Source: TheIntercept – Posted by Anthony Pell If the U.S. government tries to strong-arm American companies into ending the sale of products or applications with unbreakable encryption, the technology won�t disappear, a group of researchers conclude in a new report. It would still be widely available elsewhere. Some U.S. law enforcement officials argue that […]
Source: arsTechnica – Posted by Anthony Pell An estimated 63 percent of the encryption products available today are developed outside US borders, according to a new report that takes a firm stance against the kinds of mandated backdoors some federal officials have contended are crucial to ensuring national security. The report, prepared by security […]
Posted by Anthony Pell New upstream release: fixes CVE-2015-8476. ——————————————————————————– Fedora Update Notification FEDORA-2015-39522bb8c9 2016-02-11 09:49:16.132384 ——————————————————————————– Name : php-PHPMailer Product : Fedora 22 Version : 5.2.14 Release : 1.fc22 URL : http://phpmailer.worxware.com/ Summary : PHP email transport class with a lot of features Description : Full Featured Email Transfer Class for PHP. PHPMailer […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 22 php-PHPMailer-5.2.14-1.fc22 Fedora 23 firefox-44.0.1-2.fc23 Fedora 23 php-PHPMailer-5.2.14-1.fc23 Fedora 23 firebird-2.5.5.26952.0-1.fc23 Red Hat: 2016:0166-01: flash-plugin: Critical Advisory Fedora 23 gsi-openssh-7.1p2-3.fc23 Fedora 22 claws-mail-3.13.2-1.fc22 Red Hat: 2016:0157-01: python-django: Moderate Advisory […]
Posted by Anthony Pell New upstream release: fixes CVE-2015-8476. ——————————————————————————– Fedora Update Notification FEDORA-2015-abf9659276 2016-02-11 09:49:39.042856 ——————————————————————————– Name : php-PHPMailer Product : Fedora 23 Version : 5.2.14 Release : 1.fc23 URL : http://phpmailer.worxware.com/ Summary : PHP email transport class with a lot of features Description : Full Featured Email Transfer Class for PHP. PHPMailer […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 22 php-PHPMailer-5.2.14-1.fc22 Fedora 23 firefox-44.0.1-2.fc23 Fedora 23 php-PHPMailer-5.2.14-1.fc23 Fedora 23 firebird-2.5.5.26952.0-1.fc23 Red Hat: 2016:0166-01: flash-plugin: Critical Advisory Fedora 23 gsi-openssh-7.1p2-3.fc23 Fedora 22 claws-mail-3.13.2-1.fc22 Red Hat: 2016:0157-01: python-django: Moderate Advisory […]
Update from 3.13.1 to 3.13.2 for bug-fixes. Includes security fix forCVE-2015-8708. ——————————————————————————– Fedora Update Notification FEDORA-2016-b211281b8e 2016-02-10 10:19:50.055896 ——————————————————————————– Name : claws-mail Product : Fedora 22 Version : 3.13.2 Release : 1.fc22 URL : http://claws-mail.org Summary : Email client and news reader based on GTK+ Description : Claws Mail is an email client (and news […]
Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0157-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0157.html Issue date: 2016-02-10 CVE Names: CVE-2015-8213 […]
Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 7.0. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0156-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0156.html […]
Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 6. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0158-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0158.html Issue date: 2016-02-10 CVE Names: CVE-2015-8213 […]
Posted by Anthony Pell This update fixes for security vulnerabilities, including CVE-2016-0775,CVE-2016-0740. ——————————————————————————– Fedora Update Notification FEDORA-2016-4b06195979 2016-02-09 16:33:27.876837 ——————————————————————————– Name : python-pillow Product : Fedora 23 Version : 3.0.0 Release : 2.fc23 URL : http://python-pillow.github.io/ Summary : Python image processing library Description : Python image processing library, fork of the Python Imaging Library […]
Posted by Anthony Pell Several security issues were fixed in nginx. ========================================================================== Ubuntu Security Notice USN-2892-1 February 09, 2016 nginx vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: Several security issues were fixed in nginx. Software Description: – nginx: small, powerful, […]
Risk Medium Date Discovered February 9, 2016 Description Microsoft ASP.NET is prone to a cross-site request-forgery vulnerability. An attacker can exploit this issue to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks. Technologies Affected Microsoft ASP.NET MVC 5.0 Microsoft ASP.NET MVC 6.0 Microsoft […]
Risk High Date Discovered February 9, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]
Risk Medium Date Discovered February 9, 2016 Description Microsoft Internet Explorer is prone to an information-disclosure vulnerability. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks. Internet Explorer 9, 10, 11 are vulnerable. Technologies Affected Microsoft Internet Explorer 10 Microsoft Internet Explorer 11 Microsoft Internet Explorer 9 Recommendations Run […]
Risk Medium Date Discovered February 9, 2016 Description Microsoft Windows is prone to a local security-bypass vulnerability. A local attacker can leverage this issue to bypass certain security restrictions and perform unauthorized actions. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. Allow only trusted individuals to have […]
Risk Medium Date Discovered February 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. To exploit this vulnerability, an […]
Risk Medium Date Discovered February 9, 2016 Description Microsoft Windows is prone to a denial of service vulnerability. An attacker can exploit this issue to cause the system to stop responding, denying service to legitimate users. Recommendations Block external access at the network boundary, unless external parties require service. If global access isn’t needed, filter […]
Risk Medium Date Discovered February 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability. A local attacker can leverage this issue to execute arbitrary code with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. Ensure that only trusted users have local, interactive […]
