Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update for docker is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: docker security, bug fix, and enhancement update Advisory ID: RHSA-2016:1034-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1034.html Issue […]

Several security issues were fixed in QEMU. ========================================================================== Ubuntu Security Notice USN-2974-1 May 12, 2016 qemu, qemu-kvm vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in QEMU. Software Description: […]

Twitter May Have Cut Spy Agencies Off From Its Flood of Data
Mozilla Wants More Details on Browser Bug Exploited in an FBI Probe

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1033-01 Product: Red […]

Posted by Anthony Pell    An update for kernel-rt is now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security and bug fix update […]

Posted by Anthony Pell    An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security, bug fix, and enhancement […]

An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2016:1041-01 Product: Red Hat Enterprise […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:1033-01: kernel: Important Advisory Red Hat: 2016:1055-01: kernel-rt: Important Advisory Red Hat: 2016:1051-01: kernel-rt: Important Advisory Red Hat: 2016:1041-01: thunderbird: Important Advisory Slackware: 2016-132-01: mozilla-thunderbird: Security Update Red […]

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-ibm security update Advisory ID: RHSA-2016:1039-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1039.html Issue date: 2016-05-11 CVE Names: […]

Updated openshift packages that fix one security issue are now available for Red Hat OpenShift Enterprise 3.1. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openshift security update Advisory ID: RHSA-2016:1038-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2016:1038 Issue date: 2016-05-11 CVE […]

An update for pcre is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: pcre security update Advisory ID: RHSA-2016:1025-01 Product: Red Hat Enterprise Linux […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3565-2 security@debian.org https://www.debian.org/security/ Sebastien Delafond May 11, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : monotone ovito pdns qtcreator softhsm Debian Bug : 823823 This updates fixes a regression introduced in botan1.10 by DSA-3565-1: packages depending on libbotan1.10 needed to be rebuilt against the latest version to function properly. […]

SPF (SpeedPhish Framework) – E-mail Phishing Toolkit
Hacker Lexicon: SQL Injections, an Everyday Hacker’s Favorite Attack

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]

Posted by Anthony Pell    Several security issues were fixed in OpenJDK 6. ========================================================================== Ubuntu Security Notice USN-2972-1 May 10, 2016 openjdk-6 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in OpenJDK 6. Software Description: – openjdk-6: Open Source Java […]

Posted by Anthony Pell    An update for icedtea-web is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: icedtea-web security, bug fix, and […]

An update for openssh is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openssh security, bug fix, and enhancement update Advisory ID: RHSA-2016:0741-01 […]

An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:0855-01 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]

Security fix for CVE-2016-1548, CVE-2016-2516, CVE-2016-2518, CVE-2016-1550 ——————————————————————————– Fedora Update Notification FEDORA-2016-5b2eb0bf9c 2016-05-10 11:45:44.970959 ——————————————————————————– Name : ntp Product : Fedora 23 Version : 4.2.6p5 Release : 40.fc23 URL : http://www.ntp.org Summary : The NTP daemon and utilities Description : The Network Time Protocol (NTP) is used to synchronize a computer’s time with another reference […]

Posted by Anthony Pell    This update contains minor security fixes (for CVE-2016-3075, CVE-2016-1234,CVE-2015-8778, CVE-2015-8776, CVE-2014-9761, CVE-2015-8779) and collects fixesfor bugs encountered by Fedora users. ——————————————————————————– Fedora Update Notification FEDORA-2016-68abc0be35 2016-05-10 11:45:44.966689 ——————————————————————————– Name : glibc Product : Fedora 23 Version : 2.22 Release : 15.fc23 URL : http://www.gnu.org/software/glibc/ Summary : The GNU libc libraries […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]

Security fix for CVE-2016-2108, CVE-2016-2107, CVE-2016-2105, CVE-2016-2106 ——————————————————————————– Fedora Update Notification FEDORA-2016-1e39d934ed 2016-05-10 11:43:00.963747 ——————————————————————————– Name : openssl Product : Fedora 22 Version : 1.0.1k Release : 15.fc22 URL : http://www.openssl.org/ Summary : Utilities from the general purpose cryptography library with TLS implementation Description : The OpenSSL toolkit provides support for secure communications between machines. […]

CVE-2016-3710: QEMU: out-of-bounds memory access issue

Several vulnerabilities were discovered in qemu, a fast processor emulator. CVE-2016-3710 Wei Xiao and Qinghao Tang of 360.cn Inc discovered an out-of-bounds read and write flaw in the QEMU VGA module. A privileged guest user could use this flaw to execute arbitrary code on the host with the privileges of the hosting QEMU process. CVE-2016-3712 […]

Nitin Venkatesh discovered that websvn, a web viewer for Subversion repositories, is susceptible to cross-site scripting attacks via specially crafted file and directory names in repositories. For the stable distribution (jessie), this problem has been fixed in version 2.3.3-1.2+deb8u2. We recommend that you upgrade your websvn packages.

