Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update for java-1.6.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.6.0-ibm security update Advisory ID: RHSA-2016:0708-01 Product: Red Hat Enterprise Linux Supplementary Advisory […]

Posted by Anthony Pell    An update for mercurial is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: mercurial security update Advisory ID: RHSA-2016:0706-01 […]

Posted by Anthony Pell    An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:0707-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0707.html […]

An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: rh-mysql56-mysql security update Advisory ID: RHSA-2016:0705-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0705.html Issue date: 2016-05-02 CVE Names: CVE-2015-4792 CVE-2015-4800 CVE-2015-4802 […]

Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3565-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond May 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : botan1.10 CVE ID : CVE-2015-5726 CVE-2015-5727 CVE-2015-7827 CVE-2016-2194 CVE-2016-2195 CVE-2016-2849 Debian Bug : 817932 822698 Several security vulnerabilities were found in botan1.10, a C++ library which provides support for […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3564-1 security@debian.org https://www.debian.org/security/ Michael Gilbert May 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1660 CVE-2016-1661 CVE-2016-1662 CVE-2016-1663 CVE-2016-1664 CVE-2016-1665 CVE-2016-1666 Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1660 Atte Kettunen discovered an out-of-bounds write issue. CVE-2016-1661 Wadih Matar discovered a […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3563-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : poppler CVE ID : CVE-2015-8868 It was discovered that a heap overflow in the Poppler PDF library may result in denial of service and potentially the execution of arbitrary code if a malformed PDF […]

Several vulnerabilities were discovered in tardiff, a tarball comparison tool. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-0857 Rainer Mueller and Florian Weimer discovered that tardiff is prone to shell command injections via shell meta-characters in filenames in tar files or via shell meta-characters in the tar filename itself. CVE-2015-0858 Florian Weimer […]

We’re Going HTTPS: Here’s How WIRED Is Tackling a Huge Security Upgrade
Suspect jailed indefinitely for refusing to decrypt hard drives
How to Find the Right Penetration Testing Company
Former Tor developer created malware for the FBI to hack Tor users

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 i7z-0.27.2-16.20150629gitec09c4f.fc23 Fedora 22 libtasn1-4.8-1.fc22 Fedora 23 kernel-4.4.8-300.fc23 Debian: 3560-1: php5: Summary Ubuntu: 2952-2: PHP regression Ubuntu: 2950-2: libsoup update Debian: 3559-1: iceweasel: Summary Slackware: 2016-117-01: mozilla-firefox: Security Update […]

Update to 4.8 ——————————————————————————– Fedora Update Notification FEDORA-2016-96bfd9e873 2016-04-27 17:57:40.684989 ——————————————————————————– Name : libtasn1 Product : Fedora 22 Version : 4.8 Release : 1.fc22 URL : http://www.gnu.org/software/libtasn1/ Summary : The ASN.1 library used in GNUTLS Description : A library that provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 i7z-0.27.2-16.20150629gitec09c4f.fc23 Fedora 22 libtasn1-4.8-1.fc22 Fedora 23 kernel-4.4.8-300.fc23 Debian: 3560-1: php5: Summary Ubuntu: 2952-2: PHP regression Ubuntu: 2950-2: libsoup update Debian: 3559-1: iceweasel: Summary Slackware: 2016-117-01: mozilla-firefox: Security Update […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3560-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 27, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : php5 CVE ID : CVE-2015-8865 CVE-2016-4070 CVE-2016-4071 CVE-2016-4072 CVE-2016-4073 Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. The vulnerabilities are addressed by upgrading PHP to the […]

USN-2952-1 caused a regression in PHP. ========================================================================== Ubuntu Security Notice USN-2952-2 April 27, 2016 php5 regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: USN-2952-1 caused a regression in PHP. Software Description: – php5: HTML-embedded scripting language interpreter Details: USN-2952-1 fixed vulnerabilities in PHP. One of the […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 i7z-0.27.2-16.20150629gitec09c4f.fc23 Fedora 22 libtasn1-4.8-1.fc22 Fedora 23 kernel-4.4.8-300.fc23 Debian: 3560-1: php5: Summary Ubuntu: 2952-2: PHP regression Ubuntu: 2950-2: libsoup update Debian: 3559-1: iceweasel: Summary Slackware: 2016-117-01: mozilla-firefox: Security Update […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3559-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 27, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : iceweasel CVE ID : CVE-2016-2805 CVE-2016-2807 CVE-2016-2808 CVE-2016-2814 Multiple security issues have been found in Iceweasel, Debian’s version of the Mozilla Firefox web browser: Multiple memory safety errors and buffer overflows may lead to […]

