meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, November 23rd 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 23 November 2020

⏱️ 4 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. VMWare Update; DB2 Vuln; Fortinet SSL VPN

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, November 23rd, 2020 edition of the Sansanet Storm Center's Stormcast.

0:07.4

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.1

Here in the United States, this week, of course, is Thanksgiving week with that no podcast on Thursday and Friday and likely shorter podcast the other days

0:25.1

because it tends to be sort of a little bit slow newsweek.

0:30.4

And Thanksgiving 2000, so about 20 years ago, was actually the weekend where I wrote the first

0:36.4

version of De Hilton made it live the week after.

0:40.9

So to celebrate this, we'll do another Raspberry Pi giveaway this week.

0:47.1

What you'll have to do is go to the show notes page and there is a link to a quick survey.

0:52.8

Two questions and the third question is then your email address.

0:56.5

So if you would like to participate in the giveaway, just leave your email address.

1:03.5

And well, in security news, we have a VMware update to start out with.

1:09.8

It fixes a critical vulnerability in VMware ESXI and

1:15.8

Workstation as well as Fusion. This is approach escalation vulnerability that would

1:22.5

essentially allow an administrator of a virtual machine to run code on the host.

1:30.1

The vulnerable component here is the XHCI USB controller.

1:35.0

So for the ESXI folks who may have a harder time upgrading than some of the workstation

1:42.1

products, you have the option to just disable this USB controller,

1:49.0

which is probably not often really used.

1:53.3

And if you're one of the few organizations running IBM's DB2 database,

1:58.7

there is an update for you that fixes, first of all, DL hijacking vulnerability,

2:06.4

and then also a buffer overflow vulnerability that could be used by a local attacker to execute

2:14.8

code with root privileges, so it doesn't appear to be exploitable across the network,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.