Alexander Izmailov discovered that didiwiki, a wiki implementation, failed to correctly validate user-supplied input, thus allowing a malicious user to access any part of the filesystem. For the oldstable distribution (wheezy), this problem has been fixed in version 0.5-11+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 0.5-11+deb8u1. For the testing […]
Stepan Golosunov discovered that xdelta3, a diff utility which works with binary files, is affected by a buffer overflow vulnerability within the main_get_appheader function, which may lead to the execution of arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 3.0.0.dfsg-1+deb7u1. For the stable distribution (jessie), this problem has been […]
Gustavo Grieco discovered an out-of-bounds write vulnerability in cpio, a tool for creating and extracting cpio archive files, leading to a denial of service (application crash). For the oldstable distribution (wheezy), this problem has been fixed in version 2.11+dfsg-0.1+deb7u2. For the stable distribution (jessie), this problem has been fixed in version 2.11+dfsg-4.1+deb8u1. For the unstable […]
A lot happens in the security world, some big and some small, and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Samsung Smart TV’s, Too Smart? Recently, it has come to […]
��}ے�8�������)QR�n�|�ryڳvۧ��{��T@”$��”i^J�v;b�a�6��}߈��?�/�L$A�RI*�/��� $yC”������:���=��s#�F���g�_=-b7Q�쁣�zu�c֘嫺t�zڵ�f�DJ�mE��Ů�!��:�];����C갞Yi�yc��1���”��@�����~ �� �:oZ/,��ѷ�٫�;��M��o�����UY��:�E#f4M�����A��Y��=i���n�iy!#��P�W�n�7��nG��>�Б�uC�z.Ș�oZM��h��ac�ө��>M��@�HR�� �s�v<�z�X̽@�//��=t���� ��]����%�G��gc1*���؏���&șl���d�QD�J�g1t̍R�v�'Vք����;}K{~<��`�-)����%�֖-�:�@�<�R՛R�]��K*���LnF#/����%4��= Rpv��NcQd����Gm@C�=�#��?5Bcfx��’M�Sc����Sc�u����5h ��;�!0|ȴ��t�/�B-‘�OHQ�:��-]�����p�;c ����s��-c_�����`��Vi}P�>&��U����4 ����Tf�gI���V�[��1fw�o�G��_U�ei��Eq�=����8���i�2��s@ ����ku(�!�%�C��8aFX�^�G�b�z�K86F�7=7�ijXuo���u�V=}n����z�V��F���^Wk���q4�Y�v��}��ޓ��z=�� 9�P�f�����52}��V;z`~Ji�V�T [�xh��G�Rq��UY/|>?��oA%�N���jP�g�u2��:�}�G�1B�}������=�a��a��D*�N��’@���7��y� �|<��3�ë^*8��j�&�K�1l���B����8 � �jY�����v�͂���wU Z����`I�����f�NKʢ��߁�P"��p�U5���s �����.����V���U��Y�V�}� [U��a�2R_b�jh�4�X�ęVq2oO�_����u��”�߳��w��S�d�8|�n�^`��&0�X�r�� h�}�0{��*�F�10��3g��”�[I�[�s� �h�4�� ��߶;���:3��`��ŀw�Ib�F��w�kOwPKP�v�v��Gyv��YlDc’J�ݡ�����k�g�*�U@�yL}���)���`vG�!z&�M��`(�ή��/����ϋ�(��n��Xk ��v�鈺�9h�����`n$���5���A����*�ac/��o)���(�Nv���� ���&Ϣ�ݡс�|P�P���n65��{�U�M�k���,��%8 GW�ZԿod0�C1 UϽ��-�x֜D����g=���l�X���:^p�p���S]O5xQ)�+’���2 4.�J4�2��i�J?�/|�v�=p�J��]�P��ܹ8�+�a8�g,@ɡQ�(��W”�Ժ��`|d4N�’��u����@憠�kL��Ƒ��@��ؒ�8�1�%ޅk}���l�&�Ț��VӉ�_j0�Kea�a��`��íU��E��(j�`�P�C�f|���oƂ�*���=�����F��o�|�b��|wvFZF��d�*0q�B�;�m!�����xl�| ��D�nDo&��r���h�T��*��SFj�4~ 9���#ɜ��+���{��ϵcQ���|k8���Fc� �A��Ԥ�� ]B�(�Y�h��4 �.��0>�W�D�k ^�2��x�( o���o��V ��~�Y�偙�s6�V�V�$�0Wh�G����pR}_���;�9��J�T�=�yx�nt�hV$q?ժ�!O�g��,��n�� m�4��w?�FR�?O�zbO�D�Iz���x�O �=M#�zZ���� “��PZ��=(�Q����Gt���ޙ0(���h�4 |�q�=,���h�0ޡ��+� �p���` a���K.�J!�z>eUX���3/$A�eD>6J�m�rR���ZW �oF���3�E�#����8�}�ʾ!s?��d@J7
An anonymous contributor working with VeriSign iDefense Labs discovered that libreoffice, a full-featured office productivity suite, did not correctly handle Lotus WordPro files. This would enable an attacker to crash the program, or execute arbitrary code, by supplying a specially crafted LWP file. For the oldstable distribution (wheezy), these problems have been fixed in version […]
Parts 1 and 2 of this series provided an overview of Threat Intelligence and hopefully offered some understanding as to what role it can play in helping secure an IoT infrastructure. For those familiar with cyber security and how to implement Threat Intelligence in traditional network appliances the jump to securing an IoT Gateway is […]
A new ransomware has been discovered and what sets apart this variant from the rest is its implementation of a chat interface embedded into the product. That link for “Live Chat” will prompt the window for live support. The window should look like this and will allow you to talk directly with the cyber criminal. […]
As 2015 slides into the cybersecurity history books as “the year of the healthcare breach” I decided to examine one aspect of medical data privacy that is sometimes overlooked: the impact of breaches on patient-doctor information exchange. Specifically, I’m concerned that high profile healthcare-related IT security breaches may lead more people to withhold sensitive information […]
