Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Posted by Anthony Pell 31 Mar 2016, **PHP 5.6.20** **CLI Server:** * Fixed bug php#69953 (SupportMKCALENDAR request method). (Christoph) **Core:** * Fixed bug php#71596(Segmentation fault on ZTS with date function (setlocale)). (Anatol) **Curl:*** Fixed bug php#71694 (Support constant CURLM_ADDED_ALREADY). (mpyw) **Date:*** Fixed bug php#71635 (DatePeriod::getEndDate segfault). (Thomas Punt)**Fileinfo:** * Fixed bug php#71527 (Buffer over-write […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3541-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond April 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : roundcube CVE ID : CVE-2015-8770 High-Tech Bridge Security Research Lab discovered that Roundcube, a webmail client, contained a path traversal vulnerability. This flaw could be exploited by an attacker to access sensitive files on […]
Multiple vulnerabilities have been found in Xen, the worst of which cause a Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – Gentoo Linux Security […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Posted by Anthony Pell Libav could be made to crash or run programs as your login if it opened aspecially crafted file. ========================================================================== Ubuntu Security Notice USN-2944-1 April 04, 2016 libav vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Libav could be made to […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Posted by Anthony Pell patch to fix #1319858,#1319859,#1319861 ——————————————————————————– Fedora Update Notification FEDORA-2016-256f700c92 2016-04-04 17:23:29.743823 ——————————————————————————– Name : vtun Product : Fedora 24 Version : 3.0.3 Release : 15.fc24 URL : http://vtun.sourceforge.net Summary : Virtual tunnel over TCP/IP networks Description : VTun provides a method for creating Virtual Tunnels over TCP/IP networks and allows […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Discovered: April 4, 2016 Updated: April 5, 2016 8:48:04 AM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Infostealer.Fakepude is a Trojan horse that steals information from the compromised computer. Antivirus Protection Dates Initial Rapid Release version […]
Discovered: April 1, 2016 Updated: April 4, 2016 9:50:42 AM Type: Trojan Infection Length: Varies Systems Affected: Linux, Solaris, Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP PHP.Ransomcrypt.B is a Trojan horse that encrypts files on the compromised server. Antivirus Protection […]
The Trump Hotel Collection has once again suffered a data breach, according to a security expert. Brian Krebs reported that banking industry sources have informed him that the chain, which belongs to the Republican presidential candidate Donald Trump, has been the victim of another attack. Mr. Krebs said that he was alerted to this story […]
Digital certificates and malware go together like peanut butter and petroleum jelly — they can be sandwiched together easily, but the result is not exactly tasty or good for you. As you may know, digital certificates are used to cryptographically sign executable code and documents. If the digital certificate used for signing the content was […]
Emmanuel Thome discovered that missing sanitising in the oarsh command of OAR, a software used to manage jobs and resources of HPC clusters, could result in privilege escalation. For the oldstable distribution (wheezy), this problem has been fixed in version 2.5.2-3+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 2.5.4-2+deb8u1. For […]
Several vulnerabilities have been discovered in Mercurial, a distributed version control system. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2016-3068 Blake Burkhart discovered that Mercurial allows URLs for Git subrepositories that could result in arbitrary code execution on clone. CVE-2016-3069 Blake Burkhart discovered that Mercurial allows arbitrary code execution when converting Git […]
High-Tech Bridge Security Research Lab discovered that Roundcube, a webmail client, contained a path traversal vulnerability. This flaw could be exploited by an attacker to access sensitive files on the server, or even execute arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 0.7.2-9+deb7u2. For the testing (stretch) and unstable […]
Discovered: April 4, 2016 Updated: April 4, 2016 11:38:57 PM Type: Worm Infection Length: 262,144 bytes Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP W32.Ransomlock.AP is a is a worm that locks the desktop, making the compromised computer unusable. […]
Risk High Date Discovered March 8, 2016 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed […]
