Hanno Boeck and Marcin Noga discovered multiple vulnerabilities in libarchive; processing malformed archives may result in denial of service or the execution of arbitrary code. For the stable distribution (jessie), these problems have been fixed in version 3.1.2-11+deb8u2. For the testing distribution (stretch), these problems have been fixed in version 3.2.1-1. For the unstable distribution […]
Two vulnerabilities have been discovered in the server for the Tryton application platform, which may result in information disclosure of password hashes or file contents. For the stable distribution (jessie), these problems have been fixed in version 3.4.0-3+deb8u2. For the unstable distribution (sid), these problems have been fixed in version 4.0.4-1. We recommend that you […]
Red Hat: 2016:1781-01: rh-postgresql94-postgresql: Moderate Advisory Posted by Anthony Pell An update for rh-postgresql94-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-postgresql94-postgresql security update Advisory ID: RHSA-2016:1781-01 Product: Red Hat Software Collections […]
Debian: 3657-1: libarchive: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3657-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 30, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libarchive CVE ID : CVE-2015-8916 CVE-2015-8917 CVE-2015-8919 CVE-2015-8920 CVE-2015-8921 CVE-2015-8922 CVE-2015-8923 CVE-2015-8925 CVE-2015-8926 CVE-2015-8928 CVE-2015-8930 CVE-2015-8931 CVE-2015-8932 CVE-2015-8933 CVE-2015-8934 CVE-2016-4300 CVE-2016-4302 CVE-2016-4809 CVE-2016-5844 Hanno Boeck […]
Debian: 3656-1: tryton-server: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3656-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 30, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : tryton-server CVE ID : CVE-2016-1241 CVE-2016-1242 Two vulnerabilities have been discovered in the server for the Tryton application platform, which may result in information disclosure […]
Ubuntu: 3070-2: Linux kernel (Raspberry Pi 2) vulnerabilities Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3070-2 August 30, 2016 linux-raspi2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS Summary: Several security issues were fixed in the […]
Risk Level: Very Low. Type: Trojan.
Discovered: August 30, 2016 Updated: August 30, 2016 10:15:13 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Atmoripper is a Trojan horse for Automatic Teller Machines (ATMs) that allows an attacker to issue commands […]
We all know how much you enjoy playing – socially, professionally or casually – video games, which is why we want to take this opportunity to share more information about safe online gaming. Previously we have discussed how to protect yourself while playing, with professional online gamers offering advice based on their knowledge and experience as […]
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Slackware: 2016-242-01: kernel: Security Update Posted by Anthony Pell New kernel packages are available for Slackware 14.1 to fix a security issue. [More Info…] [slackware-security] kernel (SSA:2016-242-01) New kernel packages are available for Slackware 14.1 to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ patches/packages/linux-3.10.103/*: Upgraded. A flaw […]
Ubuntu: 3070-1: Linux kernel vulnerabilities Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3070-1 August 29, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: […]
Ubuntu: 3072-2: Linux kernel (OMAP4) vulnerabilities Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3072-2 August 29, 2016 linux-ti-omap4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software […]
Ubuntu: 3071-1: Linux kernel vulnerabilities Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3071-1 August 29, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: […]
Risk Level: Very Low. Type: Trojan, Worm.
Risk Level: Very Low. Type: Trojan, Worm.
