Menu

Monthly Archives: March 2016

New ransomware abuses Windows PowerShell, Word document macros
The Badlock bug: Start your patch prep today

A lot happens in the security world and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Microsoft Addresses Macro Malware Issue With macros being a major vulnerability point in Microsoft Office […]

10 big announcements from Google’s Cloud Conference
Why IT can’t handle data breaches alone
Bruce Schneier on the Integration of Privacy and Security
Only 0.1% of you are doing web server security right
Verizon’s breach experts missed one right under their noses
Apple vs. FBI is over, but the encryption battle rages on
Microsoft’s ‘Tay and You’ AI bot went completely Nazi

Multiple vulnerabilities have been found in Redmine, a project management web application, which may result in information disclosure. For the stable distribution (jessie), these problems have been fixed in version 3.0~20140825-8~deb8u2. For the testing distribution (stretch), these problems have been fixed in version 3.2.0-1. For the unstable distribution (sid), these problems have been fixed in […]

Stefan Sperling discovered that pidgin-otr, a Pidgin plugin implementing Off-The-Record messaging, contained a use-after-free bug. This could be used by a malicious remote user to intentionally crash the application, thus causing a denial-of-service. For the stable distribution (jessie), this problem has been fixed in version 4.0.1-1+deb8u1. For the testing (stretch) and unstable (sid) distributions, this […]

It was discovered that libmatroska, an extensible open standard audio/video container format, incorrectly processed EBML lacing. By providing maliciously crafted input, an attacker could use this flaw to force some leakage of information located in the process heap memory. For the oldstable distribution (wheezy), this problem has been fixed in version 1.3.0-2+deb7u1. For the stable […]

Expert Palestinian Hacker Indicted for Hacking Israeli Drones
U.S. government accuses 7 Iranians of hacking banks, New York dam
Emergency Java update fixes two-year-old flaw after researchers bypass old patch
USB Trojan hides in portable applications, targets air-gapped systems
Rise in malicious domains portends rise in attacks

Discovered: March 23, 2016 Updated: March 24, 2016 3:19:59 PM Also Known As: RANSOM_MAKTUB.A [Trend] Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Cryptolocker.AI is a Trojan horse that encrypts files on the compromised […]

Pakistan-Linked Hackers Conduct Third Cyber-Espionage Campaign Against India
FBI Adds Syrian Electronic Army Hackers in Cyber’s Most Wanted List
To stop the hackers, security teams need to share more data on attacks
Paris terrorists used burner phones, not encryption, to evade detection
How to make Android a real part of your business

It was discovered that inspircd, an IRC daemon, incorrectly handled PTR lookups of connecting users. This flaw allowed a remote attacker to crash the application by setting up malformed DNS records, thus causing a denial-of-service, For the oldstable distribution (wheezy), this problem has been fixed in version 2.0.5-1+deb7u2. For the stable distribution (jessie), this problem […]

DOJ knew of possible iPhone-cracking method before Apple case
Artificial Intelligence Robot claims it will destroy human race

Vincent LE GARREC discovered an integer overflow in pixman, a pixel-manipulation library for X and cairo. A remote attacker can exploit this flaw to cause an application using the pixman library to crash, or potentially, to execute arbitrary code with the privileges of the user running the application. For the oldstable distribution (wheezy), this problem […]

ISPs have built huge data systems to track us with, report says

Updated nss-util packages that fix one security issue are now available for Red Hat Enterprise Linux 6.2, 6.4, and 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 and 7.1 Extended Update Support. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: nss-util security update Advisory ID: RHSA-2016:0495-01 Product: Red Hat Enterprise Linux Advisory URL: […]

Posted by Anthony Pell    Updated krb5 packages that fix two security issues are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: krb5 security update Advisory ID: RHSA-2016:0493-01 Product: Red Hat Enterprise Linux Advisory URL: […]

