Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Red Hat: 2016:1609-01: php: Moderate Advisory Posted by Anthony Pell    An update for php is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: […]

Debian: 3647-1: icedove: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3647-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 11, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : icedove CVE ID : CVE-2016-2818 Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors […]

Red Hat: 2016:1605-01: Red Hat OpenShift Enterprise: Moderate Advisory Posted by Anthony Pell    An update is now available for Red Hat OpenShift Enterprise 3.1 and Red Hat OpenShift Enterprise 3.2. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift […]

Red Hat: 2016:1603-01: mariadb55-mariadb: Important Advisory Posted by Anthony Pell    An update for mariadb55-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: mariadb55-mariadb security update Advisory ID: RHSA-2016:1603-01 Product: Red Hat Software Collections […]

An update for mariadb is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: mariadb security update Advisory ID: RHSA-2016:1602-01 Product: Red Hat Enterprise Linux […]

Red Hat: 2016:1604-01: rh-mariadb100-mariadb: Important Advisory Posted by Anthony Pell    An update for rh-mariadb100-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: rh-mariadb100-mariadb security update Advisory ID: RHSA-2016:1604-01 Product: Red Hat Software Collections […]

Multiple vulnerabilities were discovered in the dissectors for NDS, PacketBB, WSP, MMSE, RLC, LDSS, RLC and OpenFlow, which could result in denial of service or the execution of arbitrary code. For the stable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u8. For the testing distribution (stretch), these problems have been fixed in version […]

Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service. For the stable distribution (jessie), this problem has been fixed in version 1:45.2.0-1~deb8u1. For the testing distribution (stretch), this problem has been fixed […]

Several vulnerabilities have been found in PostgreSQL-9.4, a SQL database system. CVE-2016-5423 Karthikeyan Jambu Rajaraman discovered that nested CASE-WHEN expressions are not properly evaluated, potentially leading to a crash or allowing to disclose portions of server memory. CVE-2016-5424 Nathan Bossart discovered that special characters in database and role names are not properly handled, potentially leading […]

DEF CON 24: US government retains dozens, not thousands, of zero-days
Vulnerability Exposes 900M Android Devices-and Fixing Them Won’t Be Easy
Black Hat and DEF CON: The song remains the same

Tobias Stoeckmann discovered that cache files are insufficiently validated in fontconfig, a generic font configuration library. An attacker can trigger arbitrary free() calls, which in turn allows double free attacks and therefore arbitrary code execution. In combination with setuid binaries using crafted cache files, this could allow privilege escalation. For the stable distribution (jessie), this […]

Red Hat: 2016:1582-01: nodejs010-nodejs-minimatch: Moderate Advisory Posted by Anthony Pell    An update for nodejs010-nodejs-minimatch is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: nodejs010-nodejs-minimatch security update Advisory ID: RHSA-2016:1582-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1583-01: rh-nodejs4-nodejs-minimatch: Moderate Advisory Posted by Anthony Pell    An update for rh-nodejs4-nodejs-minimatch is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-nodejs4-nodejs-minimatch security update Advisory ID: RHSA-2016:1583-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1581-01: kernel: Important Advisory Posted by Anthony Pell    An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2016:1581-01 Product: […]

Red Hat: 2016:1580-01: chromium-browser: Important Advisory Posted by Anthony Pell    An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1580-01 Product: Red Hat […]

Debian: 3645-1: chromium-browser: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3645-1 security@debian.org https://www.debian.org/security/ Michael Gilbert August 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-5139 CVE-2016-5140 CVE-2016-5141 CVE-2016-5142 CVE-2016-5143 CVE-2016-5144 Several vulnerabilites have been discovered in the chromium web browser. CVE-2016-5139 GiWan Go discovered a […]

Debian: 3644-1: fontconfig: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3644-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 08, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : fontconfig CVE ID : CVE-2016-5384 Debian Bug : 833570 Tobias Stoeckmann discovered that cache files are insufficiently validated in fontconfig, a generic font configuration library. […]

Slackware: 2016-219-03: openssh: Security Update Posted by Anthony Pell    New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] openssh (SSA:2016-219-03) New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. Here are […]