VMWorld this year feels like a confessional – operators coming clean about their lack of data visibility, heads hung in shame. The reasons are many, but foremost is workload – once you provision a data volume you never have time to get back to it and ask why, or update it really to mesh with […]
Last month ESET researchers wrote an article about a new OS X malware called OSX/Keydnap, built to steal the content of OS X’s keychain and maintain a permanent backdoor. At that time of the analysis, it was unclear how victims were exposed to OSX/Keydnap. To quote the original article: “It could be through attachments in […]
If you’ve ever hacked for a living — wearing a white hat, I hope — you probably can’t stand the unrealistic light most shows and movies shine on hacking and hackers. On the big and small screens, supergenius hackers enjoy instantaneous success and always manage to stay one step ahead of the law. Typically they’re […]
Discovered: August 29, 2016 Updated: August 30, 2016 12:01:53 PM Type: Trojan Infection Length: 39,936 bytes Systems Affected: Windows 2000, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP Trojan.Odinaff is a Trojan horse that opens a back door on the compromised computer. Antivirus Protection Dates Initial […]
Windows 10 has been notorious about automatically installing updates on users’ machines and now there is a ransomware that aims to capitalize on it. The new ransomware, Fantom, is based on the EDA2 open-source ransomware project on GitHub called hidden tear that’s recently been abandoned. Fantom behind the scenes In an attempt to conceal malicious intention, […]
Debian: 3655-1: mupdf: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3655-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 26, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mupdf CVE ID : CVE-2016-6265 CVE-2016-6525 Debian Bug : 832031 833417 Two vulnerabilities were discovered in MuPDF, a lightweight PDF viewer. The Common Vulnerabilities and […]
An update for java-1.6.0-openjdk is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: java-1.6.0-openjdk security update Advisory ID: RHSA-2016:1776-01 Product: Red Hat Enterprise […]
Two vulnerabilities were discovered in MuPDF, a lightweight PDF viewer. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-6265 Marco Grassi discovered a use-after-free vulnerability in MuPDF. An attacker can take advantage of this flaw to cause an application crash (denial-of-service), or potentially to execute arbitrary code with the privileges of the user […]
Alexander Sulfrian discovered a buffer overflow in the yy_get_next_buffer() function generated by Flex, which may result in denial of service and potentially the execution of code if operating on data from untrusted sources. Affected applications need to be rebuild. bogofilter will be rebuild against the updated flex in a followup update. Further affected applications should […]
This updates fixes many vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service or the execution of arbitrary code if malformed TIFF, WPG, RLE, RAW, PSD, Sun, PICT, VIFF, HDR, Meta, Quantum, PDB, DDS, DCM, EXIF, RGF or BMP files are processed. For […]
Andrew Carpenter of Critical Juncture discovered a cross-site scripting vulnerability affecting Action View in rails, a web application framework written in Ruby. Text declared as HTML safe will not have quotes escaped when used as attribute values in tag helpers. For the stable distribution (jessie), this problem has been fixed in version 2:4.1.8-1+deb8u4. For the […]
This week’s Threat Recap covers everything from, ‘Fantom’, the new ransomware that disguises itself as a Windows update, to hackers using Facebook photos to trick facial-recognition logins. Decryption Keys Released for Wildfire Ransomware Recently, researchers have announced the public availability of decryption keys for users affected by the Wildfire ransomware variant. This particular variant did focused […]
Debian: 3654-1: quagga: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3654-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond August 26, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : quagga CVE ID : CVE-2016-4036 CVE-2016-4049 Debian Bug : 822787 835223 Two vulnerabilities were discovered in quagga, a BGP/OSPF/RIP routing daemon. CVE-2016-4036 Tamás Németh discovered […]
Debian: 3653-1: flex: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3653-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 25, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : flex CVE ID : CVE-2016-6354 Debian Bug : 832768 Alexander Sulfrian discovered a buffer overflow in the yy_get_next_buffer() function generated by Flex, which may result […]
Debian: 3652-1: imagemagick: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3652-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 25, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imagemagick CVE ID : CVE-2016-4562 CVE-2016-4563 CVE-2016-4564 CVE-2016-5010 CVE-2016-5687 CVE-2016-5688 CVE-2016-5689 CVE-2016-5690 CVE-2016-5691 CVE-2016-5841 CVE-2016-5842 CVE-2016-6491 Debian Bugs : 832885 832887 832888 832968 833003 832474 […]
Debian: 3651-1: rails: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3651-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 25, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : rails CVE ID : CVE-2016-6316 Debian Bug : 834155 Andrew Carpenter of Critical Juncture discovered a cross-site scripting vulnerability affecting Action View in rails, a […]
