Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Updated kernel packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux 7 Extended Update Support. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security and bug fix update Advisory ID: RHSA-2016:1395-01 Product: Red Hat […]

NSA Labels Privacy-Centric Internet Users As Extremists
HTTPS crypto’s days are numbered. Here’s how Google wants to save it
Pirate swarms at risk from new patent
Hacking A Penetration Tester

An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2016:1392-01 Product: Red Hat Enterprise […]

Gentoo: 201607-02 libpcre: Multiple Vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in libpcre, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-01 Squid: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Squid, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – […]

Slackware: 2016-189-01: samba: Security Update Posted by Anthony Pell    New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] samba (SSA:2016-189-01) New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 […]

Debian: 3617-1: horizon: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3617-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 06, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : horizon CVE ID : CVE-2015-3219 CVE-2016-4428 Two cross-site scripting vulnerabilities have been found in Horizon, a web application to control an OpenStack cloud. For the […]

Two cross-site scripting vulnerabilities have been found in Horizon, a web application to control an OpenStack cloud. For the stable distribution (jessie), these problems have been fixed in version 2014.1.3-7+deb8u2. For the testing distribution (stretch), these problems have been fixed in version 3:9.0.1-2. For the unstable distribution (sid), these problems have been fixed in version […]

Android’s full-disk encryption just got much weaker-here’s why
8 Reasons You Need a Security Penetration Test
5 Ways To Think Like A Hacker

Slackware: 2016-187-01: mozilla-thunderbird: Security Update Posted by Anthony Pell    New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and – -current to fix security issues. [More Info…] [slackware-security] mozilla-thunderbird (SSA:2016-187-01) New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and – -current to fix security issues. Here are the details from the Slackware 14.2 […]

Debian: 3616-1: linux: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3616-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 04, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : linux CVE ID : CVE-2014-9904 CVE-2016-5728 CVE-2016-5828 CVE-2016-5829 CVE-2016-6130 Debian Bug : 828914 Several vulnerabilities have been discovered in the Linux kernel that may lead […]

Red Hat: 2016:1378-01: openstack-ironic: Moderate Advisory Posted by Anthony Pell    An update for openstack-ironic is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-ironic security update Advisory ID: RHSA-2016:1378-01 Product: Red Hat […]

Red Hat: 2016:1377-01: openstack-ironic: Moderate Advisory Posted by Anthony Pell    An update for openstack-ironic is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-ironic security update Advisory ID: […]

Debian: 3614-1: tomcat7: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3614-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : tomcat7 CVE ID : CVE-2016-3092 The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it […]

Debian: 3615-1: wireshark: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3615-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wireshark CVE ID : CVE-2016-5350 CVE-2016-5351 CVE-2016-5353 CVE-2016-5354 CVE-2016-5355 CVE-2016-5356 CVE-2016-5357 CVE-2016-5359 Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and […]

Debian: 3613-1: libvirt: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3613-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libvirt CVE ID : CVE-2016-5008 Vivian Zhang and Christoph Anton Mitterer discovered that setting an empty VNC password does not work as documented in Libvirt, […]

Debian: 3612-1: gimp: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3612-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : gimp CVE ID : CVE-2016-4994 Debian Bug : 828179 Shmuel H discovered that GIMP, the GNU Image Manipulation Program, is prone to a use-after-free vulnerability […]

Java Deserialization attacks on JBoss Middleware

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. CVE-2014-9904 It was discovered that the snd_compress_check_input function used in the ALSA subsystem does not properly check for an integer overflow, allowing a local user to cause a denial of service. CVE-2016-5728 Pengfei […]

Shmuel H discovered that GIMP, the GNU Image Manipulation Program, is prone to a use-after-free vulnerability in the channel and layer properties parsing process when loading a XCF file. An attacker can take advantage of this flaw to potentially execute arbitrary code with the privileges of the user running GIMP if a specially crafted XCF […]

Vivian Zhang and Christoph Anton Mitterer discovered that setting an empty VNC password does not work as documented in Libvirt, a virtualisation abstraction library. When the password on a VNC server is set to the empty string, authentication on the VNC server will be disabled, allowing any user to connect, despite the documentation declaring that […]

The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it easy to add robust, high-performance, file upload capability to servlets and web applications. A remote attacker can take advantage of this flaw by sending file upload requests that cause the HTTP server using the Apache […]

Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP, SPOOLS, IEEE 802.11, UMTS FP, USB, Toshiba, CoSine, NetScreen, WBXML which could result in denial of service or potentially the execution of arbitrary code. For the stable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u7. For the testing distribution […]

Brandon Perry discovered that xerces-c, a validating XML parser library for C++, fails to successfully parse a DTD that is deeply nested, causing a stack overflow. A remote unauthenticated attacker can take advantage of this flaw to cause a denial of service against applications using the xerces-c library. Additionally this update includes an enhancement to […]

Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in information disclosure, the bypass of CSRF protections, bypass of the SecurityManager or denial of service. For the stable distribution (jessie), these problems have been fixed in version 8.0.14-1+deb8u2. For the unstable distribution (sid), these problems have been fixed […]

Aleksandar Nikolic discovered that missing input sanitising in the RTF parser in Libreoffice may result in the execution of arbitrary code if a malformed documented is opened. For the stable distribution (jessie), this problem has been fixed in version 1:4.3.3-2+deb8u5. For the testing distribution (stretch), this problem has been fixed in version 1:5.1.4~rc1-1. For the […]

Debian: 3611-1: libcommons-fileupload-java: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3611-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 30, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libcommons-fileupload-java CVE ID : CVE-2016-3092 The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it […]

Ubuntu: 3022-1: LibreOffice vulnerability Posted by Anthony Pell    LibreOffice could be made to crash or run programs as your login if itopened a specially crafted file. ========================================================================== Ubuntu Security Notice USN-3022-1 June 29, 2016 libreoffice vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu […]

Debian: 3610-1: xerces-c: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3610-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xerces-c CVE ID : CVE-2016-4463 Debian Bug : 828990 Brandon Perry discovered that xerces-c, a validating XML parser library for C++, fails to successfully parse […]

Debian: 3609-1: tomcat8: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3609-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : tomcat8 CVE ID : CVE-2015-5174 CVE-2015-5345 CVE-2015-5346 CVE-2015-5351 CVE-2016-0706 CVE-2016-0714 CVE-2016-0763 CVE-2016-3092 Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, […]

Debian: 3608-1: libreoffice: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3608-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libreoffice CVE ID : CVE-2016-4324 Aleksandar Nikolic discovered that missing input sanitising in the RTF parser in Libreoffice may result in the execution of arbitrary […]

SSH Keys
General tips for working with iptables
Install DenyHosts on a CentOS box

The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it easy to add robust, high-performance, file upload capability to servlets and web applications. A remote attacker can take advantage of this flaw by sending file upload requests that cause the HTTP server using the Apache […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3607-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 28, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : linux CVE ID : CVE-2015-7515 CVE-2016-0821 CVE-2016-1237 CVE-2016-1583 CVE-2016-2117 CVE-2016-2143 CVE-2016-2184 CVE-2016-2185 CVE-2016-2186 CVE-2016-2187 CVE-2016-3070 CVE-2016-3134 CVE-2016-3136 CVE-2016-3137 CVE-2016-3138 CVE-2016-3140 CVE-2016-3156 CVE-2016-3157 CVE-2016-3672 CVE-2016-3951 CVE-2016-3955 CVE-2016-3961 CVE-2016-4470 CVE-2016-4482 CVE-2016-4485 CVE-2016-4486 CVE-2016-4565 CVE-2016-4569 CVE-2016-4578 CVE-2016-4580 […]

Ubuntu: 3021-1: Linux kernel vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3021-1 June 27, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: […]

Ubuntu: 3021-2: Linux kernel (OMAP4) vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3021-2 June 27, 2016 linux-ti-omap4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software […]

