Not even a week has passed since ESET warned users worldwide about an active Ray-Ban scam campaign on Facebook, which tricks users into sending their payment card details to the attackers. Today we bring you information on yet another malicious activity targeting the world’s largest social network. This time, malicious links are disguised as a […]
Discovered: April 14, 2016 Updated: April 14, 2016 8:27:22 AM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Vista, Windows XP Packed.Generic.500 is a heuristic detection for files that may have been obfuscated or encrypted in order to conceal them from antivirus software. […]
Risk High Date Discovered April 12, 2016 Description Microsoft Windows is prone to a remote code-execution vulnerability. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will result in a denial of service condition. Technologies Affected Microsoft .NET Framework 4.6 Microsoft .NET Framework […]
Risk High Date Discovered April 12, 2016 Description Microsoft Edge is prone to a remote privilege-escalation vulnerability. An attacker can exploit this issue to gain elevated privileges. Successful exploits may aid in further attacks. Recommendations Block external access at the network boundary, unless external parties require service. Filter access to the affected computer at the […]
Risk High Date Discovered April 12, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]
Risk High Date Discovered April 12, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]
Posted by Anthony Pell Rebase to the new upstream bugfix-only version. Add security fixes for thereferenced bugs. ——————————————————————————– Fedora Update Notification FEDORA-2016-f8eee2e628 2016-04-13 03:26:08.777154 ——————————————————————————– Name : imlib2 Product : Fedora 23 Version : 1.4.8 Release : 1.fc23 URL : http://docs.enlightenment.org/api/imlib2/html/ Summary : Image loading, saving, rendering, and manipulation library Description : Imlib 2 […]
Posted by Anthony Pell Update to xerces-c 3.1.3, fixing CVE-2016-0729 ——————————————————————————– Fedora Update Notification FEDORA-2016-ae9ac16cf3 2016-04-13 03:26:08.776399 ——————————————————————————– Name : xerces-c Product : Fedora 23 Version : 3.1.3 Release : 1.fc23 URL : http://xml.apache.org/xerces-c/ Summary : Validating XML Parser Description : Xerces-C is a validating XML parser written in a portable subset of C++. […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 imlib2-1.4.8-1.fc23 Fedora 23 xerces-c-3.1.3-1.fc23 Fedora 23 libreswan-3.17-1.fc23 Red Hat: 2016:0612-01: samba and samba4: Critical Advisory Red Hat: 2016:0618-01: samba: Critical Advisory Red Hat: 2016:0625-01: samba: Important Advisory Red […]
An update for samba4 and samba is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7, respectively. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba and samba4 security, bug fix, and enhancement update Advisory ID: RHSA-2016:0612-01 […]
An update for samba is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba security, bug fix, and enhancement update Advisory ID: RHSA-2016:0618-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0618.html […]
An update for samba is now available for Red Hat Enterprise Linux 4 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: samba security update Advisory ID: RHSA-2016:0625-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0625.html Issue date: 2016-04-12 CVE […]
An update for samba4 is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 Extended Update Support. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba4 security, bug fix, and enhancement […]
An update for samba3x is now available for Red Hat Enterprise Linux 5.6 Long Life and Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba3x security update Advisory ID: RHSA-2016:0624-01 Product: Red Hat Enterprise Linux […]
An update for samba is now available for Red Hat Enterprise Linux 5.6 Long Life and Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: samba security update Advisory ID: RHSA-2016:0623-01 Product: Red Hat Enterprise Linux […]
An update for samba is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 Extended Update Support. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba security update Advisory ID: RHSA-2016:0619-01 […]
An update for samba is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba security update Advisory ID: RHSA-2016:0611-01 Product: Red Hat Enterprise […]
An update for samba3x is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba3x security update Advisory ID: RHSA-2016:0613-01 Product: Red Hat Enterprise […]
Discovered: April 12, 2016 Updated: April 13, 2016 8:56:48 AM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Zbot.D is a Trojan horse that opens a back door and steals information from the compromised […]