Slackware: 2016-219-01: curl: Security Update Posted by Anthony Pell    New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] curl (SSA:2016-219-01) New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. Here are […]

Slackware: 2016-219-02: mozilla-firefox: Security Update Posted by Anthony Pell    New mozilla-firefox packages are available for Slackware 14.1 and 14.2 to fix security issues. [More Info…] [slackware-security] mozilla-firefox (SSA:2016-219-02) New mozilla-firefox packages are available for Slackware 14.1 and 14.2 to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +————————–+ patches/packages/mozilla-firefox-45.3.0esr-i586-1_slack14.2.txz: Upgraded. […]

Slackware: 2016-219-04: stunnel: Security Update Posted by Anthony Pell    New stunnel packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] stunnel (SSA:2016-219-04) New stunnel packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. Here are […]

Debian: 3643-1: kde4libs: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3643-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 06, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : kde4libs CVE ID : CVE-2016-6232 Debian Bug : 832620 Andreas Cord-Landwehr discovered that kde4libs, the core libraries for all KDE 4 applications, do not properly […]

Debian: 3642-1: lighttpd: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3642-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond August 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : lighttpd CVE ID : CVE-2016-1000212 Debian Bug : 832571 Dominic Scheirlinck and Scott Geary of Vend reported insecure behavior in the lighttpd web server. Lighttpd […]

Torrentz Has Died, But It Won’t Take Torrenting With It
Hackers Fool Tesla S’s Autopilot to Hide and Spoof Obstacles
Google Domain Enables HSTS Protection

Andreas Cord-Landwehr discovered that kde4libs, the core libraries for all KDE 4 applications, do not properly handle the extraction of archives with “../” in the file paths. A remote attacker can take advantage of this flaw to overwrite files outside of the extraction folder, if a user is tricked into extracting a specially crafted archive. […]

Ubuntu: 3046-1: LibreOffice vulnerability Posted by Anthony Pell    LibreOffice could be made to crash or run programs as your login if itopened a specially crafted file. ========================================================================== Ubuntu Security Notice USN-3046-1 August 04, 2016 libreoffice vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: LibreOffice […]

Never Trust a Found USB Drive, Black Hat Demo Shows Why

Debian: 3641-1: openjdk-7: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3641-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 04, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openjdk-7 CVE ID : CVE-2016-3458 CVE-2016-3500 CVE-2016-3508 CVE-2016-3550 CVE-2016-3606 Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in […]

In DARPA challenge, smart machines compete to fend off cyberattacks

Red Hat: 2016:1573-01: squid: Moderate Advisory Posted by Anthony Pell    An update for squid is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: […]

Hacking Hotel Keys and Point of Sale Systems at DEFCON

Debian: 3640-1: firefox-esr: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3640-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : firefox-esr CVE ID : CVE-2016-2830 CVE-2016-2836 CVE-2016-2837 CVE-2016-2838 CVE-2016-5252 CVE-2016-5254 CVE-2016-5258 CVE-2016-5259 CVE-2016-5262 CVE-2016-5263 CVE-2016-5264 CVE-2016-5265 Multiple security issues have been found in the Mozilla […]

Debian: 3639-1: wordpress: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3639-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wordpress CVE ID : CVE-2015-8834 CVE-2016-5832 CVE-2016-5834 CVE-2016-5835 CVE-2016-5837 CVE-2016-5838 CVE-2016-5839 Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote […]

Researchers Bypass Chip-and-Pin Protections at Black Hat

Debian: 3638-1: curl: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3638-1 security@debian.org https://www.debian.org/security/ Alessandro Ghedini August 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : curl CVE ID : CVE-2016-5419 CVE-2016-5420 CVE-2016-5421 Several vulnerabilities were discovered in cURL, an URL transfer library: CVE-2016-5419 Bru Rom discovered that libcurl would attempt […]

Frequent password changes are the enemy of security, FTC technologist says

Multiple security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors, buffer overflows and other implementation errors may lead to the execution of arbitrary code, cross-site scriping, information disclosure and bypass of the same-origin policy. For the stable distribution (jessie), these problems have been fixed in version 45.3.0esr-1~deb8u1. For the […]

An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2016:1551-01 Product: Red Hat Enterprise […]

Multiple security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors, buffer overflows and other implementation errors may lead to the execution of arbitrary code, cross-site scriping, information disclosure and bypass of the same-origin policy. For the stable distribution (jessie), these problems have been fixed in version 45.3.0esr-1~deb8u1. For the […]

Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote attackers to compromise a site via cross-site scripting, bypass restrictions, obtain sensitive revision-history information, or mount a denial of service. For the stable distribution (jessie), these problems have been fixed in version 4.1+dfsg-1+deb8u9. We recommend that you upgrade your wordpress packages.

Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote attackers to compromise a site via cross-site scripting, bypass restrictions, obtain sensitive revision-history information, or mount a denial of service. For the stable distribution (jessie), these problems have been fixed in version 4.1+dfsg-1+deb8u9. We recommend that you upgrade your wordpress packages.

Hackers Hijack a Big Rig Truck’s Accelerator and Brakes

An update for ntp is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ntp security update Advisory ID: RHSA-2016:1552-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1552.html Issue date: 2016-08-03 CVE […]

Several vulnerabilities were discovered in cURL, an URL transfer library: CVE-2016-5419 Bru Rom discovered that libcurl would attempt to resume a TLS session even if the client certificate had changed. CVE-2016-5420 It was discovered that libcurl did not consider client certificates when reusing TLS connections. CVE-2016-5421 Marcelo Echeverria and Fernando Muñoz discovered that libcurl was […]

Several vulnerabilities were discovered in cURL, an URL transfer library: CVE-2016-5419 Bru Rom discovered that libcurl would attempt to resume a TLS session even if the client certificate had changed. CVE-2016-5420 It was discovered that libcurl did not consider client certificates when reusing TLS connections. CVE-2016-5421 Marcelo Echeverria and Fernando Muñoz discovered that libcurl was […]

Red Hat: 2016:1541-03: kernel-rt: Important Advisory Posted by Anthony Pell    An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: […]

Red Hat: 2016:1538-01: golang: Moderate Advisory Posted by Anthony Pell    An update for golang is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: […]

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1704 The chrome development team found and fixed various issues during internal auditing. CVE-2016-1705 The chrome development team found and fixed various issues during internal auditing. CVE-2016-1706 Pinkie Pie discovered a way to escape the Pepper Plugin API sandbox. CVE-2016-1707 xisigr discovered a URL spoofing […]

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1704 The chrome development team found and fixed various issues during internal auditing. CVE-2016-1705 The chrome development team found and fixed various issues during internal auditing. CVE-2016-1706 Pinkie Pie discovered a way to escape the Pepper Plugin API sandbox. CVE-2016-1707 xisigr discovered a URL spoofing […]

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1539-01 Product: Red […]

Emilien Gaspar discovered that collectd, a statistics collection and monitoring daemon, incorrectly processed incoming network packets. This resulted in a heap overflow, allowing a remote attacker to either cause a DoS via application crash, or potentially execute arbitrary code. Additionally, security researchers at Columbia University and the University of Virginia discovered that collectd failed to […]

Emilien Gaspar discovered that collectd, a statistics collection and monitoring daemon, incorrectly processed incoming network packets. This resulted in a heap overflow, allowing a remote attacker to either cause a DoS via application crash, or potentially execute arbitrary code. Additionally, security researchers at Columbia University and the University of Virginia discovered that collectd failed to […]

It was discovered that redis, a persistent key-value database, did not properly protect redis-cli history files: they were created by default with world-readable permissions. Users and systems administrators may want to proactively change permissions on existing ~/rediscli_history files, instead of waiting for the updated redis-cli to do so the next time it is run. For […]

It was discovered that redis, a persistent key-value database, did not properly protect redis-cli history files: they were created by default with world-readable permissions. Users and systems administrators may want to proactively change permissions on existing ~/rediscli_history files, instead of waiting for the updated redis-cli to do so the next time it is run. For […]

Two use-after-free vulnerabilities were discovered in DBD::mysql, a Perl DBI driver for the MySQL database server. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using DBD::mysql (application crash), or potentially to execute arbitrary code with the privileges of the user running the application. For the stable distribution […]