Gentoo: 201606-19 kwalletd: Information disclosure Posted by Anthony Pell    Kwalletd password stores are vulnerable to codebook attacks. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – Gentoo […]

Multiple vulnerabilities have been found in IcedTea allowing remote attackers to affect confidentiality, integrity, and availability through various vectors. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Ubuntu: 3018-1: Linux kernel vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3018-1 June 27, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: […]

Ubuntu: 3020-1: Linux kernel (Vivid HWE) vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3020-1 June 27, 2016 linux-lts-vivid vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. […]

Ubuntu: 3019-1: Linux kernel (Utopic HWE) vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3019-1 June 27, 2016 linux-lts-utopic vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. […]

Ubuntu: 3018-2: Linux kernel (Trusty HWE) vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3018-2 June 27, 2016 linux-lts-trusty vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. […]

Ubuntu: 3016-4: Linux kernel (Xenial HWE) vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3016-4 June 27, 2016 linux-lts-xenial vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. […]

Ubuntu: 3017-1: Linux kernel vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3017-1 June 27, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – […]

Ubuntu: 3017-3: Linux kernel (Wily HWE) vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-3017-3 June 27, 2016 linux-lts-wily vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. […]

(Update) 800-pound Comodo tries to trademark upstart rival’s “Let’s Encrypt” name

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. CVE-2015-7515, CVE-2016-2184, CVE-2016-2185, CVE-2016-2186, CVE-2016-2187, CVE-2016-3136, CVE-2016-3137, CVE-2016-3138, CVE-2016-3140 Ralf Spenneberg of OpenSource Security reported that various USB drivers do not sufficiently validate USB descriptors. This allowed a physically present user with a […]

It was discovered that pdfbox, a PDF library for Java, was susceptible to XML External Entity attacks. For the stable distribution (jessie), this problem has been fixed in version 1:1.8.7+dfsg-1+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 1:1.8.12-1. For the unstable distribution (sid), this problem has been fixed in version […]

A Bug in Chrome Makes It Easy to Pirate Movies
Let’s Encrypt accuses Comodo of trying to swipe its brand

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security, bug fix, and enhancement update Advisory ID: RHSA-2016:1301-01 Product: […]

An update for ocaml is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ocaml security update Advisory ID: RHSA-2016:1296-01 Product: Red Hat Enterprise Linux Advisory […]

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1277-01 Product: Red […]

Over half of world’s top domains weak against email spoofing
Updating code can mean fewer security headaches

An update for libxml2 is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: libxml2 security update Advisory ID: RHSA-2016:1292-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1292 Issue […]

Redefining how we share our security data.

Red Hat: 2016:1272-01: python-django-horizon: Important Advisory Posted by Anthony Pell    An update for python-django-horizon is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: python-django-horizon security, bug fix, and […]

Red Hat: 2016:1271-01: python-django-horizon: Important Advisory Posted by Anthony Pell    An update for python-django-horizon is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: python-django-horizon security and bug […]

Red Hat: 2016:1269-01: python-django-horizon: Important Advisory Posted by Anthony Pell    An update for python-django-horizon is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: python-django-horizon security update Advisory […]

Red Hat: 2016:1268-01: python-django-horizon: Important Advisory Posted by Anthony Pell    An update for python-django-horizon is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: python-django-horizon security update Advisory […]

Red Hat: 2016:1270-01: python-django-horizon: Important Advisory Posted by Anthony Pell    An update for python-django-horizon is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: python-django-horizon security update Advisory ID: RHSA-2016:1270-01 Product: Red Hat […]

Senate rejects FBI bid for warrantless access to internet browsing histories
How Red Hat uses CVSS v3 to Assist in Rating Flaws

Slackware: 2016-172-01: libarchive: Security Update Posted by Anthony Pell    New libarchive packages are available for Slackware 14.1 and -current to fix security issues. [More Info…] [slackware-security] libarchive (SSA:2016-172-01) New libarchive packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ patches/packages/libarchive-3.2.1-i486-1_slack14.1.txz: Upgraded. […]