Several vulnerabilities were discovered in Subversion, a version control system. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2167 Daniel Shahaf and James McCoy discovered that an implementation error in the authentication against the Cyrus SASL library would permit a remote user to specify a realm string which is a prefix of the […]

Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. The vulnerabilities are addressed by upgrading PHP to the new upstream version 5.6.20, which includes additional bug fixes. Please refer to the upstream changelog for more information: For the stable distribution (jessie), these problems have been fixed in version […]

Multiple security issues have been found in Iceweasel, Debian’s version of the Mozilla Firefox web browser: Multiple memory safety errors and buffer overflows may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 38.8.0esr-1~deb7u1. For the stable distribution (jessie), these problems […]

Pirate Bay visitors infected with crypto-ransomware via bad ads
Hackers don’t just want your credit cards, now they want the pattern of your life

Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in breakouts of the Java sandbox, denial of service or information disclosure. For the stable distribution (jessie), these problems have been fixed in version 7u101-2.6.6-1~deb8u1. We recommend that you upgrade your openjdk-7 packages.

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-117-01: mozilla-firefox: Security Update Fedora 22 xstream-1.4.9-1.fc22 Gentoo: 201604-04 libksba: Multiple vulnerabilities Gentoo: 201604-05 Wireshark: Multiple vulnerabilities Fedora 23 xstream-1.4.9-1.fc23 Fedora 23 rpm-4.13.0-0.rc1.13.fc23 Red Hat: 2016:0695-01: firefox: Critical Advisory […]

Security fix for CVE-2016-3674 ——————————————————————————– Fedora Update Notification FEDORA-2016-250042b8a6 2016-04-26 16:44:25.072543 ——————————————————————————– Name : xstream Product : Fedora 22 Version : 1.4.9 Release : 1.fc22 URL : http://xstream.codehaus.org/ Summary : Java XML serialization library Description : XStream is a simple library to serialize objects to XML and back again. A high level facade is supplied […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-117-01: mozilla-firefox: Security Update Fedora 22 xstream-1.4.9-1.fc22 Gentoo: 201604-04 libksba: Multiple vulnerabilities Gentoo: 201604-05 Wireshark: Multiple vulnerabilities Fedora 23 xstream-1.4.9-1.fc23 Fedora 23 rpm-4.13.0-0.rc1.13.fc23 Red Hat: 2016:0695-01: firefox: Critical Advisory […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-117-01: mozilla-firefox: Security Update Fedora 22 xstream-1.4.9-1.fc22 Gentoo: 201604-04 libksba: Multiple vulnerabilities Gentoo: 201604-05 Wireshark: Multiple vulnerabilities Fedora 23 xstream-1.4.9-1.fc23 Fedora 23 rpm-4.13.0-0.rc1.13.fc23 Red Hat: 2016:0695-01: firefox: Critical Advisory […]

Security fix for CVE-2016-3674 ——————————————————————————– Fedora Update Notification FEDORA-2016-de909cc333 2016-04-26 16:44:53.220685 ——————————————————————————– Name : xstream Product : Fedora 23 Version : 1.4.9 Release : 1.fc23 URL : http://xstream.codehaus.org/ Summary : Java XML serialization library Description : XStream is a simple library to serialize objects to XML and back again. A high level facade is supplied […]

* Fix sigsegv in stringFormat() (rhbz:1316903) * Fix reading rpmtd behind itssize in formatValue() (rhbz:1316896) ——————————————————————————– Fedora Update Notification FEDORA-2016-c3d9a9c0c4 2016-04-26 16:44:53.188544 ——————————————————————————– Name : rpm Product : Fedora 23 Version : 4.13.0 Release : 0.rc1.13.fc23 URL : http://www.rpm.org/ Summary : The RPM package management system Description : The RPM Package Manager (RPM) is a […]

