Patrick Coleman discovered that missing input sanitising in the ADPCM decoder of the VLC media player may result in the execution of arbitrary code if a malformed media file is opened. For the stable distribution (jessie), this problem has been fixed in version 2.2.4-1~deb8u1. For the unstable distribution (sid), this problem has been fixed in […]
Two related issues have been discovered in Expat, a C library for parsing XML. CVE-2012-6702 It was introduced when CVE-2012-0876 was addressed. Stefan Sørensen discovered that the use of the function XML_Parse() seeds the random number generator generating repeated outputs for rand() calls. CVE-2016-5300 It is the product of an incomplete solution for CVE-2012-0876. The […]
The University of Calgary has handed over $20,000 CND to cybercriminals, who had launched a ransomware attack on the institution. It revealed that 10 days after its systems were affected, it has been unable to fully restore its systems back to normal. This is despite efforts by its IT department to “isolate the effects of […]
Debian: 3598-1: vlc: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3598-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 07, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : vlc CVE ID : CVE-2016-5108 Patrick Coleman discovered that missing input sanitising in the ADPCM decoder of the VLC media player may result in the […]
Debian: 3597-1: expat: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3597-1 security@debian.org https://www.debian.org/security/ Luciano Bello June 07, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : expat CVE ID : CVE-2012-6702 CVE-2016-5300 Two related issues have been discovered in Expat, a C library for parsing XML. CVE-2012-6702 It was introduced when […]
��}ے�F���(Q>”9&^�n�uZ-y�9���=�9���$�Aƥٴ���}ڈ݈��_0�’�%��U �I4%�{$_UYUY�Y�YYYOtn�5t��q�? � 7��a ��{2�}|��’�TT�?’�u�v�{1�b�|��į~-�7�� Yc3�x�O�vPc��b8�U��D;�’�;W��E��#^��ޯ];|�a���:v
��}�۸��o�j��O��Z$u��g,��c�Y�Ϸxf�f?�QQ$$qL�^F��N�y��JUR�WHU��˛�’I7R�E���w{/�H��ht7��ᝧ��Oy��x��������%��M� �N�t��rH�q�? �5��un=�R�܂’����MVT��&�y_9�z�v��B,�����”6��#kj���I�� c� �� ���#�zCTե�&0�ر��4�,�2ǪV�$��$t%��(��?D�p��q�x9� �Σ�U�d�:��!��a�ֆN;��N�s��>l�ׂ��6h�+��v��@� P���33’t㱖4x��iG��?��}O{�’� 0#�,�H�r����?��ЖZ����ʊ�aZ��gV@+ZEa��k~4WRڟ���N�VT��|���Bj�~xE?�~0�/�����k����tf1� %�/8g���*(qk�Ns}8��?sNh;�$”}�I�� ��!��{��s�’� F��a�!}o������~�h ��7�tآ��’:�!+-C���{$��YnbcKg{�*k����g�۳�0oG������v�����a�F-��)�M���tn���tFe���͋hEu�f��[:hzf�_���ɿJ�V�G!���ݻg�c�uO�ӣ��c�’��;����q�8%�npA�`RaƮ9Q��S ���ʼn��q�cߦ�����^kw��me���f��j7[��O�����FSw�7����57����z�V�N�ocw��#�Fg����:MT�����Ct4�5G�˅MM@���:�i|H:t������t}~H�Do�?�ҋqɣ��x���^��3 �ij�� ���b_~y�!_��K,u�bV�c�U?p����Q�0և���j����g�D}(��ȥn� E}3����z�*��;�gn������m}Y�N� �o�^�A�J/G�� qHb�#�u����7�]��Z��lz����ZT .&��e�>0�R�J%�,���w��r��y��f�$č,�s��ՍB��1����?:�Ҽ%�F�v�57�R66�s���ZS��g �!d�s�6Y��1�����~��g+��[J=�߅��g� ���.”�|)���i��/�2����҄��dB#X8?��x��}E���������ƯQ�^�myL������{h�+6[�0��_��Nٲ{��=9!]�M~��.�^E:����BB�0#�g���%4�%Zx�y1���4�Q��2�$Y��>-I ����#g8�J�$]���’ �w����´C࿓��fT/��`N��ˋJ��ixY��>$��3z�N�V��Dg��{�j�5��5���a� [=��.MG�K�4%y�Fb��&���`� V5�w%{�z��cB0�E�m�*5fv��N3e1>{&��d��UC��K�x�x���0�)���-:�]0�� Ƶ�����#]����u]qNY t�(�R�”���� 3″��{���6��J-S=(�H�J1�u�+�!��Z�)|x�”����mh�w�&��u]�Ə�h��X��E��r�:�{�Z���� ��Lw9rwxKR�^�1�b��I�8�S2f~H5�dgl�^��zFs(Fs�@��{�1�&�Ӫ�z�BlY.��^ץރ�s]�f�Q�(�F���0��ʝ����͈�����[67���a�`�)`G��l��ty�UHis�0�f��Υ/�Y��9@(�$U& �K�� �2Cg���6*n� �Y;�L[`lz��{탃�9i��I��`����7����9�ī.�hE����>)6 ��o[�ƺ��(u�OiuI6��s{���u�{�tp� �+4)oXњٟ�����(��K$:�1[���g6d>����̝[�V8vz�z{�#y�R������ev���*W��b����sUT�_G��r�)sc���U�����-lñsA�8��e���|�P��S�9xY�P�TG���,6u~�I��_�6�’��ú,x�L�k4���w[�S_�0�c�!;E2��h�q�����k]�����1@�o+��O��B����{d��Ik�”a��t,m6~_I@q`XА���t�)=��Kx䭈�=””�64m’�I8|���l3J�LV|_!Z��5l�h����{���z�{��� ��f�� a�{�( �ʻJ�V�j���%� ���O�82�0r�#��$�ە�o��qV�w�V���5:��wd��Үޭ��Q!�m���Ap�.L�u�$P���R’Ws�jƙ���D�$bQ��L��tݯ�I��6=����l���+(��g�+��Ͼ����ZW��P;})�[X�>)��C�%�,�@�h�g��*��W*��/r�)@��2�k����”`Q��5″%��5u��z r�#>(��t������=�q+`M�y#���P!�����H�G��c���g�nF�Gc����U���7��?x�{������8�|U�G����$�1^��%�6�;�~���,�x��I �� 8%!���*+֓�s�!�W^n�7��rK
Several vulnerabilities were discovered in spice, a SPICE protocol client and server library. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-0749 Jing Zhao of Red Hat discovered a memory allocation flaw, leading to a heap-based buffer overflow in spice’s smartcard interaction. A user connecting to a guest VM via spice can take […]
Red Hat: 2016:1207-01: glibc: Moderate Advisory Posted by Anthony Pell An update for glibc is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: glibc security update Advisory ID: RHSA-2016:1207-01 Product: […]
Red Hat: 2016:1206-01: jenkins: Moderate Advisory Posted by Anthony Pell An updated Jenkins package and image that includes security fixes are now available for Red Hat OpenShift Enterprise 3.2. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jenkins security update Advisory […]
Debian: 3596-1: spice: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3596-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 06, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : spice CVE ID : CVE-2016-0749 CVE-2016-2150 Several vulnerabilities were discovered in spice, a SPICE protocol client and server library. The Common Vulnerabilities and Exposures project […]
Red Hat: 2016:1205-01: spice: Important Advisory Posted by Anthony Pell An update for spice is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: […]
Red Hat: 2016:1204-01: spice-server: Important Advisory Posted by Anthony Pell An update for spice-server is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: […]
Discovered: June 6, 2016 Updated: June 6, 2016 6:27:43 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Steladok is a Trojan horse that opens a back door on the compromised computer, […]
Discovered: June 6, 2016 Updated: June 6, 2016 6:39:22 PM Type: Trojan Infection Length: 140,288 bytes Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Hookaberg is a Trojan horse that steals information from the compromised computer. Antivirus […]
Discovered: June 5, 2016 Updated: June 7, 2016 7:15:48 AM Type: Trojan Infection Length: 182,784 bytes Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.AX is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to […]
��}�r�Ȓ���P�O�d�x�͒I�-ۧ}Ʒ����c{ P$!�Qj�”��i��m�`#6b���~�|�ff@�HQ�v��}1Tee孲����y������Oǯ^���pM�pW}�0?�#�x�}6�”_��M��w�s��V�
Recently, Microsoft published a new password policy recommendation paper containing advice that flies in the face of conventional wisdom on the subject. Some of the contrarian viewpoints include: Eliminate long password requirements Eliminate complexity requirements Do away with password life expirations Along with this unconventional advice comes a bunch of useful suggestions: Ban common passwords […]
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.0.25. Please see the MariaDB 10.0 Release Notes for further details: For the stable distribution (jessie), these problems have been fixed in version 10.0.25-0+deb8u1. We recommend that you upgrade your mariadb-10.0 packages.