Red Hat: 2016:1532-02: kernel-rt: Important Advisory Posted by Anthony Pell    An update for kernel-rt is now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: […]

New attack bypasses HTTPS protection on Macs, Windows, and Linux

Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-8338 Julien Grall discovered that Xen on ARM was susceptible to denial of service via long running memory operations. CVE-2016-4480 Jan Beulich discovered that incorrect page table handling could result in privilege escalation inside a Xen […]

Debian: 3633-1: xen: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3633-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 27, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xen CVE ID : CVE-2015-8338 CVE-2016-4480 CVE-2016-4962 CVE-2016-5242 CVE-2016-6258 Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies […]

Debian: 3632-1: mariadb-10.0: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3632-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 27, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mariadb-10.0 CVE ID : CVE-2016-3477 CVE-2016-3521 CVE-2016-3615 CVE-2016-5440 Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB […]

Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. The vulnerabilities are addressed by upgrading PHP to the new upstream version 5.6.24, which includes additional bug fixes. Please refer to the upstream changelog for more information: https://php.net/ChangeLog-5.php#5.6.24 For the stable distribution (jessie), these problems have been fixed in […]

Secunia Research at Flexera Software discovered an integer overflow vulnerability within the _gdContributionsAlloc() function in libgd2, a library for programmatic graphics creation and manipulation. A remote attacker can take advantage of this flaw to cause a denial-of-service against an application using the libgd2 library. For the stable distribution (jessie), this problem has been fixed in […]

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: java-1.7.0-openjdk security update Advisory ID: RHSA-2016:1504-01 Product: Red Hat Enterprise […]

Ubuntu: 3043-1: OpenJDK 8 vulnerabilities Posted by Anthony Pell    Several security issues were fixed in OpenJDK 8. ========================================================================== Ubuntu Security Notice USN-3043-1 July 27, 2016 openjdk-8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS Summary: Several security issues were fixed in OpenJDK 8. Software Description: […]

Debian: 3631-1: php5: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3631-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 26, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : php5 CVE ID : CVE-2016-5385 CVE-2016-5399 CVE-2016-6289 CVE-2016-6290 CVE-2016-6291 CVE-2016-6292 CVE-2016-6294 CVE-2016-6295 CVE-2016-6296 CVE-2016-6297 Several vulnerabilities were found in PHP, a general-purpose scripting language commonly […]

Debian: 3630-1: libgd2: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3630-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 26, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libgd2 CVE ID : CVE-2016-6207 Secunia Research at Flexera Software discovered an integer overflow vulnerability within the _gdContributionsAlloc() function in libgd2, a library for programmatic […]

An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:1489-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1489.html […]

The KickassTorrents Case Could Be Huge
Over 100 suspicious, snooping Tor nodes discovered
Schneier: Next president may face IoT cyberattack that causes people to die
Linux 4.7 now out with enhanced security and advanced graphics support

Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.0.26. Please see the MariaDB 10.0 Release Notes for further details: https://mariadb.com/kb/en/mariadb/mariadb-10026-release-notes/ For the stable distribution (jessie), these problems have been fixed in version 10.0.26-0+deb8u1. For the unstable distribution (sid), these problems have […]

Several vulnerabilities were discovered in the Network Time Protocol daemon and utility programs: CVE-2015-7974 Matt Street discovered that insufficient key validation allows impersonation attacks between authenticated peers. CVE-2015-7977 CVE-2015-7978 Stephen Gray discovered that a NULL pointer dereference and a buffer overflow in the handling of ntpdc reslist commands may result in denial of service. CVE-2015-7979 […]

Red Hat: 2016:1487-01: samba4: Moderate Advisory Posted by Anthony Pell    An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: […]

An update for samba is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: samba security and bug fix update Advisory ID: RHSA-2016:1486-01 Product: […]

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1485-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1485.html Issue date: 2016-07-26 CVE Names: […]

Debian: 3629-1: ntp: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3629-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 25, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : ntp CVE ID : CVE-2015-7974 CVE-2015-7977 CVE-2015-7978 CVE-2015-7979 CVE-2015-8138 CVE-2015-8158 CVE-2016-1547 CVE-2016-1548 CVE-2016-1550 CVE-2016-2516 CVE-2016-2518 Several vulnerabilities were discovered in the Network Time Protocol daemon […]