Posted by Anthony Pell    Updated tomcat6 packages that fix one security issue and one bug are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: tomcat6 security and bug fix update Advisory ID: RHSA-2016:0492-01 Product: […]

Posted by Anthony Pell    An updated foomatic package that fixes three security issues is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: foomatic security update Advisory ID: RHSA-2016:0491-01 Product: Red Hat Enterprise Linux Advisory […]

Updated kernel packages that fix one security issue, several bugs, and add one enhancement are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:0494-01 Product: Red […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0495-01: nss-util: Critical Advisory Red Hat: 2016:0493-01: krb5: Moderate Advisory Red Hat: 2016:0492-01: tomcat6: Moderate Advisory Red Hat: 2016:0491-01: foomatic: Moderate Advisory Red Hat: 2016:0494-01: kernel: Moderate Advisory […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0495-01: nss-util: Critical Advisory Red Hat: 2016:0493-01: krb5: Moderate Advisory Red Hat: 2016:0492-01: tomcat6: Moderate Advisory Red Hat: 2016:0491-01: foomatic: Moderate Advisory Red Hat: 2016:0494-01: kernel: Moderate Advisory […]

CVE-2016-3119, NULL dereference in LDAP module. —- Fix an issue with returncodes on `gss_inquire_attrs_for_mech`. This resolves an issue with gss-ntlmssp,and anything else that is interposing but not implementing the correspondingmechglue function. ——————————————————————————– Fedora Update Notification FEDORA-2016-56840babc3 2016-03-22 15:54:44.506003 ——————————————————————————– Name : krb5 Product : Fedora 23 Version : 1.14.1 Release : 3.fc23 URL : http://web.mit.edu/kerberos/www/ […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3525-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 22, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : pixman CVE ID : CVE-2014-9766 Vincent LE GARREC discovered an integer overflow in pixman, a pixel-manipulation library for X and cairo. A remote attacker can exploit this flaw to cause an application using the […]

FBI could ‘bypass’ Apple to unlock San Bernardino iPhone

The FBI has said it may no longer need Apple’s assistance in opening the locked iPhone belonging to an attacker in December’s San Bernardino, California shooting. As reported by the BBC, a court hearing with Apple scheduled for today (March 22nd) has been postponed at the request of the US Department of Justice, after federal […]

Microsoft adds macros lockdown feature in Office 2016 in response to increasing attacks
A Government Error Just Revealed Snowden Was the Target in the Lavabit Case
Pwn2Own Day Two: Safari, Edge Go Down And Winner Crowned
Google’s reverse engineering software BinDiff now free for researchers
Ransomware targets Flash and Silverlight vulnerabilities
Hackers Target NASA with DDoS Attack, Claim to Shutdown Email Servers

It was discovered that the ActiveMQ Java message broker performs unsafe deserialisation. For additional information, please refer to the upstream advisory at http://activemq.apache.org/security-advisories.data/CVE-2015-5254-announcement.txt. For the oldstable distribution (wheezy), this problem has been fixed in version 5.6.0+dfsg-1+deb7u2. For the stable distribution (jessie), this problem has been fixed in version 5.6.0+dfsg1-4+deb8u2. For the testing distribution (stretch), this […]

This update disables the Graphite font shaping library in Iceweasel, Debian’s version of the Mozilla Firefox web browser. For the oldstable distribution (wheezy), this problem has been fixed in version 38.7.1esr-1~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 38.7.1esr-1~deb8u1. For the unstable distribution (sid), this problem has been fixed in […]

Apple to release iOS 9.3 after fixing iMessages encryption vulnerability

Posted by Anthony Pell    Update to 2.40 Fixes various security issues, seehttp://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for moreinfo. ——————————————————————————– Fedora Update Notification FEDORA-2016-eacfc58fb9 2016-03-21 19:49:51.272763 ——————————————————————————– Name : seamonkey Product : Fedora 23 Version : 2.40 Release : 1.fc23 URL : http://www.seamonkey-project.org Summary : Web browser, e-mail, news, IRC client, HTML editor Description : SeaMonkey is an all-in-one […]