Risk High Date Discovered March 8, 2016 Description Microsoft Windows is prone to a remote code-execution vulnerability. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. Technologies Affected Microsoft Windows 10 for 32-bit Systems Microsoft […]
Gentoo: 201606-04 GnuPG: Multiple vulnerabilities Posted by Anthony Pell Multiple vulnerabilities have been found in GnuPG and libgcrypt, the worst of which may allow a local attacker to obtain confidential key information. – – – – – – – – – – – – – – – – – – – – – – […]
Gentoo: 201606-03 libjpeg-turbo: Multiple vulnerabilities Posted by Anthony Pell Two vulnerabilities have been discovered in libjpeg-turbo, the worse of which could allow remote attackers access to sensitive information. – – – – – – – – – – – – – – – – – – – – – – – – – – […]
Debian: 3595-1: mariadb-10.0: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3595-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mariadb-10.0 CVE ID : CVE-2016-0640 CVE-2016-0641 CVE-2016-0643 CVE-2016-0644 CVE-2016-0646 CVE-2016-0647 CVE-2016-0648 CVE-2016-0649 CVE-2016-0650 CVE-2016-0655 CVE-2016-0666 CVE-2016-0668 Debian Bug : 823325 Several issues have been discovered […]
Gentoo: 201606-02 Puppet Server and Agent: Multiple vulnerabilities Posted by Anthony Pell Multiple vulnerabilities have been found in Puppet Server and Agent, the worst of which could lead to arbitrary code execution. – – – – – – – – – – – – – – – – – – – – – – […]
Gentoo: 201606-01 PuTTY: Multiple vulnerabilities Posted by Anthony Pell Multiple vulnerabilities have been found in PuTTY, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – […]
Debian: 3548-3: samba: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3548-3 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : samba Debian Bug : 821002 822937 The upgrade to Samba 4.2 issued as DSA-3548-1 introduced several upstream regressions and as well a packaging regression causing […]
Debian: 3594-1: chromium-browser: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3594-1 security@debian.org https://www.debian.org/security/ Michael Gilbert June 04, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1696 CVE-2016-1697 CVE-2016-1698 CVE-2016-1699 CVE-2016-1700 CVE-2016-1701 CVE-2016-1702 Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1696 A cross-origin bypass […]
Slackware: 2016-155-01: ntp: Security Update Posted by Anthony Pell New ntp packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. [More Info…] [slackware-security] ntp (SSA:2016-155-01) New ntp packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. Here are the details […]
Debian: 3593-1: libxml2: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3593-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libxml2 CVE ID : CVE-2015-8806 CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-2073 CVE-2016-3627 CVE-2016-3705 CVE-2016-4447 CVE-2016-4449 CVE-2016-4483 Debian Bug : 812807 813613 […]
Red Hat: 2016:1201-01: chromium-browser: Important Advisory Posted by Anthony Pell An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1201-01 Product: Red Hat […]
Ubuntu: 2991-1: nginx vulnerability Posted by Anthony Pell nginx could be made to crash if it received specially crafted networktraffic. ========================================================================== Ubuntu Security Notice USN-2991-1 June 02, 2016 nginx vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: […]
Ubuntu: 2990-1: ImageMagick vulnerabilities Posted by Anthony Pell Several security issues were fixed in ImageMagick. ========================================================================== Ubuntu Security Notice USN-2990-1 June 02, 2016 imagemagick vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several […]
Welcome to this week’s security review, including the story of a DNS hijack that sets the victim’s computer to use specific DNS servers. The post The security review: Crouching Tiger, Hidden DNS appeared first on We Live Security.
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1696 A cross-origin bypass was found in the bindings to extensions. CVE-2016-1697 Mariusz Mlynski discovered a cross-origin bypass in Blink/Webkit. CVE-2016-1698 Rob Wu discovered an information leak. CVE-2016-1699 Gregory Panakkal discovered an issue in the Developer Tools feature. CVE-2016-1700 Rob Wu discovered a use-after-free issue […]
Several vulnerabilities were discovered in libxml2, a library providing support to read, modify and write XML and HTML files. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause a denial-of-service against the application, or potentially the execution of arbitrary code with the […]
There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. MySpace Hack Could Be Largest in Recent History Recently, LeakedSource announced that they had obtained […]
Discovered: June 2, 2016 Updated: June 3, 2016 3:43:31 PM Also Known As: IronGate [FireEye] Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Gatenori is a Trojan horse that may attempt to gain access to […]
The Internet Crime Complaint Center (IC3) has issued a public service announcement warning people about online fraudsters, who are attempting to exploit a recent spate of data breaches that have only just come to light. This includes historic security incidents at Myspace, Tumblr and LinkedIn, for example, which have collectively compromised hundreds of millions of […]
Some people change their smartphone or tablet almost as casually as they change their clothes. They buy and later sell mobile devices without the slightest concern about the information that, one device after another, they keep putting in the hands of total strangers. This article is aimed at all those people, and in it you will be […]
��}ks۸���j���5��H��W�H����ɹy�=g��$��HH�M��u2�:?co��ت������@ |H�e%����# 4��F��@?�������’/��g�_��zl6��E�;sDW&��e���M;��9�T���Ǧu���H��LL�C�m �(�L�p�,(��j� ��.j#sIp�5?&��C[�2~P�s�”f��� �ƙ� ��f��oI�
