Menu

Monthly Archives: May 2016

Tick-tock: Time is running out to move from SHA-1 to SHA-2

Are you ready for the coming SHA-1 deprecation deadline? I suspect most companies aren’t. They don’t know about the issue — and the pending January 1, 2017 deadline. Others are probably aware that there is something called “SHA-1 deprecation” and have gotten some browser certificate errors, but don’t fully appreciate the need to be substantially […]

Edward Snowden – the movie

Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit. CVE-2016-2105 Guido Vranken discovered that an overflow can occur in the function EVP_EncodeUpdate(), used for Base64 encoding, if an attacker can supply a large amount of data. This could lead to a heap corruption. CVE-2016-2106 Guido Vranken discovered that an overflow can occur in […]

Anonymous Target Bank of Greece Website with Massive DDoS Attack

It was discovered that a heap overflow in the Poppler PDF library may result in denial of service and potentially the execution of arbitrary code if a malformed PDF file is opened. For the stable distribution (jessie), this problem has been fixed in version 0.26.5-2+deb8u1. For the testing distribution (stretch), this problem has been fixed […]

Microsoft Planning to Use DNA for Data Storage

An update for java-1.6.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.6.0-ibm security update Advisory ID: RHSA-2016:0708-01 Product: Red Hat Enterprise Linux Supplementary Advisory […]

Posted by Anthony Pell    An update for mercurial is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: mercurial security update Advisory ID: RHSA-2016:0706-01 […]

Posted by Anthony Pell    An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:0707-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0707.html […]

An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: rh-mysql56-mysql security update Advisory ID: RHSA-2016:0705-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0705.html Issue date: 2016-05-02 CVE Names: CVE-2015-4792 CVE-2015-4800 CVE-2015-4802 […]

Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3565-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond May 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : botan1.10 CVE ID : CVE-2015-5726 CVE-2015-5727 CVE-2015-7827 CVE-2016-2194 CVE-2016-2195 CVE-2016-2849 Debian Bug : 817932 822698 Several security vulnerabilities were found in botan1.10, a C++ library which provides support for […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3564-1 security@debian.org https://www.debian.org/security/ Michael Gilbert May 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1660 CVE-2016-1661 CVE-2016-1662 CVE-2016-1663 CVE-2016-1664 CVE-2016-1665 CVE-2016-1666 Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1660 Atte Kettunen discovered an out-of-bounds write issue. CVE-2016-1661 Wadih Matar discovered a […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3563-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : poppler CVE ID : CVE-2015-8868 It was discovered that a heap overflow in the Poppler PDF library may result in denial of service and potentially the execution of arbitrary code if a malformed PDF […]

Consider Selfie Sticks Old-School — Time to use Hover Drones for Selfies
IT leaders pick productivity over security
Microsoft to begin SHA-1 crypto shutoff with Windows 10’s summer upgrade
TrueCrypter ransomware lets you pay with Amazon gift cards
Qatar National Bank Accepts Data Breach while Hackers Release Inside Video

Several vulnerabilities were discovered in tardiff, a tarball comparison tool. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-0857 Rainer Mueller and Florian Weimer discovered that tardiff is prone to shell command injections via shell meta-characters in filenames in tar files or via shell meta-characters in the tar filename itself. CVE-2015-0858 Florian Weimer […]