# Bugs fixed: * 762027 print-preview: Fix possible integer overflow flaw(CVE-2013-7447) # Updated translations: * Gaelic (Scottish) * Portuguese ——————————————————————————– Fedora Update Notification FEDORA-2016-330bfc0338 2016-03-21 19:49:51.272885 ——————————————————————————– Name : gnome-photos Product : Fedora 23 Version : 3.18.3 Release : 1.fc23 URL : https://live.gnome.org/GnomePhotos Summary : Access, organize and share your photos on GNOME Description : […]

Posted by Anthony Pell    Updated openssh packages that fix two security issues are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openssh security update Advisory ID: RHSA-2016:0465-01 Product: Red Hat Enterprise Linux Advisory URL: […]

Posted by Anthony Pell    Updated openssh packages that fix two security issues are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openssh security update Advisory ID: RHSA-2016:0466-01 Product: Red Hat Enterprise Linux Advisory URL: […]

Git could be made to crash or run programs as your login if it receivedchanges from a specially crafted remote repository. ========================================================================== Ubuntu Security Notice USN-2938-1 March 21, 2016 git vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: […]

Several security issues were fixed in WebKitGTK+. ========================================================================== Ubuntu Security Notice USN-2937-1 March 21, 2016 webkitgtk vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: Several security issues were fixed in WebKitGTK+. Software Description: – webkitgtk: Web content engine library for GTK+ Details: […]

Twitter security noticeboard

Ten years ago, Jack Dorsey, Noah Glass, Biz Stone and Evan Williams founded Twitter. Little would they know of its impact, its popularity and its usefulness to people the world over. As its celebrates its 10th birthday, we take a look at things from a security point of view with our ‘noticeboard’ feature. Here’s to […]