WordPress Patches SOME, XSS Flaws in Version 4.5.2
Garbage in, garbage out: Why Ars ignored this week’s massive password breach
Security researcher arrested for disclosing US election website vulnerabilities
This unusual botnet targets scientists, engineers, and academics
Founder of virtual currency sentenced to 20 years in prison

Rock Stevens, Andrew Ruef and Marcin Icewall Noga discovered a heap-based buffer overflow vulnerability in the zip_read_mac_metadata function in libarchive, a multi-format archive and compression library, which may lead to the execution of arbitrary code if a user or automated system is tricked into processing a specially crafted ZIP file. For the stable distribution (jessie), […]

Simon McVittie discovered a cross-site scripting vulnerability in the error reporting of Ikiwiki, a wiki compiler. This update also hardens ikiwiki’s use of imagemagick in the img plugin. For the stable distribution (jessie), this problem has been fixed in version 3.20141016.3. For the unstable distribution (sid), this problem has been fixed in version 3.20160506. We […]

Posted by Anthony Pell    Security fix for CVE-2015-8869 ——————————————————————————– Fedora Update Notification FEDORA-2016-1c4e616564 2016-05-09 00:02:50.053328 ——————————————————————————– Name : ocaml Product : Fedora 24 Version : 4.02.3 Release : 3.fc24 URL : http://www.ocaml.org Summary : OCaml compiler and programming environment Description : OCaml is a high-level, strongly-typed, functional and object-oriented programming language from the ML […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3571-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 08, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : ikiwiki CVE ID : CVE-2016-4561 Simon McVittie discovered a cross-site scripting vulnerability in the error reporting of Ikiwiki, a wiki compiler. This update also hardens ikiwiki’s use of imagemagick in the img plugin. For […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Posted by Anthony Pell    Update to version 20160222-1 to fix bugs(#1285888,1307846,1320511,1320956,1320958) ——————————————————————————– Fedora Update Notification FEDORA-2016-6c03d31846 2016-05-07 11:36:53.859231 ——————————————————————————– Name : parallel Product : Fedora 24 Version : 20160222 Release : 1.fc24 URL : http://www.gnu.org/software/parallel/ Summary : Shell tool for executing jobs in parallel Description : GNU Parallel is a shell tool for executing […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

10-year-old gets $10,000 bounty for finding Instagram vulnerability
Another breach, another dollar: Is it time to kill the password?
Millions of stolen email credentials shared online by Russian hacker

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3570-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mercurial CVE ID : CVE-2016-3105 Blake Burkhart discovered an arbitrary code execution flaw in Mercurial, a distributed version control system, when using the convert extension on Git repositories with specially crafted names. This flaw […]

Posted by Anthony Pell    Don’t export background images from deleted slides. ——————————————————————————– Fedora Update Notification FEDORA-2016-34f9ed9753 2016-05-05 10:04:33.646885 ——————————————————————————– Name : libreoffice Product : Fedora 23 Version : 5.0.6.2 Release : 3.fc23 URL : http://www.libreoffice.org/ Summary : Free Software Productivity Suite Description : LibreOffice is an Open Source, community-developed, office productivity suite. It includes […]

– new upstream version (46.0.1) – fixed focus on TWM (rhbz#1322626) ——————————————————————————– Fedora Update Notification FEDORA-2016-25843fda6b 2016-05-05 10:04:33.645657 ——————————————————————————– Name : firefox Product : Fedora 23 Version : 46.0.1 Release : 1.fc23 URL : https://www.mozilla.org/firefox/ Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance […]

Hitler’s “unbreakable” encryption machine – and the Bletchley Park devices which cracked the code
Big data breaches found at major email services – expert

It was discovered that libpam-sshauth, a PAM module to authenticate using an SSH server, does not correctly handle system users. In certain configurations an attacker can take advantage of this flaw to gain root privileges. For the stable distribution (jessie), this problem has been fixed in version 0.3.1-1+deb8u1. For the testing distribution (stretch), this problem […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3569-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openafs CVE ID : CVE-2015-8312 CVE-2016-2860 Two vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-8312 Potential denial of service […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3568-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libtasn1-6 CVE ID : CVE-2016-4008 Pascal Cuoq and Miod Vallat discovered that Libtasn1, a library to manage ASN.1 structures, does not correctly handle certain malformed DER certificates. A remote attacker can take advantage of […]