Slackware: 2016-172-02: pcre: Security Update Posted by Anthony Pell    New pcre packages are available for Slackware 14.1 and -current to fix security issues. [More Info…] [slackware-security] pcre (SSA:2016-172-02) New pcre packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ patches/packages/pcre-8.39-i486-1_slack14.1.txz: Upgraded. […]

Red Hat: 2016:1262-01: chromium-browser: Important Advisory Posted by Anthony Pell    An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1262-01 Product: Red Hat […]

Debian: 3605-1: libxslt: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3605-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 19, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libxslt CVE ID : CVE-2015-7995 CVE-2016-1683 CVE-2016-1684 Debian Bug : 802971 Several vulnerabilities were discovered in libxslt, an XSLT processing runtime library, which could lead […]

Multiple vulnerabilities have been found in PHP, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201606-09 FFmpeg: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in FFmpeg, the worst of which could lead to arbitrary code execution or Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201606-08 Adobe Flash Player: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201606-07 dhcpcd: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in dhcpcd allowing remote attackers to possibly execute arbitrary code or cause a Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201606-06 nginx: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in nginx, the worst of which may allow a remote attacker to cause a Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – […]

An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2016:1238-01 Product: Red Hat Enterprise Linux Supplementary Advisory […]

An update for ImageMagick is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: ImageMagick security update Advisory ID: RHSA-2016:1237-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1237 Issue […]

Debian: 3604-1: drupal7: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3604-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 16, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : drupal7 CVE ID : not yet available A privilege escalation vulnerability has been found in the User module of the Drupal content management framework. For […]

Gentoo: 201606-05 spice: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in spice, the worst of which may result in the remote execution of arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – […]

Several vulnerabilities were discovered in libxslt, an XSLT processing runtime library, which could lead to information disclosure or denial-of-service (application crash) against an application using the libxslt library. For the stable distribution (jessie), these problems have been fixed in version 1.1.28-2+deb8u1. We recommend that you upgrade your libxslt packages.

A privilege escalation vulnerability has been found in the User module of the Drupal content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/SA-CORE-2016-002. For the stable distribution (jessie), this problem has been fixed in version 7.32-1+deb8u7. For the unstable distribution (sid), this problem has been fixed in version 7.44-1. We […]

Debian: 3603-1: libav: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3603-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libav CVE ID : CVE-2016-3062 Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. A full list of […]

Debian: 3602-1: php5: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3602-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : php5 CVE ID : CVE-2013-7456 CVE-2016-3074 CVE-2016-4537 CVE-2016-4538 CVE-2016-4539 CVE-2016-4540 CVE-2016-4541 CVE-2016-4542 CVE-2016-4543 CVE-2016-4544 CVE-2016-5093 CVE-2016-5094 CVE-2016-5095 CVE-2016-5096 Several vulnerabilities were found in PHP, a […]

5 Ways to Defuse Data Threat from Departing Employees

Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. A full list of the changes is available at https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.7 For the stable distribution (jessie), this problem has been fixed in version 6:11.7-1~deb8u1. We recommend that you upgrade your libav packages.

Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. The vulnerabilities are addressed by upgrading PHP to the new upstream version 5.6.22, which includes additional bug fixes. Please refer to the upstream changelog for more information: For the stable distribution (jessie), these problems have been fixed in version […]

A popular cloud privacy bill stalls in the Senate
Here Is How Hackers Bypass Google’s Two-Factor Authentication
Let’s Encrypt accidentally leaks user email data

Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service. Debian follows the extended support releases (ESR) of Thunderbird. Support for the 38.x series has ended, so starting with this update we’re now […]

Red Hat: 2016:1225-01: kernel: Important Advisory Posted by Anthony Pell    An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory […]

Debian: 3601-1: icedove: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3601-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : icedove CVE ID : CVE-2016-2806 Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors […]

House Poised to Advance Privacy and Defend Encryption…If Allowed to Vote
NSA Looking to Exploit Internet of Things, Including Biomedical Devices, Official Says
Hacker puts 51 million file sharing accounts for sale on dark web