Several vulnerabilities were discovered in Imagemagick, a program suite for image manipulation. This update fixes a large number of potential security problems such as null-pointer access and buffer-overflows that might lead to memory leaks or denial of service. None of these security problems have a CVE number assigned. For the oldstable distribution (wheezy), this problem […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 postgresql-9.5.2-1.fc24 Fedora 24 xerces-c-3.1.3-1.fc24 Fedora 24 libreswan-3.17-1.fc24 Red Hat: 2016:0617-01: kernel: Moderate Advisory Debian: 3485-2: didiwiki: Summary Red Hat: 2016:0615-01: openvswitch: Important Advisory Ubuntu: 2948-2: Linux kernel (Utopic […]
Posted by Anthony Pell Update to xerces-c 3.1.3, fixing CVE-2016-0729 ——————————————————————————– Fedora Update Notification FEDORA-2016-9ff972ca42 2016-04-12 09:36:30.965273 ——————————————————————————– Name : xerces-c Product : Fedora 24 Version : 3.1.3 Release : 1.fc24 URL : http://xml.apache.org/xerces-c/ Summary : Validating XML Parser Description : Xerces-C is a validating XML parser written in a portable subset of C++. […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 postgresql-9.5.2-1.fc24 Fedora 24 xerces-c-3.1.3-1.fc24 Fedora 24 libreswan-3.17-1.fc24 Red Hat: 2016:0617-01: kernel: Moderate Advisory Debian: 3485-2: didiwiki: Summary Red Hat: 2016:0615-01: openvswitch: Important Advisory Ubuntu: 2948-2: Linux kernel (Utopic […]
An update for kernel is now available for Red Hat Enterprise Linux 6.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security and bug fix update Advisory ID: RHSA-2016:0617-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0617.html Issue […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3485-2 security@debian.org https://www.debian.org/security/ Sebastien Delafond April 12, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : didiwiki Debian Bug : 818708 The update for didiwiki issued as DSA-3485-1 introduced a regression that caused a large number of valid pages to not be accessible anymore. This occurred mostly for pages whose […]
Updated openvswitch packages that fix one security issue are now available for Red Hat OpenShift Enterprise 3.1. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openvswitch security update Advisory ID: RHSA-2016:0615-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2016:0615 Issue date: 2016-04-11 CVE […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 postgresql-9.5.2-1.fc24 Fedora 24 xerces-c-3.1.3-1.fc24 Fedora 24 libreswan-3.17-1.fc24 Red Hat: 2016:0617-01: kernel: Moderate Advisory Debian: 3485-2: didiwiki: Summary Red Hat: 2016:0615-01: openvswitch: Important Advisory Ubuntu: 2948-2: Linux kernel (Utopic […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3547-1 security@debian.org https://www.debian.org/security/ Luciano Bello April 11, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imagemagick Debian Bug : 811308 Several vulnerabilities were discovered in Imagemagick, a program suite for image manipulation. This update fixes a large number of potential security problems such as null-pointer access and buffer-overflows that […]
Discovered: April 11, 2016 Updated: April 11, 2016 8:41:53 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Downloader.Orcalata is a Trojan horse that downloads potentially malicious files onto the compromised computer. Antivirus Protection Dates Initial Rapid […]
If you’re under the age of 65, chances are you’ll live long enough to see most cars become autonomous, self-driving, shared transportation pods. You’ll see home delivery by drone become the norm. You’ll become host to the myriad of computers you and your clothing will contain. All reality will become augmented reality. You’ll be able […]
Risk Medium Date Discovered April 12, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted […]
Risk High Date Discovered April 12, 2016 Description Microsoft Windows is prone to a memory-corruption vulnerability. Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed attacks will cause denial-of-service conditions. Technologies Affected Microsoft .NET Framework 3.0 SP2 Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.5.1 Microsoft Live […]
Risk Medium Date Discovered April 12, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted […]
Risk High Date Discovered April 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered April 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered April 12, 2016 Description Microsoft XML Core Services is prone to a remote code-execution vulnerability. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions. Technologies Affected Microsoft Windows 10 for 32-bit Systems Microsoft Windows 10 for x64-based […]
Risk High Date Discovered April 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered April 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered April 12, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]
Risk High Date Discovered April 12, 2016 Description Microsoft Internet Explorer is prone to a remote code-execution vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]