To pay or not to pay? What you should know about ransomware

��}�v۸��o���5��H��_�-�&�s;����ݽ=I�”!�6E2$e����+�9�w_l��S�$;r�{�uwl �B�P( �_�?:���1����ޣ�Q4v�C�aWa��ӉB� 쫮� ��(��=��>f�>Q����Q��O���E�g��׉}�U�<7bn��^�L!�x�*���p�� dQw �]��r8�W��v�}�}'��q�YC�/��1�*�6��^erOm+u-vi�L�/ b�vdSGM�n�����B;b�%�m"���|�o�����<�ɶ��Ң�5x矼���?6ywa��:e5��K�����le����w�ono��Z�W���fk���ы��[������ ��U���a�1 @�d7�P!cfٴ�����ttW�]<�N�)s�K2s�ѵnzcc�k)#�1 �Ρ�"���9t�<�~�X���� ��_Ϗ����ԎF��hZo� �#��N=��k���"�C�ˈF�ڛ�p�M��ޔо7�H@��Oi�b=KY��f`���B�(�^�&��Opjo@��%��MB(g1«t-2�i �cC�gg *�95/B�6 �!� �Y��=��u]1��L�z.p�����Bc ��PKɡA��țjP�������6��30��$���]��x82�b�J���Q~`� �M�U����d���������O'��w�t�g8^2�������zK����*I^U�=�C�t�3h�;�B��lm͎�l���0S����{& �L5�d6��`���_��~ì���Ī���%���������j8�u�z���EW��66�o5�m)��E��mlX:�>�,���`�D�{�Ҁ� �I������; ��C���R,��D���A�@=��[���lm7��w[�F��ܩ7��f�a��F�oju�a�0�:�S�[���lIX��ݮ��}�=�Pk����h�uP��z}�q�6�)�CS�l�}S�K�Rvl�VY.|q}J��`H���:ԪS�g�u4��f�o��Ac��’>��a�&��>*�OЙHeL�Ԯ�/߿�@���[���u�>�n�8�l�&����l�$ ���{m���]���:���Kh�;��͂��lZM���J� H f)�a�q�ޠ%yQ�����#��9�j����u�;��cF�]��qA�52��`�F�p틖�`^lv�]u 3�1����1�3���r��.%���@�����[��/2W�^�� Yհ>�P�g�o�� *�P�śJl��z>,S=�g�P����D�ԥ�E1g��3q��{�j�k-��U@��]*�Uѽjܽ�P��*1�o �����qu��Bu0��y1`��$р �(�_�}�i�I+F;�p榈Uc.�Љ�W�4��+����F�S@Fb�* ��L}�o�Y[�:2����7MX胠�2�F���A�?��Q@��`��$_1��u�k�C���V�zX� ���om<ނX�g��o��8=�G�� T�z�zZ��Ԃߍ��C�N!��Y�$ Hd�H�9���H��:^��������g�x�V�*���bZ������}m�q/�R�I10����bB�(���q��0�z9��&��Bw�H|;���Cu?�G�R�V�˧旤h�=�g1��_����� a�y�y�o��ݟ���’���+漶�Q[[���g���&(�g�$�m�&�/�̧/�-�v���}v�}��n$��+��} � �1�H��K���|��uumFHZ���r��L�p��Ϙn��`�PӾRg��ص*9DMӡa�U�.�č�!�4����QPx%��d��TA��b�b>Y+4o�mli��C8��E�UXV]n����s8v�t0���MB#� ��-՟��������9��´C�߉�p���up ‘ሕA)��R>+�p���1{�J�V.�dc����;�rs���6^�c)�d��(��z+ܘ@EA-��#w�D�M�����WU$:��=��@s&A�>��� �bal�Oΐp-�|��P�g.��HY��v}��c1�:��B@�5��s@A�*�-ܿ.���,]�颔���B�GnT�I}3�ȄH�O����@��c�Tʔw�2��ree�;z��*��Zf��?��U�*q��&�Pxo�crT�_���y���Cp�߇�?��������F�F(ɕ�3t� =y�xПD����/J��� *���[��a�,U�’�PcW b�,��Z�b�!�D��: qO�R�š��� ��.ܜ�g-{`���y��7*������%d��D��_ ɒ�ɲ2Yv�n���(���$R��6q8�J ��g��qA��+-cGl�m��%��T�~G�j�$��l��?G��t�;��ũ����>��u���p�= X��E��l�Z[�;��4I�A(u�s��戚2 zC#F�#���2��Ϥ��1����?�a��(tAӷWӛg�7�0�����a”>-[���!�n�!�B�D�yM��3�F��,�Pxr��K���o� ,m��#V��7u�ty��i�0�&���� �,L��C>��`�>���L�(�}���( �Ƃ’�$�ri�n�d��m��.�e�z�$� 2�GY��x��,JOM���=;�n�)V�i��2�ҲM�ȗe�Mq���@��z���n7�W��A��BťC�Ϻb�@��7;�U2 �#y�y��MFނp�cK2��4�J�gnΝ:wplv:�mq��gZ��q�Yc��N�`��,��#���i�8@R� +����&��4o,A���������]��E��3m{Z�,� […]

US will still push for encryption workarounds, even though iPhone hearing was postponed

APPLE-SA-2016-03-21-7 OS X Server 5.1 Subject: APPLE-SA-2016-03-21-7 OS X Server 5.1 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:54:38 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-7 OS X Server 5.1 OS X Server 5.1 is now available and addresses the following: Server App Available for: OS X Yosemite v10.10.5 and later […]

APPLE-SA-2016-03-21-6 Safari 9.1 Subject: APPLE-SA-2016-03-21-6 Safari 9.1 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:54:10 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-6 Safari 9.1 Safari 9.1 is now available and addresses the following: libxml2 Available for: OS X Mavericks v10.9.5, OS X Yosemite v10.10.5, OS X El Capitan v10.11 to v10.11.3 […]