An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2016:0695-01 Product: Red Hat Enterprise […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3558-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 26, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openjdk-7 CVE ID : CVE-2016-0636 CVE-2016-0686 CVE-2016-0687 CVE-2016-0695 CVE-2016-3425 CVE-2016-3426 CVE-2016-3427 Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in breakouts of the Java sandbox, denial of […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-117-01: mozilla-firefox: Security Update Fedora 22 xstream-1.4.9-1.fc22 Gentoo: 201604-04 libksba: Multiple vulnerabilities Gentoo: 201604-05 Wireshark: Multiple vulnerabilities Fedora 23 xstream-1.4.9-1.fc23 Fedora 23 rpm-4.13.0-0.rc1.13.fc23 Red Hat: 2016:0695-01: firefox: Critical Advisory […]

Update to 2.7.4 (for CVE-2016-2315, CVE-2016-2324). ——————————————————————————– Fedora Update Notification FEDORA-2016-8f164810c3 2016-04-26 16:32:18.393829 ——————————————————————————– Name : git Product : Fedora 24 Version : 2.7.4 Release : 1.fc24 URL : http://git-scm.com/ Summary : Fast Version Control System Description : Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides […]

94 Percent of IT Pros See Free Wi-Fi Hotspots as a Significant Security Threat
James Clapper: Snowden sped up sophistication of crypto, “it’s not a good thing”
MongoDB configuration error exposed 93 million Mexican voter records

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 mingw-poppler-0.34.0-2.fc23 Fedora 23 golang-1.5.4-1.fc23 Fedora 23 ansible1.9-1.9.6-1.fc23 Fedora 23 mod_nss-1.0.12-3.fc23 Fedora 23 gsi-openssh-7.2p2-1.fc23 Fedora 22 golang-1.5.4-1.fc22 Fedora 22 mingw-poppler-0.30.0-4.fc22 Fedora 22 mod_nss-1.0.11-7.fc22 Community Linux Events Linux User Groups […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 mingw-poppler-0.34.0-2.fc23 Fedora 23 golang-1.5.4-1.fc23 Fedora 23 ansible1.9-1.9.6-1.fc23 Fedora 23 mod_nss-1.0.12-3.fc23 Fedora 23 gsi-openssh-7.2p2-1.fc23 Fedora 22 golang-1.5.4-1.fc22 Fedora 22 mingw-poppler-0.30.0-4.fc22 Fedora 22 mod_nss-1.0.11-7.fc22 Community Linux Events Linux User Groups […]

Update to 1.9.6. Fixes bug #1327744 as well as CVE-2016-3096 ——————————————————————————– Fedora Update Notification FEDORA-2016-65519440f5 2016-04-25 18:03:33.087200 ——————————————————————————– Name : ansible1.9 Product : Fedora 23 Version : 1.9.6 Release : 1.fc23 URL : http://ansible.com Summary : SSH-based configuration management, deployment, and task execution system Description : Ansible is a radically simple model-driven configuration management, multi-node […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 mingw-poppler-0.34.0-2.fc23 Fedora 23 golang-1.5.4-1.fc23 Fedora 23 ansible1.9-1.9.6-1.fc23 Fedora 23 mod_nss-1.0.12-3.fc23 Fedora 23 gsi-openssh-7.2p2-1.fc23 Fedora 22 golang-1.5.4-1.fc22 Fedora 22 mingw-poppler-0.30.0-4.fc22 Fedora 22 mod_nss-1.0.11-7.fc22 Community Linux Events Linux User Groups […]