Posted by Anthony Pell    Several security issues were fixed in OpenJDK 7. ========================================================================== Ubuntu Security Notice USN-2964-1 May 05, 2016 openjdk-7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: Several security issues were fixed in OpenJDK 7. Software Description: – openjdk-7: […]

Posted by Anthony Pell    Several security issues were fixed in OpenJDK 8. ========================================================================== Ubuntu Security Notice USN-2963-1 May 05, 2016 openjdk-8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS Summary: Several security issues were fixed in OpenJDK 8. Software Description: – openjdk-8: Open Source Java […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3569-1: openafs: Summary Debian: 3568-1: libtasn1-6: Summary Ubuntu: 2964-1: OpenJDK 7 vulnerabilities Ubuntu: 2963-1: OpenJDK 8 vulnerabilities Ubuntu: 2961-1: Little CMS vulnerability Debian: 3567-1: libpam-sshauth: Summary Fedora 23 obs-signd-2.2.1-8.fc23 […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3567-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 04, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libpam-sshauth CVE ID : CVE-2016-4422 It was discovered that libpam-sshauth, a PAM module to authenticate using an SSH server, does not correctly handle system users. In certain configurations an attacker can take advantage of […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3569-1: openafs: Summary Debian: 3568-1: libtasn1-6: Summary Ubuntu: 2964-1: OpenJDK 7 vulnerabilities Ubuntu: 2963-1: OpenJDK 8 vulnerabilities Ubuntu: 2961-1: Little CMS vulnerability Debian: 3567-1: libpam-sshauth: Summary Fedora 23 obs-signd-2.2.1-8.fc23 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3569-1: openafs: Summary Debian: 3568-1: libtasn1-6: Summary Ubuntu: 2964-1: OpenJDK 7 vulnerabilities Ubuntu: 2963-1: OpenJDK 8 vulnerabilities Ubuntu: 2961-1: Little CMS vulnerability Debian: 3567-1: libpam-sshauth: Summary Fedora 23 obs-signd-2.2.1-8.fc23 […]

Security fix for CVE-2016-2108, CVE-2016-2107, CVE-2016-2105, CVE-2016-2106 ——————————————————————————– Fedora Update Notification FEDORA-2016-05c567df1a 2016-05-04 15:02:38.890153 ——————————————————————————– Name : openssl Product : Fedora 23 Version : 1.0.2h Release : 1.fc23 URL : http://www.openssl.org/ Summary : Utilities from the general purpose cryptography library with TLS implementation Description : The OpenSSL toolkit provides support for secure communications between machines. […]

Posted by Anthony Pell    USN-2950-1 introduced regressions in Samba. ========================================================================== Ubuntu Security Notice USN-2950-3 May 04, 2016 samba regressions ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: USN-2950-1 introduced regressions in Samba. Software Description: […]

Posted by Anthony Pell    USN-2950-1 introduced regressions in Samba. ========================================================================== Ubuntu Security Notice USN-2950-2 May 04, 2016 samba regressions ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: USN-2950-1 introduced regressions in Samba. Software Description: […]

Open Source ImageMagick Security Bug Puts Sites at Risk
NIST readies ‘post-quantum’ crypto competition
How to Conduct Internal Penetration Testing

Pascal Cuoq and Miod Vallat discovered that Libtasn1, a library to manage ASN.1 structures, does not correctly handle certain malformed DER certificates. A remote attacker can take advantage of this flaw to cause an application using the Libtasn1 library to hang, resulting in a denial of service. For the stable distribution (jessie), this problem has […]

Two vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-8312 Potential denial of service caused by a bug in the pioctl logic allowing a local user to overrun a kernel buffer with a single NUL byte. CVE-2016-2860 Peter Iannucci discovered that […]

Blake Burkhart discovered an arbitrary code execution flaw in Mercurial, a distributed version control system, when using the convert extension on Git repositories with specially crafted names. This flaw in particular affects automated code conversion services that allow arbitrary repository names. For the stable distribution (jessie), this problem has been fixed in version 3.1.2-2+deb8u3. For […]