Discovered: February 17, 2016 Updated: February 17, 2016 7:21:42 PM Type: Trojan Systems Affected: Windows 7, Windows Vista, Windows XP Backdoor.Cloworm is a Trojan horse that opens a back door on the compromised computer. It may also download potentially malicious files. Antivirus Protection Dates Initial Rapid Release version February 17, 2016 revision 033 Latest Rapid […]
Imagine your friend’s house is broken into over and over. Each time the intruder gains entry by smashing a window. In response, your friend notices that his door locks aren’t Bluetooth-enabled or biometric, so he buys intelligent door locks for his house. He is surprised, over and over, that no matter how much he upgrades […]
Despite warnings from people like me, unpatched software is the top reason computers get exploited. People aren’t too dumb or lazy to install patches. They want to do the right thing. But patching can be difficult for a multitude of reasons, and those roadblocks explain why patching is performed so poorly in most organizations. Let’s walk […]
Because I’m a computer security guy, I have friends who like to show off their new RFID-blocking wallets and purses. “Look what I got for Christmas!” they say. My lack of response should be telling, but they don’t seem to pick up on it. They’ve seen the TV ads about malicious hackers who can “stand […]
As I landed in Dallas returning from my recent visit to China, I picked up my cellphone voicemails. One of them was from my bank, telling me my personal debit card was frozen and would have to be unlocked. I knew I should’ve let my bank and credit card companies know I was traveling, but […]
I’ve written a few times about the pending mini-Y2K issue that is SHA-1 deprecation. In a nutshell, all digital certificates are signed by a hashing algorithm — and SHA-1 is the signature type used by almost everyone. But SHA-1 has significant cryptographic weaknesses, which is why the crypto world has recommended for years that digital […]
You can call me a pundit, I guess, but I don’t like making predictions. Most industry forecasts are horribly inaccurate and miss the stuff people will care about a year later. For me, it’s hard enough to digest what happened in the past and make sense of it, but this was a landmark year. Here […]
Security boundaries in the IT world are changing, porous, often imaginary lines. A security boundary is a demarcation that delineates sovereign or administrative borders that dictate who controls what. Boundary owners are supposed to protect the assets inside their domains against all other unauthorized incursions. Security boundaries are important. Nearly every war is fought over […]
A hospital in the US is still unable to fully access its computer system, over a week after cybercriminals launched a ransomware attack. It has been reported that the individual(s) behind the attack at the Hollywood Presbyterian Medical Center, which is based in Los Angeles, California, have demanded 9,000 bitcoins (approximately $3.6 million) in return […]
From an outbreak of malicious spyware to the UK’s bill on investigatory powers, here’s our comprehensive breakdown of cybersecurity news from the past week. Remtasu is disguised in Facebook hacking tool ESET’s Camilo Gutierrez Amaya reported how Remtasu, a well-known piece of spyware, which first surfaced almost four years ago, is now appearing in disguise […]
Online dating has transformed from being a modest, underused and ‘hush hush’ concept – with a pinch of embarrassment – to a mainstream, popular and transformative entity. As a Pew Research Center survey from 2013 revealed, it has “lost much of its stigma”. Looking for love in the 21st century? It’s possibly a click and […]
The UK government should make ‘malicious data breaches’ a criminal offence, according to a new report from the Science and Technology Committee. Its paper, titled The Big Data Dilemma, argues that fines alone are not enough of a punishment. Further, the committee highlighted its concern over big data techniques that can “re-identify” individuals “from previously […]