Sync with openssh package. ——————————————————————————– Fedora Update Notification FEDORA-2016-188267b485 2016-04-25 18:03:33.085699 ——————————————————————————– Name : gsi-openssh Product : Fedora 23 Version : 7.2p2 Release : 1.fc23 URL : http://www.openssh.com/portable.html Summary : An implementation of the SSH protocol with GSI authentication Description : SSH (Secure SHell) is a program for logging into and executing commands on a […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 mingw-poppler-0.34.0-2.fc23 Fedora 23 golang-1.5.4-1.fc23 Fedora 23 ansible1.9-1.9.6-1.fc23 Fedora 23 mod_nss-1.0.12-3.fc23 Fedora 23 gsi-openssh-7.2p2-1.fc23 Fedora 22 golang-1.5.4-1.fc22 Fedora 22 mingw-poppler-0.30.0-4.fc22 Fedora 22 mod_nss-1.0.11-7.fc22 Community Linux Events Linux User Groups […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 mingw-poppler-0.34.0-2.fc23 Fedora 23 golang-1.5.4-1.fc23 Fedora 23 ansible1.9-1.9.6-1.fc23 Fedora 23 mod_nss-1.0.12-3.fc23 Fedora 23 gsi-openssh-7.2p2-1.fc23 Fedora 22 golang-1.5.4-1.fc22 Fedora 22 mingw-poppler-0.30.0-4.fc22 Fedora 22 mod_nss-1.0.11-7.fc22 Community Linux Events Linux User Groups […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 mingw-poppler-0.34.0-2.fc23 Fedora 23 golang-1.5.4-1.fc23 Fedora 23 ansible1.9-1.9.6-1.fc23 Fedora 23 mod_nss-1.0.12-3.fc23 Fedora 23 gsi-openssh-7.2p2-1.fc23 Fedora 22 golang-1.5.4-1.fc22 Fedora 22 mingw-poppler-0.30.0-4.fc22 Fedora 22 mod_nss-1.0.11-7.fc22 Community Linux Events Linux User Groups […]

Update to 1.9.6. Fixes bug #1327744 as well as CVE-2016-3096 ——————————————————————————– Fedora Update Notification FEDORA-2016-28ff51a3f5 2016-04-25 18:02:16.026705 ——————————————————————————– Name : ansible1.9 Product : Fedora 22 Version : 1.9.6 Release : 1.fc22 URL : http://ansible.com Summary : SSH-based configuration management, deployment, and task execution system Description : Ansible is a radically simple model-driven configuration management, multi-node […]

Sync with openssh package. ——————————————————————————– Fedora Update Notification FEDORA-2016-fc1cc33e05 2016-04-25 18:02:16.026570 ——————————————————————————– Name : gsi-openssh Product : Fedora 22 Version : 6.9p1 Release : 8.fc22 URL : http://www.openssh.com/portable.html Summary : An implementation of the SSH protocol with GSI authentication Description : SSH (Secure SHell) is a program for logging into and executing commands on a […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 mingw-poppler-0.34.0-2.fc23 Fedora 23 golang-1.5.4-1.fc23 Fedora 23 ansible1.9-1.9.6-1.fc23 Fedora 23 mod_nss-1.0.12-3.fc23 Fedora 23 gsi-openssh-7.2p2-1.fc23 Fedora 22 golang-1.5.4-1.fc22 Fedora 22 mingw-poppler-0.30.0-4.fc22 Fedora 22 mod_nss-1.0.11-7.fc22 Community Linux Events Linux User Groups […]

Posted by Anthony Pell    Several security issues were fixed in MySQL. ========================================================================== Ubuntu Security Notice USN-2954-1 April 25, 2016 mysql-5.7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS Summary: Several security issues were fixed in MySQL. Software Description: – mysql-5.7: MySQL database Details: Multiple security […]

Creators of SpyEye Virus Sentenced to 24 Years in Prison
Misunderstanding Indicators of Compromise
How I Hacked Facebook, and Found Someone’s Backdoor Script
Using the Java Security Manager in Enterprise Application Platform 7

Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.49. Please see the MySQL 5.5 Release Notes and Oracle’s Critical Patch Update advisory for further details: For the stable distribution (jessie), these problems have been fixed in version 5.5.49-0+deb8u1. We recommend that […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 python-tgcaptcha2-0.3.1-1.fc23 Fedora 23 parallel-20160222-1.fc23 Fedora 23 thunderbird-45.0-2.fc23 Fedora 23 openssh-7.2p2-3.fc23 Fedora 22 python-tgcaptcha2-0.3.1-1.fc22 Fedora 22 parallel-20160222-1.fc22 Debian: 3556-1: libgd2: Summary Fedora 23 w3m-0.5.3-24.fc23 Community Linux Events Linux User […]