Debian: 3628-1: perl: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3628-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 25, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : perl CVE ID : CVE-2016-1238 CVE-2016-6185 Debian Bug : 829578 Multiple vulnerabilities were discovered in the implementation of the Perl programming language. The Common Vulnerabilities […]

Hackers create Safe Skies TSA master key from scratch, release designs
Malicious computers caught snooping on Tor-anonymized Dark Web sites
Snowden Designs a Device to Warn if Your iPhone’s Radios Are Snitching

Several vulnerabilities have been fixed in phpMyAdmin, the web-based MySQL administration interface. CVE-2016-1927 The suggestPassword function relied on a non-secure random number generator which makes it easier for remote attackers to guess generated passwords via a brute-force approach. CVE-2016-2039 CSRF token values were generated by a non-secure random number generator, which allows remote attackers to […]

An update for mariadb55-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: mariadb55-mariadb security update Advisory ID: RHSA-2016:1481-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1481.html Issue date: 2016-07-25 CVE Names: CVE-2015-4792 CVE-2015-4802 CVE-2015-4815 […]

An update for mysql55-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: mysql55-mysql security update Advisory ID: RHSA-2016:1480-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1480.html Issue date: 2016-07-25 CVE Names: CVE-2015-4792 CVE-2015-4802 CVE-2015-4815 […]

Debian: 3627-1: phpmyadmin: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3627-1 security@debian.org https://www.debian.org/security/ Thijs Kinkhorst July 24, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : phpmyadmin CVE ID : CVE-2016-1927 CVE-2016-2039 CVE-2016-2040 CVE-2016-2041 CVE-2016-2560 CVE-2016-2561 CVE-2016-5099 CVE-2016-5701 CVE-2016-5705 CVE-2016-5706 CVE-2016-5731 CVE-2016-5733 CVE-2016-5739 Several vulnerabilities have been fixed in phpMyAdmin, the […]

Debian: 3626-1: openssh: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3626-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 24, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openssh CVE ID : CVE-2016-6210 Debian Bug : 831902 Eddie Harari reported that the OpenSSH SSH daemon allows user enumeration through timing differences when trying […]

Slackware: 2016-204-01: bind: Security Update Posted by Anthony Pell    New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…] [slackware-security] bind (SSA:2016-204-01) New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. […]

CVE-2016-1238 John Lightsey and Todd Rinaldo reported that the opportunistic loading of optional modules can make many programs unintentionally load code from the current working directory (which might be changed to another directory without the user realising) and potentially leading to privilege escalation, as demonstrated in Debian with certain combinations of installed packages. The problem […]

Eddie Harari reported that the OpenSSH SSH daemon allows user enumeration through timing differences when trying to authenticate users. When sshd tries to authenticate a non-existing user, it will pick up a fixed fake password structure with a hash based on the Blowfish algorithm. If real users passwords are hashed using SHA256/SHA512, then a remote […]

5 ‘Mr. Robot’ Hacks That Could Happen in Real Life
Firefox sets kill-Flash schedule

Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.50. Please see the MySQL 5.5 Release Notes and Oracle’s Critical Patch Update advisory for further details: For the stable distribution (jessie), these problems have been fixed in version 5.5.50-0+deb8u1. We recommend that […]

Debian: 3625-1: squid3: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3625-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond July 22, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : squid3 CVE ID : CVE-2016-4051 CVE-2016-4052 CVE-2016-4053 CVE-2016-4054 CVE-2016-4554 CVE-2016-4555 CVE-2016-4556 Debian Bug : 823968 Several security issues have been discovered in the Squid caching […]

Slackware: 2016-203-01: gimp: Security Update Posted by Anthony Pell    New gimp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…] [slackware-security] gimp (SSA:2016-203-01) New gimp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the […]

Slackware: 2016-203-02: php: Security Update Posted by Anthony Pell    New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] php (SSA:2016-203-02) New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 […]

Debian: 3624-1: mysql-5.5: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3624-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 21, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mysql-5.5 CVE ID : CVE-2016-3477 CVE-2016-3521 CVE-2016-3615 CVE-2016-5440 Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL […]