If you’ve ever been infected with serious malware, you may have assumed the culprit is a person sitting in the basement of their mom’s house, or a small group of people huddled in a garage somewhere. It’s really not that simple. There’s a whole global cyber underground network that’s working diligently to make all this happen […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3538-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 31, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libebml CVE ID : CVE-2015-8789 CVE-2015-8790 CVE-2015-8791 Several vulnerabilities were discovered in libebml, a library for manipulating Extensible Binary Meta Language files. CVE-2015-8789 Context-dependent attackers could trigger a use-after-free vulnerability by providing a maliciously […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3537-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 31, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imlib2 CVE ID : CVE-2014-9762 CVE-2014-9763 CVE-2014-9764 Several vulnerabilities were discovered in imlib2, an image manipulation library. CVE-2014-9762 A segmentation fault could occur when opening GIFs without a colormap. CVE-2014-9763 Several divisions by zero, […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3536-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 31, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libstruts1.2-java CVE ID : CVE-2015-0899 It was discovered that libstruts1.2-java, a Java framework for MVC applications, contains a bug in its multi-page validation code. This allows input validation to be bypassed, even if MPV […]
Security fix for CVE-2016-2315, CVE-2016-2324 (by updating to 2.4.11). ——————————————————————————– Fedora Update Notification FEDORA-2016-cee7647200 2016-03-30 17:30:15.403378 ——————————————————————————– Name : git Product : Fedora 22 Version : 2.4.11 Release : 1.fc22 URL : http://git-scm.com/ Summary : Fast Version Control System Description : Git is a fast, scalable, distributed revision control system with an unusually rich command […]
Multiple CVEs ——————————————————————————– Fedora Update Notification FEDORA-2016-b91d895e5a 2016-03-30 17:30:15.402965 ——————————————————————————– Name : moodle Product : Fedora 22 Version : 2.8.11 Release : 1.fc22 URL : http://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) – a free, Open Source software package designed using sound pedagogical principles, to help […]
An update for openvswitch is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openvswitch security update Advisory ID: RHSA-2016:0537-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: […]
Multiple CVEs ——————————————————————————– Fedora Update Notification FEDORA-2016-403715aaec 2016-03-30 17:35:06.232672 ——————————————————————————– Name : moodle Product : Fedora 23 Version : 2.9.5 Release : 1.fc23 URL : http://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) – a free, Open Source software package designed using sound pedagogical principles, to help […]
��}ے�F���(A�”i�o���Z�X�H����Y�E� ƥٴ���}ٍ8’b�6b7b��?�/�̬��l6%�Ҍ%����������z|��wǧ{�}{���ૻ�’��e�����N4�|��51>d�(�[-1�)oy�} ��y<�=�O���)�L*��c粯/�^���}�1K��k��Z��51��G�8�k ������f��,��/���|UϜ�v��/�(Sz��Ѥo�K��:�h2�s"�t��2]��TA1v�:�/y�^�ٰk^���`���=�u�m����r��|������{ջ�ja^��c�7ڝ����݃�;{{���N�v�����gO;= ��?�u�p�������s @�Wd��PcSn;f_�ǃ�辦�x6�3�:�z���! ��%������8~a�N’���!r�1�M���r<�9w���;{�v���=�%h}AMp�nz�눖�zJ��"��ќԁ+PV2���j���Q^�� r,�/-��)~+~X���%�t%�L~c�@!?C�ˠDy���Ie]���naP㿲�]��}�%���s�GF���6�T���O��Z�13D0��E$ jY”�?���O����~��Ԡ)�f��~��Q�?h����tj5!BJ����-���*�0��S��y�����5���[�F�Gڰn6�M��!