APPLE-SA-2016-03-21-5 OS X El Capitan 10.11.4 and Security Update 2016-002 Subject: APPLE-SA-2016-03-21-5 OS X El Capitan 10.11.4 and Security Update 2016-002 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:53:54 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-5 OS X El Capitan 10.11.4 and Security Update 2016-002 OS X El Capitan 10.11.4 and […]

APPLE-SA-2016-03-21-4 Xcode 7.3 Subject: APPLE-SA-2016-03-21-4 Xcode 7.3 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:53:29 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-4 Xcode 7.3 Xcode 7.3 is now available and addresses the following: otool Available for: OS X El Capitan v10.11 and later Impact: A local attacker may be able to […]

APPLE-SA-2016-03-21-3 tvOS 9.2 Subject: APPLE-SA-2016-03-21-3 tvOS 9.2 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:53:12 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-3 tvOS 9.2 tvOS 9.2 is now available and addresses the following: FontParser Available for: Apple TV (4th generation) Impact: Opening a maliciously crafted PDF file may lead to an […]

APPLE-SA-2016-03-21-2 watchOS 2.2 Subject: APPLE-SA-2016-03-21-2 watchOS 2.2 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:51:14 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-2 watchOS 2.2 watchOS 2.2 is now available and addresses the following: Disk Images Available for: Apple Watch Sport, Apple Watch, Apple Watch Edition, and Apple Watch Hermes Impact: An […]

APPLE-SA-2016-03-21-1 iOS 9.3 Subject: APPLE-SA-2016-03-21-1 iOS 9.3 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:49:31 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-1 iOS 9.3 iOS 9.3 is now available and addresses the following: AppleUSBNetworking Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: […]

Apple patches 56 vulnerabilities in OS X El Capitan, improves Live Photo sharing
Financial threats 2015: 73 percent drop in financial Trojan infections but threat is far from neutralized
Google warns of Android flaw used to gain root access to devices
Clarke: Precedent-Seeking FBI Won’t Ask NSA to Unlock Phone
Hackers Steal $81 Million from Federal Reserve
Tor Project says it can quickly catch spying code
Google, Microsoft, Yahoo, and others publish new email security standard
Get hired as a security pro: Insider tips

Over the years I’ve hired or helped hire hundreds of computer security folks. Although job interviews tend to last an hour, I can usually tell in a few minutes if I’m talking to the right person for the job. If I think I have the right person, I will lead them into saying the right […]

Discovered: March 21, 2016 Updated: March 22, 2016 10:29:37 AM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Infostealer.Olymvis is a Trojan horse that steals information from the compromised computer. Antivirus Protection Dates Initial Rapid Release version […]

Hacking Brain Possible with DARPA’ New Targeted Neuroplasticity Training Program
Facebook Develops Artificial Intelligence to Map World Populace Accurately

Alex Rousskov from The Measurement Factory discovered that Squid3, a fully featured web proxy cache, does not properly handle errors for certain malformed HTTP responses. A remote HTTP server can exploit this flaw to cause a denial of service (assertion failure and daemon exit). For the oldstable distribution (wheezy), this problem has been fixed in […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 webkitgtk3-2.4.10-1.fc23 Fedora 23 websvn-2.3.3-12.fc23 Fedora 23 proftpd-1.3.5b-1.fc23 Fedora 23 libvpx-1.4.0-6.fc23 Fedora 23 git-2.5.5-1.fc23 Debian: 3524-1: activemq: Summary Debian: 3523-1: iceweasel: Summary Fedora 22 websvn-2.3.3-12.fc22 Community Linux Events Linux […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 webkitgtk3-2.4.10-1.fc23 Fedora 23 websvn-2.3.3-12.fc23 Fedora 23 proftpd-1.3.5b-1.fc23 Fedora 23 libvpx-1.4.0-6.fc23 Fedora 23 git-2.5.5-1.fc23 Debian: 3524-1: activemq: Summary Debian: 3523-1: iceweasel: Summary Fedora 22 websvn-2.3.3-12.fc22 Community Linux Events Linux […]

