ISC StormCast for Monday, May 13th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 13 May 2019
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, May 13th, 2019 edition of the San Santernat Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich and I'm recording from San Diego, California. |
| 0:13.4 | If you are reading our Sansanet Storm Center diaries, you probably have noticed that DDA is really well known for creating |
| 0:23.3 | a ton of useful little tools, typically in Python. |
| 0:28.7 | If you want a collection of all of DDA's tools, nothing easier than that. |
| 0:33.8 | With the S-S suite, that's a Docker container that contains all of the DA's latest tools |
| 0:41.7 | pre-installed. |
| 0:43.0 | So great if you have to analyze documents and the like, that's what usually his tools are |
| 0:48.6 | really great at. |
| 0:52.2 | And the Cisco Talas research team has released details about a new vulnerability in the |
| 0:58.4 | SQLite 3 database. |
| 1:01.9 | This vulnerability does allow remote code execution. |
| 1:05.2 | It is a use after free vulnerability and certainly exploitable. |
| 1:09.6 | However, before you go out and panic and try to rush |
| 1:13.8 | out and update, consider that an attacker would have to actually send a custom, carefully crafted, |
| 1:22.3 | SQL command to the database. If you do allow users to execute arbitrary commands against the database, |
| 1:30.3 | well, that's usually already a user in a more trusted position. So being able to execute |
| 1:38.3 | code on the SQLite server may not really give them that much more access. So this is nothing that could easily be |
| 1:45.7 | exploited, for example, for a web application or something like that, unless you do allow for |
| 1:51.9 | SQL injection. A patch is available and you should certainly apply it, but no need to rush it. |
| 1:59.5 | So if you don't see an updated package for your particular |
| 2:02.5 | operating system, you can certainly wait a couple days. And talking about patches, NVIDIA |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