�����pi�� �2�Q�Eu��:Z�i�-c�#2�����Z��G���=x`#�uO�ӓ�m`�g�X Hs�kM( p��d��Ş��Mm�c���X1R?���@L���?6����v�{�n3}n�7��f�Ѵ�H<����W��roM=�k�wa�v��~����F���^���4��w�����ǔ�|M�5�,#����V�cs���z��9~"Q�p��5�U��}���ǵ�V�#�8j�r��j%���a��az��D*��v�# �����y�^~�xl�.j�~�8�قm��4cH���+����q@v�m���.�rBl<����5hY-_���7�uM��,��FJ�D0�BuMx�s��!���֒��fyV�$(Z�С�� ��n��2��HI����###�Ox=�q82��y�`dD3�X�r�W��?T�F��.uU�V�<�����$[ H �*����u�c���S���&�$@���;��9?�9%�݃�q6��E`��f��(}��É hU}�p��Y�O�h9]�&|�燬͌�~�#(�6:�~�PHo%8���B��Xטc�kտ�}ư��u,����2���)�,X ] �p�P��,�V�10����&���oM��k�5�Z�’��?ow���uf���#�ȋnד�Lȭ”��a�9�B’�%i�h�*��óm̕���#3v���-2�����y����Vb�* ھ �>���4�#0�#���ɖp�%���>( ��md��T�ݑq(DF��o;� iŰ5LG�g�A귇���1�FX� R�1v�o���è`��E0�ފ���Q�0lO� ,�����g���P�̡�}�PW��v:u�z�(�,#w�=�s=��^��4t%�@��Ƣn;�6��̽���^�=gQ�”�C�:X����+����.�/kzf���j��p1y=-�A�m����U��z�F�J�ɸ8�������;PrhTo��p�+acӾ��a~�f`M�&��u���@ֆ �oM��̌#��@��ؒ�8�sO:b��w�>���a�’�Ȇ��Ӆ���K6Ua�~�5`�?��O�<���EQk~��RşT�7���.��nvL7�g��S���}Wm���0|x5u�:`˾M��� �m� �vaG�*4��ax�a�a�� w�U�νȼJ��{�q$�8#V��o ��#), m4�ч��r�)US��cT�0�+Ԋ��翀���Z�L�]����0���}#ln���J���ױ�&�gh�G���q8����r��s�ݗv��j���A�ѣ^�`�ޣ�”��F]>�i_�w�e�V�̲.�ٖ�]kx��j$eq�� ��33�&�k�ɠ|��k#��k�{})D��Pi�tx���� �i��̩�/�oĉT����hQ�>�<���sI��w��� ���ۆQjBabL���btN,Q��b���B��/�:k0�w�B T���5�� 78�*�X[��}�{�j4������!t��5z�ܗ����T�(�E� tk��s���9��G���� �J������C�=-g���Qrݦ|��Y[�U��/侠@�� �i_��7�2A@ɟl�@�4��*�)�S�B�p��է����)�z�+��B��Rb����G�PGb*B�R�Aq�1� �hyA�+%5��5K1��ak�Ij/D�v5�9��� �{�����+?�X�ת��(�&�v�%�8�x�,�fܚ���j��J`�Ki��Wn�G�L���O�M���-Z��0��qJ9F�f��0�zRܩ��6����l���9X���|���rSН�G�v�w�s�G���|���2������Ϫ4�Bd1��Ѫՙ���q|’Zn���IM��K�_0��8ňf�& Z�!(�56�W03���!9�K�s���` M� �@��-k3�W��0��’w�� ���i�~`&ٙ� ��Z��c��a�O�$F�d�����ႁ��0�F�]��L�a� QJ���P���U1S�f�)��S�?n!i٩�2Ճ���-��Nyc^jl��C+3��C���?��U�&Q�p�l,��W19���`�O�s���>,��l�1|�M�^8Ski$/���BP�ɫ’���8����[�� p�dL�}��[����2��C�_���U�v.��K�@���{*i��/�)��M`9�:�B��k��-I~5=���VO�˿�YS��ʒ:Y��L�/�d��/��J��lXhP��R�2��b�”�h�K`p�4�N�<'�IE�G�eע���}��N߲�w��n�a$�o��Ê����yF?q*g�hէ����ފ0 �ۣ�UpR!]D�-w������J�d�������C'��R�C�̈��'�N�$�3bԚ <�&+6���[a[�ںM��Wu�OI�l����R����������p����[f �S��N��MFp,sz?1b�j�ל�8�k�-b� ��*$d����u%�����X�_*�n�x�”���Ւ-��X�-�q�**�X���8��,v��?W��4}�#�������čJh���8gw햜M�mu:i-�Ld�]����|���O}�����?�;ӷ�|��M��* 8�}7)NQj��@�����(E��M�>}�O���x 0�+?����Za�]C�^J���TD-,ؙ�V_��wY8MС���Z.h�����t�̕��ܒ��U��r�~^�� �6c�u�h�V�� […]
Several vulnerabilities were discovered in libebml, a library for manipulating Extensible Binary Meta Language files. CVE-2015-8789 Context-dependent attackers could trigger a use-after-free vulnerability by providing a maliciously crafted EBML document. CVE-2015-8790 Context-dependent attackers could obtain sensitive information from the process’ heap memory by using a maliciously crafted UTF-8 string. CVE-2015-8791 Context-dependent attackers could obtain sensitive […]
Several vulnerabilities were discovered in imlib2, an image manipulation library. CVE-2014-9762 A segmentation fault could occur when opening GIFs without a colormap. CVE-2014-9763 Several divisions by zero, resulting in a program crash, could occur when handling PNM files. CVE-2014-9764 A segmentation fault could occur when opening GIFs with feh. For the oldstable distribution (wheezy), these […]
It was discovered that libstruts1.2-java, a Java framework for MVC applications, contains a bug in its multi-page validation code. This allows input validation to be bypassed, even if MPV is not used directly. For the oldstable distribution (wheezy), this problem has been fixed in version 1.2.9-5+deb7u2. We recommend that you upgrade your libstruts1.2-java packages.
Stelios Tsampas discovered a buffer overflow in the Kamailio SIP proxy which might result in the execution of arbitrary code. For the stable distribution (jessie), this problem has been fixed in version 4.2.0-2+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 4.3.4-2. For the unstable distribution (sid), this problem has been […]
Posted by Anthony Pell An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:0525-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0525.html […]
An update for openvswitch is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openvswitch security update Advisory ID: RHSA-2016:0524-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: […]
An update for openvswitch is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openvswitch security update Advisory ID: RHSA-2016:0523-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3535-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : kamailio CVE ID : CVE-2016-2385 Stelios Tsampas discovered a buffer overflow in the Kamailio SIP proxy which might result in the execution of arbitrary code. For the stable distribution (jessie), this problem has been […]
This update provides recent upstrem fix published with openssh-7.2p2 (#1316529). ——————————————————————————– Fedora Update Notification FEDORA-2016-d339d610c1 2016-03-29 15:13:21.929232 ——————————————————————————– Name : openssh Product : Fedora 22 Version : 6.9p1 Release : 11.fc22 URL : http://www.openssh.com/portable.html Summary : An open source implementation of SSH protocol versions 1 and 2 Description : SSH (Secure SHell) is a program […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Red Hat: 2016:0525-01: chromium-browser: Important Advisory Red Hat: 2016:0524-01: openvswitch: Important Advisory Red Hat: 2016:0523-01: openvswitch: Important Advisory Debian: 3535-1: kamailio: Summary Fedora 22 openssh-6.9p1-11.fc22 Fedora 22 webkitgtk-2.4.10-1.fc22 Debian: 3534-1: […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3534-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : dhcpcd CVE ID : CVE-2012-6698 CVE-2012-6699 CVE-2012-6700 Guido Vranken discovered several vulnerabilities in dhcpcd, a DHCP client, which may result in denial of service. For the oldstable distribution (wheezy), these problems have been fixed […]
PCRE could be made to crash or run programs if it processed aspecially-crafted regular expression. ========================================================================== Ubuntu Security Notice USN-2943-1 March 29, 2016 pcre3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: PCRE could be made to crash […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3533-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openvswitch CVE ID : CVE-2016-2074 Kashyap Thimmaraju and Bhargava Shastry discovered a remotely triggerable buffer overflow vulnerability in openvswitch, a production quality, multilayer virtual switch implementation. Specially crafted MPLS packets could overflow the buffer […]
Discovered: March 30, 2016 Updated: March 30, 2016 10:56:21 AM Type: Trojan Infection Length: 32,743 bytes Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Annieco is a Trojan horse that steals information from the compromised computer. Antivirus Protection Dates […]
Trojan.Ransomcrypt.AG is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt them. For more information on ransomware threats, please see the following resource: The dawn of ransomwear: How ransomware could move to wearable devices
Risk Medium Date Discovered August 12, 2008 Description Microsoft Windows Messenger is prone to an information-disclosure vulnerability. An attacker can exploit this issue by enticing an unsuspecting victim to visit a malicious HTML page. Successfully exploiting this issue allows remote attackers to obtain sensitive information that may aid in further attacks. Technologies Affected Microsoft Windows […]
Risk High Date Discovered June 17, 2008 Description Microsoft Word is prone to a remote memory-corruption vulnerability. An attacker could exploit this issue by enticing a victim to open and interact with malicious Word files. Successfully exploiting this issue will corrupt memory and crash the application. Given the nature of this issue, attackers may also […]
APPLE-SA-2016-03-28-1 OS X: Flash Player plug-in blocked Subject: APPLE-SA-2016-03-28-1 OS X: Flash Player plug-in blocked From: Apple Product Security <email@hidden> Date: Mon, 28 Mar 2016 13:20:04 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-28-1 OS X: Flash Player plug-in blocked Due to security issues in older versions, Apple has updated the web plug-in blocking mechanism […]
I love honeypots. I’ve even written a book about them. Any time you set up a fake system that nothing and no one should try to connect to, you cull invaluable information that any security defender will find useful. I’m still surprised that honeypots aren’t part of every organization’s security strategy. My guess is that’s […]
Guido Vranken discovered several vulnerabilities in dhcpcd, a DHCP client, which may result in denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 1:3.2.3-11+deb7u1. We recommend that you upgrade your dhcpcd packages.
