Risk Level: Very Low. Type: Trojan.
Debian: 3592-1: nginx: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3592-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : nginx CVE ID : CVE-2016-4450 It was discovered that a NULL pointer dereference in the Nginx code responsible for saving client request bodies to a […]
Working in customer care you get to see every kind of issue computer users can have. This can lead to extremely interesting situations. One particularly noteworthy issue we are seeing is an interesting DNS hijack that sets the victim’s computer to use specific DNS servers. While this attack might not sound that interesting and may […]
If you’re concerned about the security of your organization’s data you should be looking out for elofants on your network. I’ve seen them myself and, if your organization’s network is statistically average, then it is statistically likely to be harboring at least one ELOFANT, otherwise known as: Employee Left Or Fired, Access Not Terminated. While […]
Discovered: June 2, 2016 Updated: June 2, 2016 11:39:43 AM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Uverat.B is a Trojan horse that opens a back door on the compromised computer. It may also […]
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1190-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2016:1190 Issue date: 2016-06-01 CVE Names: […]
Debian: 3591-1: imagemagick: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3591-1 security@debian.org https://www.debian.org/security/ Luciano Bello June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imagemagick CVE ID : CVE-2016-5118 Debian Bug : 825799 Bob Friesenhahn from the GraphicsMagick project discovered a command injection vulnerability in ImageMagick, a program suite […]
Ubuntu: 2989-1: Linux kernel vulnerabilities Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2989-1 June 01, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: […]
Debian: 3590-1: chromium-browser: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3590-1 security@debian.org https://www.debian.org/security/ Michael Gilbert June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1667 CVE-2016-1668 CVE-2016-1669 CVE-2016-1670 CVE-2016-1672 CVE-2016-1673 CVE-2016-1674 CVE-2016-1675 CVE-2016-1676 CVE-2016-1677 CVE-2016-1678 CVE-2016-1679 CVE-2016-1680 CVE-2016-1681 CVE-2016-1682 CVE-2016-1683 CVE-2016-1684 CVE-2016-1685 CVE-2016-1686 CVE-2016-1687 CVE-2016-1688 […]
Ubuntu: 2988-1: LXD vulnerabilities Posted by Anthony Pell Several security issues were fixed in LXD. ========================================================================== Ubuntu Security Notice USN-2988-1 May 31, 2016 lxd vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 Summary: Several security issues were fixed in LXD. Software Description: […]
Ubuntu: 2987-1: GD library vulnerabilities Posted by Anthony Pell The GD library could be made to crash or run programs if it processed aspecially crafted image file. ========================================================================== Ubuntu Security Notice USN-2987-1 May 31, 2016 libgd2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – […]
Ubuntu: 2986-1: dosfstools vulnerabilities Posted by Anthony Pell dosfstools could be made to crash or run programs if it processed aspecially crafted filesystem. ========================================================================== Ubuntu Security Notice USN-2986-1 May 31, 2016 dosfstools vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu […]
��}�r۸���j�aN��D$u�-v���ɜ��r۱��Ηd] I�)�CR�u2�:��_�n�� [�Op�MΓl7R�E�,+���d.�H��ht7�����o�O~�|��Uǣd���]�Ə’ #:��Q����ņ�9�V?Рν�#j��{���{5b/��%����”,P �����O��?b�d��~�ڴ5x��쿳�5�o����i_u.�ZǗ��vB�fK{�b��}�tgo︽��|���l��;~���i�#`�`�^pA”�w�8��4Q H����NkdL]��ja��u���O�SsJ}��ԙD^236���!�������28,�C�����7r:�b��#�7o��d�%#�A���8���^���v(ZؤQ���^��=���q�$Hbb�I���5�T��4v”/,�R ^�h/!S;�XOf� ��6n�x�x.� c$��MtJf8��CF�����$ٗ4C�8>�)��ꍩYЁ��9v�`3��i7[{V�mYc�G�`�>Т![4��1GL/�XH�dƥ�g( �hp����t��q;Jְ��Uo�Y�^�_ׄ�j�̙ �4�:j�ǖ`�W���(�pz[�x�&:k��u��b�$g�0q�$��0�0�v��>�����җ+#ـV���`b=$-:���̊�` �>?$Mb6�A�%h��,B!�i���#�N�*|B�%��W�_o=+6u����:�ܮ�BX��g�^����D,F�gG1g��9�����Ff��c`�H��.�WO�W�XxT’��=AU�e��-n�3ShfaV#/F4�[Or-���”��ax���QJP�6�v���>6���t`O�$�{�L!�b`_zwD}�R!f��ͻ`��M@U��92:h�l7C�h���:�F��>�J�;2�K�$���`��$_1lӁ83���!z�˄F33,P�i��������0*�aC�6��dz wsF#�F����”x5���Y4�9����76����N���=H����-s�l����(]�jPo˜W@_����������>sg$�H�~�6s�|+{�x��Yt����T�Su^�բNp1y3-S�u��V*a�)�Z-������ۮ1���(�@Fo�(TI�97.���(�BzF���;E��J��v/A�Q��9#���3�!�7 `��d1��8���I����3Z�C�R�� �.�;�/8�tYK�Z���S��n�,�=��:,�C���ɘ
There’s a widely held view that our world is full of uber hackers who are too brilliant to stop. Thus, we should fear zero-day attacks because they’re our biggest problem. Nothing could be further from the truth. Most hackers follow the path created by a very few smart ones — and zero days make up […]
It was discovered that a NULL pointer dereference in the Nginx code responsible for saving client request bodies to a temporary file might result in denial of service: Malformed requests could crash worker processes. For the stable distribution (jessie), this problem has been fixed in version 1.6.2-5+deb8u2. For the unstable distribution (sid), this problem has […]
Bob Friesenhahn from the GraphicsMagick project discovered a command injection vulnerability in ImageMagick, a program suite for image manipulation. An attacker with control on input image or the input filename can execute arbitrary commands with the privileges of the user running the application. This update removes the possibility of using pipe (|) in filenames to […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1667 Mariusz Mylinski discovered a cross-origin bypass. CVE-2016-1668 Mariusz Mylinski discovered a cross-origin bypass in bindings to v8. CVE-2016-1669 Choongwoo Han discovered a buffer overflow in the v8 javascript library. CVE-2016-1670 A race condition was found that could cause the renderer process to reuse ids […]
