Flash Poll
Latest Content
Prepared for a Cyberattack?
Flash Poll  |  3/11/2015  | 
Eyes On The Analytics Prize
Flash Poll  |  3/1/2015  | 
Analyze This?
Flash Poll  |  2/1/2015  | 
Monitor Management
Flash Poll  |  1/2/2015  | 
Action Speaks Louder…
Flash Poll  |  1/1/2015  | 
Reliable Sources
Flash Poll  |  12/1/2014  | 
Defending Against Malware
Flash Poll  |  11/10/2014  | 
Intelligence Hired Guns?
Flash Poll  |  11/1/2014  | 
Breach Security 101
Flash Poll  |  10/21/2014  | 
Death of the Perimeter
Flash Poll  |  10/21/2014  | 
See Something, Say Something
Flash Poll  |  10/1/2014  | 
Bashed & Shellshocked
Flash Poll  |  9/30/2014  | 
Hacking Humans
Flash Poll  |  9/5/2014  | 
Security of 'Things'
Flash Poll  |  8/21/2014  | 
Security Org Chart
Flash Poll  |  7/18/2014  | 
Risk Management Report Card
Flash Poll  |  6/16/2014  | 
Greatest Threat
Flash Poll  |  6/4/2014  | 
Lessons Learned
Flash Poll  |  6/1/2014  | 
Cyber Security Skills
Flash Poll  |  5/29/2014  | 
Cyberbreach or Cyberrisk Insurance
Flash Poll  |  5/20/2014  | 
State of IT Security
Flash Poll  |  5/5/2014  | 
Broken Heartbeat
Flash Poll  |  4/10/2014  | 
Windows XP
Flash Poll  |  4/2/2014  | 
Safety Equipment
Flash Poll  |  11/15/2013  | 


Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6501
Published: 2015-03-30
The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_s...

CVE-2014-9652
Published: 2015-03-30
The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote atta...

CVE-2014-9653
Published: 2015-03-30
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory ...

CVE-2014-9705
Published: 2015-03-30
Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of multiple dictionaries.

CVE-2014-9709
Published: 2015-03-30
The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.