Kashyap Thimmaraju and Bhargava Shastry discovered a remotely triggerable buffer overflow vulnerability in openvswitch, a production quality, multilayer virtual switch implementation. Specially crafted MPLS packets could overflow the buffer reserved for MPLS labels in an OVS internal data structure. A remote attacker can take advantage of this flaw to cause a denial of service, or […]
Discovered: March 29, 2016 Updated: March 29, 2016 1:49:56 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Cryptolocker.AJ is a Trojan horse that encrypts files on the compromised computer. Symantec Security Response is […]
Risk High Date Discovered February 5, 2015 Description Adobe Flash Player is prone to multiple unspecified security vulnerabilities. Attackers can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed attacks may cause denial-of-service conditions. Recommendations Run all software as a nonprivileged user with minimal access rights. […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3532-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 27, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : quagga CVE ID : CVE-2016-2342 Debian Bug : 819179 Kostya Kortchinsky discovered a stack-based buffer overflow vulnerability in the VPNv4 NLRI parser in bgpd in quagga, a BGP/OSPF/RIP routing daemon. A remote attacker can […]
Posted by Anthony Pell **Version 2.5.6** * Fix php-bug php#71719: Buffer overflow in HTTP url parsingfunctions (Mike, rc0r) * Fix gh-issue #28: Possible null pointer dereference inphp_http_url_mod() (rc0r) * Fix gh-issue #22: Fix PHP5 config.w32 (Jan Ehrhardt)* Fix gh-issue #20: setSslOptions notice with curl 7.43 (Mike, Vitaliy Demidov) ——————————————————————————– Fedora Update Notification FEDORA-2016-9d6b6d0689 2016-03-27 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]
Posted by Anthony Pell ### 6.x-2.7 Fixes [Embedded Media Field – Moderately Critical – Access Bypass -DRUPAL-SA-CONTRIB-2016-004](https://www.drupal.org/node/2666446) #### Changessince 6.x-2.6: * by dalin: Ensure that width and height are always numbers. *#1868588 by tangent: URL detection regex does not match hyphens / breaks HTMLmarkup ——————————————————————————– Fedora Update Notification FEDORA-2016-f0bb0dad51 2016-03-27 00:00:51.401145 ——————————————————————————– Name : […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]
This update provides recent upstrem fix published with openssh-7.2p2 (#1316529). ——————————————————————————– Fedora Update Notification FEDORA-2016-0bcab055a7 2016-03-27 00:00:51.399587 ——————————————————————————– Name : openssh Product : Fedora 24 Version : 7.2p2 Release : 1.fc24 URL : http://www.openssh.com/portable.html Summary : An open source implementation of SSH protocol versions 1 and 2 Description : SSH (Secure SHell) is a program […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]
Posted by Anthony Pell Cumulative maintenance release from upstream. Highlights are: * SSH RSAhostkeys smaller than 2048 bits now work properly. * MLSD response lines are nowproperly CRLF terminated. * Fixed selection of DH groups from TLSDHParamFile(CVE-2016-3125) Various other bug fixes are also included. ——————————————————————————– Fedora Update Notification FEDORA-2016-ac3587be9a 2016-03-27 00:00:51.398858 ——————————————————————————– Name : […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]
Discovered: March 26, 2016 Updated: March 28, 2016 2:05:38 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.AF is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt them. For […]
Kostya Kortchinsky discovered a stack-based buffer overflow vulnerability in the VPNv4 NLRI parser in bgpd in quagga, a BGP/OSPF/RIP routing daemon. A remote attacker can exploit this flaw to cause a denial of service (daemon crash), or potentially, execution of arbitrary code, if bgpd is configured with BGP peers enabled for VPNv4. For the oldstable […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1646 Wen Xu discovered an out-of-bounds read issue in the v8 library. CVE-2016-1647 A use-after-free issue was discovered. CVE-2016-1648 A use-after-free issue was discovered in the handling of extensions. CVE-2016-1649 lokihardt discovered a buffer overflow issue in the Almost Native Graphics Layer Engine (ANGLE) library. […]