Posted by Anthony Pell    Cumulative maintenance release from upstream. Highlights are: * SSH RSAhostkeys smaller than 2048 bits now work properly. * MLSD response lines are nowproperly CRLF terminated. * Fixed selection of DH groups from TLSDHParamFile(CVE-2016-3125). Various other bug fixes are also included. ——————————————————————————– Fedora Update Notification FEDORA-2016-977d57cf2d 2016-03-20 22:04:03.376869 ——————————————————————————– Name : […]

Fix CVE-2016-1621 in bundled libwebm code. ——————————————————————————– Fedora Update Notification FEDORA-2016-fae59061fe 2016-03-20 22:04:03.376115 ——————————————————————————– Name : libvpx Product : Fedora 23 Version : 1.4.0 Release : 6.fc23 URL : http://www.webmproject.org/code/ Summary : VP8 Video Codec SDK Description : libvpx provides the VP8 SDK, which allows you to integrate your applications with the VP8 video codec, […]

Security fix for CVE-2016-2315, CVE-2016-2324 (by updating to 2.5.5). ——————————————————————————– Fedora Update Notification FEDORA-2016-6554eff611 2016-03-20 22:04:03.375556 ——————————————————————————– Name : git Product : Fedora 23 Version : 2.5.5 Release : 1.fc23 URL : http://git-scm.com/ Summary : Fast Version Control System Description : Git is a fast, scalable, distributed revision control system with an unusually rich command […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3524-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 20, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : activemq CVE ID : CVE-2015-5254 It was discovered that the ActiveMQ Java message broker performs unsafe deserialisation. For additional information, please refer to the upstream advisory at http://activemq.apache.org/security-advisories.data/CVE-2015-5254-announcement.txt For the oldstable distribution (wheezy), this […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3523-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 20, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : iceweasel CVE ID : not available This update disables the Graphite font shaping library in Iceweasel, Debian’s version of the Mozilla Firefox web browser. For the oldstable distribution (wheezy), this problem has been fixed […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 webkitgtk3-2.4.10-1.fc23 Fedora 23 websvn-2.3.3-12.fc23 Fedora 23 proftpd-1.3.5b-1.fc23 Fedora 23 libvpx-1.4.0-6.fc23 Fedora 23 git-2.5.5-1.fc23 Debian: 3524-1: activemq: Summary Debian: 3523-1: iceweasel: Summary Fedora 22 websvn-2.3.3-12.fc22 Community Linux Events Linux […]

Posted by Anthony Pell    Cumulative maintenance release from upstream. Highlights are: * SSH RSAhostkeys smaller than 2048 bits now work properly. * MLSD response lines are nowproperly CRLF terminated. * Fixed selection of DH groups from TLSDHParamFile(CVE-2016-3125). Various other bug fixes are also included. ——————————————————————————– Fedora Update Notification FEDORA-2016-f95d8ea3ad 2016-03-20 16:01:37.694775 ——————————————————————————– Name : […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3522-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 20, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : squid3 CVE ID : CVE-2016-2571 Alex Rousskov from The Measurement Factory discovered that Squid3, a fully featured web proxy cache, does not properly handle errors for certain malformed HTTP responses. A remote HTTP server […]

Posted by Anthony Pell    Multiple vulnerabilities have been found in OpenSSL, the worst allowing remote attackers to decrypt TLS sessions. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 webkitgtk3-2.4.10-1.fc23 Fedora 23 websvn-2.3.3-12.fc23 Fedora 23 proftpd-1.3.5b-1.fc23 Fedora 23 libvpx-1.4.0-6.fc23 Fedora 23 git-2.5.5-1.fc23 Debian: 3524-1: activemq: Summary Debian: 3523-1: iceweasel: Summary Fedora 22 websvn-2.3.3-12.fc22 Community Linux Events Linux […]

Symantec fixes high-risk flaws in Symantec Endpoint Protection
Tim Cook comments on iPhone data privacy and security