meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, December 6th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 6 December 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. VLC Update Issues; AMI MegaRAC BMC Vuln; Netgear IPv6; Veritas NetBackup

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, December 6, 2020 edition of the Santernut Storms, Stormcast.

0:09.0

My name is Johannes Ulrich and today I'm recording from San Francisco, California.

0:15.0

I mentioned, I think it was late last week, maybe Friday, about the latest version of VideoLens, VLC, fixing some critical

0:23.6

vulnerability.

0:25.4

DDA looked into this closer and was surprised that he didn't sort of see the update available

0:31.8

pop up from within the application.

0:34.0

He checked it manually and well, it turned out that the feed that they're using,

0:40.1

we see a simple web service, did still advertise the older version.

0:45.7

Earlier today, VideoLan did actually fix this problem, so you should see that update

0:53.1

now being advertised straight from within the

0:56.3

application.

0:58.2

And then bad news for everybody running a server with a baseboard management controller from

1:05.2

AMI, which, well, sadly, is probably pretty much sort of everybody.

1:10.1

Eclipseum has a blog post with details regarding three different vulnerabilities that they

1:16.5

identified. The most critical one has a CVSS score of 9.9 and it is a fairly straightforward

1:25.4

sort of command injection vulnerability in the Redfish API.

1:30.0

Redfish is sort of the more modern IPMI replacement, more built around web standards,

1:36.7

and with that, of course, inherits some of the standard web application vulnerability

1:41.4

that I'm actually teaching about here in San Francisco this week.

1:46.6

Only constraint here is that the badge code that you are injecting as part of the URL has to be,

1:54.9

well, first of all, valid bash code, but also a valid URL component because nothing here can be

2:00.7

sort of URL encoded. Well, they have a little

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.