Multiple security vulnerabilities have been fixed in the Tomcat servlet and JSP engine, which may result on bypass of security manager restrictions, information disclosure, denial of service or session fixation. For the oldstable distribution (wheezy), these problems have been fixed in version 6.0.45+dfsg-1~deb7u1. We recommend that you upgrade your tomcat6 packages.
Posted by Anthony Pell **Version 2.5.6** * Fix php-bug php#71719: Buffer overflow in HTTP url parsingfunctions (Mike, rc0r) * Fix gh-issue #28: Possible null pointer dereference inphp_http_url_mod() (rc0r) * Fix gh-issue #22: Fix PHP5 config.w32 (Jan Ehrhardt)* Fix gh-issue #20: setSslOptions notice with curl 7.43 (Mike, Vitaliy Demidov) ——————————————————————————– Fedora Update Notification FEDORA-2016-474c1d8264 2016-03-25 […]
Fix signature verification bypass attack, reported by Jann Horn ——————————————————————————– Fedora Update Notification FEDORA-2016-b98995ae24 2016-03-25 01:07:07.545267 ——————————————————————————– Name : torbrowser-launcher Product : Fedora 23 Version : 0.2.4 Release : 1.fc23 URL : https://github.com/micahflee/torbrowser-launcher Summary : Tor Browser Bundle managing tool Description : Tor Browser Launcher is intended to make Tor Browser easier to install and […]
OpenJDK could be made to crash or run programs as your login if it receivedspecially crafted input. ========================================================================== Ubuntu Security Notice USN-2942-1 March 24, 2016 openjdk-7 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: OpenJDK could be made to crash or run […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 php-pecl-http-2.5.6-1.fc23 Fedora 23 torbrowser-launcher-0.2.4-1.fc23 Ubuntu: 2942-1: OpenJDK 7 vulnerability Red Hat: 2016:0516-01: java-1.8.0-oracle: Critical Advisory Red Hat: 2016:0513-01: java-1.8.0-openjdk: Critical Advisory Red Hat: 2016:0515-01: java-1.7.0-oracle: Critical Advisory Red […]
Posted by Anthony Pell An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-openjdk security update Advisory ID: RHSA-2016:0513-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0513.html Issue date: […]
Posted by Anthony Pell An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-oracle security update Advisory ID: RHSA-2016:0515-01 Product: Oracle Java […]
Posted by Anthony Pell An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: java-1.7.0-openjdk security update Advisory ID: RHSA-2016:0512-01 Product: Red Hat Enterprise […]
Posted by Anthony Pell An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: java-1.8.0-openjdk security update Advisory ID: RHSA-2016:0514-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0514.html Issue date: […]
Posted by Anthony Pell An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-openjdk security update Advisory ID: RHSA-2016:0511-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0511.html Issue date: […]
Quagga could be made to crash or run programs if it received speciallycrafted network traffic. ========================================================================== Ubuntu Security Notice USN-2941-1 March 24, 2016 quagga vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Quagga could be made to crash […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3527-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 24, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : inspircd CVE ID : CVE-2015-8702 It was discovered that inspircd, an IRC daemon, incorrectly handled PTR lookups of connecting users. This flaw allowed a remote attacker to crash the application by setting up malformed […]
An update for python-django is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0505-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: […]