Discovered: April 11, 2016 Updated: April 12, 2016 11:07:13 AM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Antivirus Protection Dates Initial Rapid Release version April 11, 2016 revision 039 Latest Rapid Release version […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 pulp-rpm-2.8.2-1.fc24 Fedora 24 pulp-puppet-2.8.2-1.fc24 Fedora 24 pulp-2.8.2-1.fc24 Fedora 23 python-pillow-3.0.0-4.fc23 Fedora 22 python-pillow-2.8.2-5.fc22 Fedora 23 xen-4.5.3-1.fc23 Fedora 23 latex2rtf-2.3.10-1.fc23 Fedora 23 php-5.6.20-1.fc23 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 pulp-rpm-2.8.2-1.fc24 Fedora 24 pulp-puppet-2.8.2-1.fc24 Fedora 24 pulp-2.8.2-1.fc24 Fedora 23 python-pillow-3.0.0-4.fc23 Fedora 22 python-pillow-2.8.2-5.fc22 Fedora 23 xen-4.5.3-1.fc23 Fedora 23 latex2rtf-2.3.10-1.fc23 Fedora 23 php-5.6.20-1.fc23 Community Linux Events Linux User Groups […]
Update to 2.8.2 for CVE-2016-3095. ——————————————————————————– Fedora Update Notification FEDORA-2016-f75bd73891 2016-04-11 09:11:06.297385 ——————————————————————————– Name : pulp Product : Fedora 24 Version : 2.8.2 Release : 1.fc24 URL : https://github.com/pulp/pulp Summary : An application for managing software repositories Description : Pulp provides replication, access, and accounting for software repositories. ——————————————————————————– Update Information: Update to 2.8.2 for […]
This update fixes an integer overflow in Jpeg2KEncode.c causing a bufferoverflow (CVE-2016-3076). ——————————————————————————– Fedora Update Notification FEDORA-2016-35700c5956 2016-04-10 10:23:15.141497 ——————————————————————————– Name : python-pillow Product : Fedora 23 Version : 3.0.0 Release : 4.fc23 URL : http://python-pillow.github.io/ Summary : Python image processing library Description : Python image processing library, fork of the Python Imaging Library (PIL) […]
This update fixes an integer overflow in Jpeg2KEncode.c causing a bufferoverflow (CVE-2016-3076). ——————————————————————————– Fedora Update Notification FEDORA-2016-6ad4474058 2016-04-10 10:18:57.729299 ——————————————————————————– Name : python-pillow Product : Fedora 22 Version : 2.8.2 Release : 5.fc22 URL : http://python-pillow.github.io/ Summary : Python image processing library Description : Python image processing library, fork of the Python Imaging Library (PIL) […]
update to 4.5.3 —- broken AMD FPU FIP/FDP/FOP leak workaround [XSA-172,CVE-2016-3158, CVE-2016-3159] ——————————————————————————– Fedora Update Notification FEDORA-2016-e5432ca977 2016-04-09 10:22:58.046533 ——————————————————————————– Name : xen Product : Fedora 23 Version : 4.5.3 Release : 1.fc23 URL : http://xen.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command […]
Update to 2.3.10 for CVE-2015-8106 ——————————————————————————– Fedora Update Notification FEDORA-2016-b9368247d4 2016-04-09 10:22:58.046350 ——————————————————————————– Name : latex2rtf Product : Fedora 23 Version : 2.3.10 Release : 1.fc23 URL : http://latex2rtf.sourceforge.net/ Summary : LaTeX to RTF converter that handles equations, figures, and cross-references Description : LaTeX2rtf is a translator program which is intended to translate a LaTeX […]
Posted by Anthony Pell 31 Mar 2016, **PHP 5.6.20** **CLI Server:** * Fixed bug php#69953 (SupportMKCALENDAR request method). (Christoph) **Core:** * Fixed bug php#71596(Segmentation fault on ZTS with date function (setlocale)). (Anatol) **Curl:*** Fixed bug php#71694 (Support constant CURLM_ADDED_ALREADY). (mpyw) **Date:*** Fixed bug php#71635 (DatePeriod::getEndDate segfault). (Thomas Punt)**Fileinfo:** * Fixed bug php#71527 (Buffer over-write […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 pulp-rpm-2.8.2-1.fc24 Fedora 24 pulp-puppet-2.8.2-1.fc24 Fedora 24 pulp-2.8.2-1.fc24 Fedora 23 python-pillow-3.0.0-4.fc23 Fedora 22 python-pillow-2.8.2-5.fc22 Fedora 23 xen-4.5.3-1.fc23 Fedora 23 latex2rtf-2.3.10-1.fc23 Fedora 23 php-5.6.20-1.fc23 Community Linux Events Linux User Groups […]
Posted by Anthony Pell 31 Mar 2016, **PHP 5.6.20** **CLI Server:** * Fixed bug php#69953 (SupportMKCALENDAR request method). (Christoph) **Core:** * Fixed bug php#71596(Segmentation fault on ZTS with date function (setlocale)). (Anatol) **Curl:*** Fixed bug php#71694 (Support constant CURLM_ADDED_ALREADY). (mpyw) **Date:*** Fixed bug php#71635 (DatePeriod::getEndDate segfault). (Thomas Punt)**Fileinfo:** * Fixed bug php#71527 (Buffer over-write […]
update to 4.5.3 —- broken AMD FPU FIP/FDP/FOP leak workaround [XSA-172,CVE-2016-3158, CVE-2016-3159] ——————————————————————————– Fedora Update Notification FEDORA-2016-5f196e4e4a 2016-04-09 10:20:41.903381 ——————————————————————————– Name : xen Product : Fedora 22 Version : 4.5.3 Release : 1.fc22 URL : http://xen.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 pulp-rpm-2.8.2-1.fc24 Fedora 24 pulp-puppet-2.8.2-1.fc24 Fedora 24 pulp-2.8.2-1.fc24 Fedora 23 python-pillow-3.0.0-4.fc23 Fedora 22 python-pillow-2.8.2-5.fc22 Fedora 23 xen-4.5.3-1.fc23 Fedora 23 latex2rtf-2.3.10-1.fc23 Fedora 23 php-5.6.20-1.fc23 Community Linux Events Linux User Groups […]
Welcome to this week’s security review, which includes an in-depth look at how the ransomware dubbed Locky is infiltrating computer systems. The past seven days of security have also seen the takedown of the Mumblehard Linux botnet, the addition of end-to-end encryption by WhatsApp and a massive data breach in Turkey which could affect more than half […]