An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:0715-01 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0715-01: kernel: Moderate Advisory Fedora 22 cacti-0.8.8g-1.fc22 Fedora 23 cacti-0.8.8g-1.fc23 Slackware: 2016-124-01: openssl: Security Update Red Hat: 2016:0716-01: java-1.8.0-ibm: Critical Advisory Debian: 3566-1: openssl: Summary Red Hat: 2016:0711-01: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0715-01: kernel: Moderate Advisory Fedora 22 cacti-0.8.8g-1.fc22 Fedora 23 cacti-0.8.8g-1.fc23 Slackware: 2016-124-01: openssl: Security Update Red Hat: 2016:0716-01: java-1.8.0-ibm: Critical Advisory Debian: 3566-1: openssl: Summary Red Hat: 2016:0711-01: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0715-01: kernel: Moderate Advisory Fedora 22 cacti-0.8.8g-1.fc22 Fedora 23 cacti-0.8.8g-1.fc23 Slackware: 2016-124-01: openssl: Security Update Red Hat: 2016:0716-01: java-1.8.0-ibm: Critical Advisory Debian: 3566-1: openssl: Summary Red Hat: 2016:0711-01: […]

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-ibm security update Advisory ID: RHSA-2016:0716-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0716.html Issue date: 2016-05-03 CVE Names: […]

Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3566-1 security@debian.org https://www.debian.org/security/ Alessandro Ghedini May 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openssl CVE ID : CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 CVE-2016-2109 CVE-2016-2176 Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit. CVE-2016-2105 Guido Vranken discovered that an overflow can […]

Posted by Anthony Pell    An updated Jenkins package and image that include a security fix are now available for Red Hat OpenShift Enterprise 3.1. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: jenkins security update Advisory ID: RHSA-2016:0711-01 Product: Red Hat […]

Posted by Anthony Pell    Several security issues were fixed in OpenSSL. ========================================================================== Ubuntu Security Notice USN-2959-1 May 03, 2016 openssl vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed […]

The CloudFlare and Tor Stalemate Is Harming Users
How Craig Wright Privately ‘Proved’ He Created Bitcoin
New BlackArch Linux version released, now provides 1400 pentesting tools

Several security vulnerabilities were found in botan1.10, a C++ library which provides support for many common cryptographic operations, including encryption, authentication, X.509v3 certificates and CRLs. CVE-2015-5726 The BER decoder would crash due to reading from offset 0 of an empty vector if it encountered a BIT STRING which did not contain any data at all. […]

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1660 Atte Kettunen discovered an out-of-bounds write issue. CVE-2016-1661 Wadih Matar discovered a memory corruption issue. CVE-2016-1662 Rob Wu discovered a use-after-free issue related to extensions. CVE-2016-1663 A use-after-free issue was discovered in Blink’s bindings to V8. CVE-2016-1664 Wadih Matar discovered a way to spoof […]

Two highly dangerous OpenSSL security bugs have been patched

Posted by Anthony Pell    New mercurial packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. [More Info…] [slackware-security] mercurial (SSA:2016-123-01) New mercurial packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware […]

Git contains multiple vulnerabilities that allow for the remote execution of arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – Gentoo Linux Security Advisory GLSA 201605-01 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-123-01: mercurial: Security Update Gentoo: 201605-01 Git: Multiple vulnerabilities Ubuntu: 2957-2: Libtasn1 vulnerability Fedora 23 php-5.6.21-1.fc23 Ubuntu: 2958-1: poppler vulnerabilities Ubuntu: 2957-1: Libtasn1 vulnerability Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-123-01: mercurial: Security Update Gentoo: 201605-01 Git: Multiple vulnerabilities Ubuntu: 2957-2: Libtasn1 vulnerability Fedora 23 php-5.6.21-1.fc23 Ubuntu: 2958-1: poppler vulnerabilities Ubuntu: 2957-1: Libtasn1 vulnerability Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical […]

poppler could be made to crash or run programs if it opened a speciallycrafted file. ========================================================================== Ubuntu Security Notice USN-2958-1 May 02, 2016 poppler vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: poppler could be made to crash […]

Libtasn1 could be made to hang if it processed specially crafted data. ========================================================================== Ubuntu Security Notice USN-2957-1 May 02, 2016 libtasn1-3, libtasn1-6 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Libtasn1 could be made to hang if it […]

Thousands of taxpayers affected by W-2 Phishing attacks this year
Privacy Activists Cheer Passage of Email Privacy Act, Brace for Senate Battle
Two Tips to Keep Your Phone’s Encrypted Messages Encrypted

Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit. CVE-2016-2105 Guido Vranken discovered that an overflow can occur in the function EVP_EncodeUpdate(), used for Base64 encoding, if an attacker can supply a large amount of data. This could lead to a heap corruption. CVE-2016-2106 Guido Vranken discovered that an overflow can occur in […]

It was discovered that a heap overflow in the Poppler PDF library may result in denial of service and potentially the execution of arbitrary code if a malformed PDF file is opened. For the stable distribution (jessie), this problem has been fixed in version 0.26.5-2+deb8u1. For the testing distribution (stretch), this problem has been fixed […]