
Exploit for Microsoft RDC Client on Mac
https://www.wearesegment.com/research/Microsoft-Remote-Desktop-Client-for-Mac-Remote-Code-Execution
https://isc.sans.edu/forums/diary/How+to+Have+Fun+With+IPv6+Fragments+and+Scapy/21963/
Apple Updates Everything
https://support.apple.com/en-us/HT201222
WebEx Secret Install URL
https://bugs.chromium.org/p/project-zero/issues/detail?id=1096
Vulnerability in Symantec Norton Download Manager
https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2017&suid=20170117_00
Exploit for Microsoft RDC Client on Mac
https://www.wearesegment.com/research/Microsoft-Remote-Desktop-Client-for-Mac-Remote-Code-Execution
Discussion
It was fixed after the podcast was recorded. When I recorded the podcast, version 1.0.3 had been released, which included an incomplete fix. I believe the latest version is not 1.0.5 which does fix the problem. (but then again, maybe they will update it again after I hit submit)
as far as other browsers go: there is a chance that they are vulnerable too, but Google only looked into the Chrome plugin.
as far as other browsers go: there is a chance that they are vulnerable too, but Google only looked into the Chrome plugin.
New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form
Also, is IE or Safari a problem? I would suspect it is, but would like to know if anyone has confirmed.