In recent years, the ESET Latin America Investigation Laboratory has witnessed a growth in malware developed using scripting languages. This is why we now want to demonstrate how to configure a dynamic analysis environment to isolate such threats so we can understand and observe their behavior in a controlled environment. What do we mean by […]
Several vulnerabilities have been fixed in the GNU C Library, glibc. The first vulnerability listed below is considered to have critical impact. CVE-2015-7547 The Google Security Team and Red Hat discovered that the glibc host name resolver function, getaddrinfo, when processing AF_UNSPEC queries (for dual A/AAAA lookups), could mismanage its internal buffers, leading to a […]
Several vulnerabilities have been fixed in the GNU C Library, eglibc. The CVE-2015-7547 vulnerability listed below is considered to have critical impact. CVE-2014-8121 Robin Hack discovered that the nss_files database did not correctly implement enumeration interleaved with name-based or ID-based lookups. This could cause the enumeration enter an endless loop, leading to a denial of […]
Holger Fuhrmannek discovered that missing input sanitising in the Graphite font rendering engine could result in the execution of arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 38.6.1esr-1~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 38.6.1esr-1~deb8u1. For the unstable distribution (sid), this problem has […]
Several vulnerabilities have been found in PostgreSQL-9.4, a SQL database system. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. Certain custom configuration settings (GUCs) for PL/Java will now be modifiable only by the database superuser to mitigate this issue. CVE-2016-0773 Tom Lane and Greg Stark discovered a flaw in the way PostgreSQL […]
Several vulnerabilities have been found in PostgreSQL-9.1, a SQL database system. CVE-2015-5288 Josh Kupershmidt discovered a vulnerability in the crypt() function in the pgCrypto extension. Certain invalid salt arguments can cause the server to crash or to disclose a few bytes of server memory. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. […]
Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered that the ECDH secret decryption keys in applications using the libgcrypt20 library could be leaked via a side-channel attack. See https://www.cs.tau.ac.IL/~tromer/ecdh/ for details. For the stable distribution (jessie), this problem has been fixed in version 1.6.3-2+deb8u1. For the unstable distribution (sid), this problem has been […]
Several vulnerabilities were discovered in the resolver in nginx, a small, powerful, scalable web/proxy server, leading to denial of service or, potentially, to arbitrary code execution. These only affect nginx if the resolver directive is used in a configuration file. For the oldstable distribution (wheezy), these problems have been fixed in version 1.2.1-2.2+wheezy4. For the […]
Two vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2221 Shailesh Suthar discovered an open redirection vulnerability. CVE-2016-2222 Ronni Skansing discovered a server-side request forgery (SSRF) vulnerability. For the oldstable distribution (wheezy), these problems have been fixed in version 3.6.1+dfsg-1~deb7u10. For the stable distribution […]
Several vulnerabilities were discovered in qemu, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service, that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. discovered that the […]
Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service (via resource exhaustion), that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. […]
Discovered: February 15, 2016 Updated: February 16, 2016 3:26:08 PM Type: Trojan Infection Length: 229,645 bytes Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Redsip is a Trojan horse that opens a back door on the compromised computer. It […]
Discovered: February 15, 2016 Updated: February 15, 2016 5:40:48 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Contopee is a Trojan horse that opens a back door on the compromised computer. It may […]
Discovered: February 12, 2016 Updated: February 12, 2016 7:53:04 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Fimlis is a Trojan horse that opens a back door on the compromised computer and downloads potentially malicious files. […]