Posted by Anthony Pell    Update to version 20160222-1 to fix bugs(#1285888,1307846,1320511,1320956,1320958) ——————————————————————————– Fedora Update Notification FEDORA-2016-73eb29f890 2016-04-24 17:22:11.575647 ——————————————————————————– Name : parallel Product : Fedora 23 Version : 20160222 Release : 1.fc23 URL : http://www.gnu.org/software/parallel/ Summary : Shell tool for executing jobs in parallel Description : GNU Parallel is a shell tool for executing […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 python-tgcaptcha2-0.3.1-1.fc23 Fedora 23 parallel-20160222-1.fc23 Fedora 23 thunderbird-45.0-2.fc23 Fedora 23 openssh-7.2p2-3.fc23 Fedora 22 python-tgcaptcha2-0.3.1-1.fc22 Fedora 22 parallel-20160222-1.fc22 Debian: 3556-1: libgd2: Summary Fedora 23 w3m-0.5.3-24.fc23 Community Linux Events Linux User […]

Security fix for CVE-2015-8325: ignore PAM environment vars when UseLogin=yes. ——————————————————————————– Fedora Update Notification FEDORA-2016-7f5004093e 2016-04-24 17:22:11.574810 ——————————————————————————– Name : openssh Product : Fedora 23 Version : 7.2p2 Release : 3.fc23 URL : http://www.openssh.com/portable.html Summary : An open source implementation of SSH protocol versions 1 and 2 Description : SSH (Secure SHell) is a program […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 python-tgcaptcha2-0.3.1-1.fc23 Fedora 23 parallel-20160222-1.fc23 Fedora 23 thunderbird-45.0-2.fc23 Fedora 23 openssh-7.2p2-3.fc23 Fedora 22 python-tgcaptcha2-0.3.1-1.fc22 Fedora 22 parallel-20160222-1.fc22 Debian: 3556-1: libgd2: Summary Fedora 23 w3m-0.5.3-24.fc23 Community Linux Events Linux User […]

Posted by Anthony Pell    Update to version 20160222-1 to fix bugs(#1285888,1307846,1320511,1320956,1320958) ——————————————————————————– Fedora Update Notification FEDORA-2016-7eb5caa94d 2016-04-24 17:21:43.073116 ——————————————————————————– Name : parallel Product : Fedora 22 Version : 20160222 Release : 1.fc22 URL : http://www.gnu.org/software/parallel/ Summary : Shell tool for executing jobs in parallel Description : GNU Parallel is a shell tool for executing […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3556-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 24, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libgd2 CVE ID : CVE-2016-3074 Debian Bug : 822242 Hans Jerry Illikainen discovered that libgd2, a library for programmatic graphics creation and manipulation, suffers of a signedness vulnerability which may result in a heap […]

Resolves:rh#1324349 – denial of service with crafted html files ——————————————————————————– Fedora Update Notification FEDORA-2016-80c07fbb6c 2016-04-24 01:34:43.161129 ——————————————————————————– Name : w3m Product : Fedora 23 Version : 0.5.3 Release : 24.fc23 URL : http://w3m.sourceforge.net/ Summary : A pager with Web browsing abilities Description : The w3m program is a pager (or text file viewer) that can […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 python-tgcaptcha2-0.3.1-1.fc23 Fedora 23 parallel-20160222-1.fc23 Fedora 23 thunderbird-45.0-2.fc23 Fedora 23 openssh-7.2p2-3.fc23 Fedora 22 python-tgcaptcha2-0.3.1-1.fc22 Fedora 22 parallel-20160222-1.fc22 Debian: 3556-1: libgd2: Summary Fedora 23 w3m-0.5.3-24.fc23 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 python-tgcaptcha2-0.3.1-1.fc23 Fedora 23 parallel-20160222-1.fc23 Fedora 23 thunderbird-45.0-2.fc23 Fedora 23 openssh-7.2p2-3.fc23 Fedora 22 python-tgcaptcha2-0.3.1-1.fc22 Fedora 22 parallel-20160222-1.fc22 Debian: 3556-1: libgd2: Summary Fedora 23 w3m-0.5.3-24.fc23 Community Linux Events Linux User […]