Posted by Anthony Pell A NetworkManager 1.0.x branch stable update: * Release notes:https://cgit.freedesktop.org/NetworkManager/NetworkManager/tree/NEWS?h=1.0.12 *Release announcement: https://mail.gnome.org/archives/networkmanager-list/2016-April/msg00000.html ——————————————————————————– Fedora Update Notification FEDORA-2016-8201e3fefa 2016-04-03 14:04:39.114316 ——————————————————————————– Name : NetworkManager Product : Fedora 23 Version : 1.0.12 Release : 1.fc23 URL : http://www.gnome.org/projects/NetworkManager/ Summary : Network connection manager and user applications Description : NetworkManager is a system […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3540-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : lhasa CVE ID : CVE-2016-2347 Marcin Noga discovered an integer underflow in Lhasa, a lzh archive decompressor, which might result in the execution of arbitrary code if a malformed archive is processed. For the […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Posted by Anthony Pell Multiple vulnerabilities have been found in QEMU, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – – – – – – […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Posted by Anthony Pell Update to NetworkManager 1.2-beta3. Upstream release announcement:https://mail.gnome.org/archives/networkmanager-list/2016-March/msg00164.html ——————————————————————————– Fedora Update Notification FEDORA-2016-cd218eef79 2016-04-02 15:48:47.755168 ——————————————————————————– Name : NetworkManager Product : Fedora 24 Version : 1.2.0 Release : 0.8.beta3.fc24 URL : http://www.gnome.org/projects/NetworkManager/ Summary : Network connection manager and user applications Description : NetworkManager is a system service that manages network interfaces […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome to this week’s security review, which includes insight into Remaiten, bolstering Trident’s cybersecurity, the value of backing up your data and why banks, according to some, should not compensate victims of online fraud. Remaiten: The Linux bot that targets routers and other IoT devices Researchers at ESET revealed that they were actively monitoring a […]
In recent months, there has been a significant increase in the number of networks and users affected by ransomware known as Locky, which is used to encrypt a victim’s files and then demand a ransom to be paid in bitcoins. But, how does this threat manage to infiltrate computer systems and hijack data? From the ESET Research Lab in […]
Marcin Noga discovered an integer underflow in Lhasa, a lzh archive decompressor, which might result in the execution of arbitrary code if a malformed archive is processed. For the oldstable distribution (wheezy), this problem has been fixed in version 0.0.7-2+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 0.2.0+git3fe46-1+deb8u1. For the […]
Randell Jesup and the Firefox team discovered that srtp, Cisco’s reference implementation of the Secure Real-time Transport Protocol (SRTP), does not properly handle RTP header CSRC count and extension header length. A remote attacker can exploit this vulnerability to crash an application linked against libsrtp, resulting in a denial of service. For the oldstable distribution […]
An update for libssh is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: libssh security update Advisory ID: RHSA-2016:0566-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0566.html Issue date: 2016-03-31 CVE Names: […]
An update for mariadb is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: mariadb security and bug fix update Advisory ID: RHSA-2016:0534-01 Product: […]
Posted by Anthony Pell An update for krb5 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: krb5 security update Advisory ID: […]
Posted by Anthony Pell Update to origin 1.1.3, disable v1beta1, v1beta3, fix application/json contenttype, don’t let hyperkube to parse flags for all commands (make it optional)—- Update to origin 1.1.3, disable v1beta1, v1beta3, fix application/jsoncontent type, don’t let hyperkube to parse flags —- Update to origin 1.1.3,disable v1beta1, v1beta3, fix application/json content type —- […]
New upstream release with security bug fix ——————————————————————————– Fedora Update Notification FEDORA-2016-6dc5678273 2016-03-31 20:29:07.231134 ——————————————————————————– Name : python-rsa Product : Fedora 24 Version : 3.4.1 Release : 1.fc24 URL : http://stuvel.eu/rsa Summary : Pure-Python RSA implementation Description : Python-RSA is a pure-Python RSA implementation. It supports encryption and decryption, signing and verifying signatures, and key […]
Posted by Anthony Pell An update for bind is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 Extended Update Support. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: bind security update Advisory ID: RHSA-2016:0562-01 Product: Red Hat […]
APPLE-SA-2016-03-31-1 iBooks Author 2.4.1 Subject: APPLE-SA-2016-03-31-1 iBooks Author 2.4.1 From: Apple Product Security <email@hidden> Date: Thu, 31 Mar 2016 14:14:32 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-31-1 iBooks Author 2.4.1 iBooks Author 2.4.1 is now available and addresses the following: iBooks Author Available for: OS X Yosemite v10.10 or later Impact: Parsing a maliciously […]
A lot happens in the security world and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. MedStar Health, Latest Medical Services Ransomware Target Early this week, MedStar Health, one of the […]
Discovered: April 1, 2016 Updated: April 1, 2016 2:17:04 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Huntpos is a Trojan horse that steals information from the compromised computer. Antivirus Protection Dates Initial […]
Discovered: April 1, 2016 Updated: April 1, 2016 3:49:26 PM Type: Worm Infection Length: 526,336 bytes Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP W32.Woniore is a worm that spreads through removable drives. It also downloads potentially […]