Risk Medium Date Discovered February 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability. A local attacker can leverage this issue to execute arbitrary code with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. Ensure that only trusted users have local, interactive […]
Risk High Date Discovered February 9, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered February 9, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Source: ZDNet Security – Posted by Dave Wreski A new bill introduced by two congressmen aims to prevent local legislatures from enacting laws weakening security or banning sales of encrypted smartphones in their states. On Wednesday, Rep. Ted Lieu (D-CA, 33rd) introduced the bipartisan draft bill — dubbed the Ensuring National Constitutional Rights of […]
Source: arsTechnica – Posted by Anthony Pell Google has confirmed a number of changes to Gmail with the arrival of two new features that will let you know if the people you�re corresponding with aren�t hip with TLS encryption. The alterations are fairly subtle: when you receive a message from, or are on the […]
Source: tomsHardware – Posted by Dave Wreski After New York and California tried to pass bills that ban phones from using disk encryption that only the device owners can decrypt, senator John McCain wants to ban all encryption that can�t be decrypted by companies and the government at the federal level. McCain called for […]
Source: Motherboard – Posted by Anthony Pell A hacker, who wishes to remain anonymous, plans to dump the apparent names, job titles, email addresses and phone numbers of over 20,000 supposed Federal Bureau of Investigation (FBI) employees, as well as over 9,000 alleged Department of Homeland Security (DHS) employees, Motherboard has learned. The hacker […]
Type: Vulnerability. Microsoft Active Directory Federation Services is prone to a denial of service vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: New libsndfile packages are available for Slackware 13.37, 14.0, 14.1, and -current to fix security issues. [More Info…]
LinuxSecurity.com: New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. [More Info…]
LinuxSecurity.com: USN-2880-1 introduced a regression in Firefox.
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: Security Report Summary
Many of you are probably familiar with VirusTotal, a service that allows you to scan a file or URL using multiple antivirus and URL scanners. VirusTotal results are often used in write-ups about new malware to show how widely a sample is detected by the AV community. We receive links to VirusTotal results via our […]
In a 2016 survey of 500 PC gamers, Webroot discovered statistically significant differences in the ways that male and female gamers approach internet security, 3rd party modifications, and the way they choose to portray their gender online. In fact, we found surprisingly large discrepancies between those who identified as male and those who identified as […]
There is no such thing as a free lunch, and even if there was… who likes airline food that much anyway? The post Southwest Airlines flight giveaway scams spread on Facebook appeared first on We Live Security.
A new e-learning tool has been launched in the UK to help HR professionals effectively deal with cybersecurity issues in the British workplace. The post Cybersecurity e-learning course launches in the UK for HR staff appeared first on We Live Security.
Learn how to boost your Facebook privacy on Safer Internet Day with our excellent cheat sheet. It’ll work to your advantage now and in the future. The post Stay safe with our Facebook cheat sheet appeared first on We Live Security.
LinuxSecurity.com: Nearly three years after former NSA contractor Edward Snowden first leaked details about massive domestic spying, his revelations have prompted a broader discourse, especially among legal scholars, over the potentially invasive nature of big data cybersurveillance tools.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Outlook for Mac is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.
Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Office is prone to a privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
LinuxSecurity.com: An updated sos package that fixes one security issue and one bug is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…]
LinuxSecurity.com: Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0 for RHEL 7. Red Hat Product Security has rated this update as having Moderate security [More…]
LinuxSecurity.com: Update from 3.13.1 to 3.13.2 for bug-fixes. Includes security fix forCVE-2015-8708.
LinuxSecurity.com: – update to upstream release 1.8.1 – CVE-2016-0747: Insufficient limits ofCNAME resolution in resolver – CVE-2016-0746: Use-after-free during CNAMEresponse processing in resolver – CVE-2016-0742: Invalid pointer dereference inresolver
LinuxSecurity.com: Prosody 0.9.10 ============== A summary of changes in this release: Security——– * mod_dialback: Adopt key generation algorithm from XEP-0185, toprevent impersonation attacks (CVE-2016-0756) Fixes and improvements———————- * Startup: Open /dev/urandom read-only, to fix afailure to start on some systems (fixes #585) * Networking: Improve handling ofthe ‘select’ network backend running out of file descriptors […]
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: Security Report Summary
security update
security update
security update
security update
A 17-year-old student in American has been arrested and charged with illegally accessing government computers, months after the data breach took place. The post Student arrested for grade changing school data breach appeared first on We Live Security.
Almost a year ago we warned about the spreading of Remtasu, and far from lessening, we have been able to identify numerous instances of this threat being propagated further. The post Remtasu is disguising itself as a tool to appropriate Facebook accounts appeared first on We Live Security.
Highlights from the past seven days in information security include encryption insights, Android updates, Facebook at 12 and a data breach at UCF in the US. The post The security review: Encryption 101 and Android security updates appeared first on We Live Security.