Posted by Anthony Pell    The 4.5.2 stable update contains a number of important fixes across the tree.This build should also boot on some of the i686 systems that would not bootbefore. ——————————————————————————– Fedora Update Notification FEDORA-2016-7f37d42add 2016-04-23 23:42:43.599148 ——————————————————————————– Name : binutils Product : Fedora 24 Version : 2.26 Release : 18.fc24 URL : […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 python-tgcaptcha2-0.3.1-1.fc23 Fedora 23 parallel-20160222-1.fc23 Fedora 23 thunderbird-45.0-2.fc23 Fedora 23 openssh-7.2p2-3.fc23 Fedora 22 python-tgcaptcha2-0.3.1-1.fc22 Fedora 22 parallel-20160222-1.fc22 Debian: 3556-1: libgd2: Summary Fedora 23 w3m-0.5.3-24.fc23 Community Linux Events Linux User […]

Several vulnerabilities were discovered in imlib2, an image manipulation library. CVE-2011-5326 Kevin Ryde discovered that attempting to draw a 2×1 radi ellipse results in a floating point exception. CVE-2014-9771 It was discovered that an integer overflow could lead to invalid memory reads and unreasonably large memory allocations. CVE-2016-3993 Yuriy M. Kaminskiy discovered that drawing using […]

Hans Jerry Illikainen discovered that libgd2, a library for programmatic graphics creation and manipulation, suffers of a signedness vulnerability which may result in a heap overflow when processing specially crafted compressed gd2 data. A remote attacker can take advantage of this flaw to cause an application using the libgd2 library to crash, or potentially, to […]

SpyEye Makers Get 24 Years in Prison
FBI Hints It Paid Hackers $1 Million to Get Into San Bernardino iPhone
700 Million People Just Got Encryption That Congress Can’t Touch

CVE-2016-3960 (XSA-173) Ling Liu and Yihan Lian of the Cloud Security Team, Qihoo 360 discovered an integer overflow in the x86 shadow pagetable code. A HVM guest using shadow pagetables can cause the host to crash. A PV guest using shadow pagetables (i.e. being migrated) with PV superpages enabled (which is not the default) can […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3553-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond April 22, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : varnish CVE ID : CVE-2015-8852 Debian Bug : 783510 Régis Leroy from Makina Corpus discovered that varnish, a caching HTTP reverse proxy, is vulnerable to HTTP smuggling issues, potentially resulting in cache poisoning or […]

**Version 0.90.3** * security update to prevent a minor vulnerability *fix issues with post-only ticket form See [changelog](https://github.com/glpi-project/glpi/issues?q=milestone:0.90.3) for more details. —- **Version0.90.2** Include bugfixes and some minor features : * An alert in centralpage when some of your mysql tables are marked as crashed * A betterflexibility in splitted layout for small screens * […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3553-1: varnish: Summary Fedora 22 glpi-0.90.3-1.fc22 Fedora 22 springframework-amqp-1.3.9-4.fc22 Fedora 22 drupal7-block_class-2.3-1.fc22 Fedora 23 libtasn1-4.8-1.fc23 Fedora 23 glpi-0.90.3-1.fc23 Fedora 23 drupal7-block_class-2.3-1.fc23 Debian: 3554-1: xen: Summary Community Linux Events Linux […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3553-1: varnish: Summary Fedora 22 glpi-0.90.3-1.fc22 Fedora 22 springframework-amqp-1.3.9-4.fc22 Fedora 22 drupal7-block_class-2.3-1.fc22 Fedora 23 libtasn1-4.8-1.fc23 Fedora 23 glpi-0.90.3-1.fc23 Fedora 23 drupal7-block_class-2.3-1.fc23 Debian: 3554-1: xen: Summary Community Linux Events Linux […]

Update to 4.8 ——————————————————————————– Fedora Update Notification FEDORA-2016-383b8250e6 2016-04-21 21:27:32.207875 ——————————————————————————– Name : libtasn1 Product : Fedora 23 Version : 4.8 Release : 1.fc23 URL : http://www.gnu.org/software/libtasn1/ Summary : The ASN.1 library used in GNUTLS Description : A library that provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and […]

**Version 0.90.3** * security update to prevent a minor vulnerability *fix issues with post-only ticket form See [changelog](https://github.com/glpi-project/glpi/issues?q=milestone:0.90.3) for more details. —- **Version0.90.2** Include bugfixes and some minor features : * An alert in centralpage when some of your mysql tables are marked as crashed * A betterflexibility in splitted layout for small screens * […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3553-1: varnish: Summary Fedora 22 glpi-0.90.3-1.fc22 Fedora 22 springframework-amqp-1.3.9-4.fc22 Fedora 22 drupal7-block_class-2.3-1.fc22 Fedora 23 libtasn1-4.8-1.fc23 Fedora 23 glpi-0.90.3-1.fc23 Fedora 23 drupal7-block_class-2.3-1.fc23 Debian: 3554-1: xen: Summary Community Linux Events Linux […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3554-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 21, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xen CVE ID : CVE-2016-3158 CVE-2016-3159 CVE-2016-3960 Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-3158, CVE-2016-3159 (XSA-172) Jan Beulich from SUSE discovered […]

An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-oracle security update Advisory ID: RHSA-2016:0678-01 Product: Oracle Java for Red Hat Enterprise Linux […]

An update for java-1.6.0-sun is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.6.0-sun security update Advisory ID: RHSA-2016:0679-01 Product: Oracle Java for Red Hat Enterprise Linux […]

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-openjdk security update Advisory ID: RHSA-2016:0675-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0675.html Issue date: 2016-04-21 CVE Names: CVE-2016-0686 CVE-2016-0687 […]

An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-oracle security update Advisory ID: RHSA-2016:0677-01 Product: Oracle Java […]

DRAM bitflipping exploits that hijack computers just got easier
Female Hackers Still Face Harassment at Conferences
Hacking Team postmortem is something all security leaders should read
Denial-of-service attacks now a cover for something more sinister

Régis Leroy from Makina Corpus discovered that varnish, a caching HTTP reverse proxy, is vulnerable to HTTP smuggling issues, potentially resulting in cache poisoning or bypassing of access control policies. For the oldstable distribution (wheezy), this problem has been fixed in version 3.0.2-2+deb7u2. We recommend that you upgrade your varnish packages.

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-openjdk security update Advisory ID: RHSA-2016:0650-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0650.html Issue date: 2016-04-20 CVE Names: CVE-2016-0686 CVE-2016-0687 […]

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-openjdk security update Advisory ID: RHSA-2016:0651-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0651.html Issue date: 2016-04-20 CVE Names: CVE-2016-0686 CVE-2016-0687 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0650-01: java-1.8.0-openjdk: Critical Advisory Red Hat: 2016:0651-01: java-1.8.0-openjdk: Critical Advisory Fedora 23 springframework-amqp-1.3.9-4.fc23 Fedora 24 mercurial-3.7.3-1.fc24 Fedora 24 webkitgtk4-2.12.1-1.fc24 Fedora 23 kernel-4.4.7-300.fc23 Fedora 22 libreswan-3.17-1.fc22 Fedora 24 w3m-0.5.3-24.fc24 […]

Security risks with higher level languages in middleware products

CVE-2016-3630, CVE-2016-3068, CVE-2016-3069 ——————————————————————————– Fedora Update Notification FEDORA-2016-74f9a65b3a 2016-04-20 15:24:02.554822 ——————————————————————————– Name : mercurial Product : Fedora 24 Version : 3.7.3 Release : 1.fc24 URL : http://www.selenic.com/mercurial/ Summary : Mercurial — a distributed SCM Description : Mercurial is a fast, lightweight source control management system designed for efficient handling of very large distributed projects. Quick […]