Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Debian: 3599-1: p7zip: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3599-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : p7zip CVE ID : CVE-2016-2335 Debian Bug : 824160 Marcin ‘Icewall’ Noga of Cisco Talos discovered an out-of-bound read vulnerability in the CInArchive::ReadFileItem method in […]

Securing the server programs hiding in your Docker containers
Why you don’t have to fix every vulnerability
Firefox 47 fixes 13 vulnerabilities, boosts YouTube playback, HTML5 support

An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2016:1217-01 Product: Red Hat Enterprise […]

How Bad Is Burr-Feinstein Anti-Encryption Legislation?
New Intelligence Bill Gives FBI More Secret Surveillance Power

Patrick Coleman discovered that missing input sanitising in the ADPCM decoder of the VLC media player may result in the execution of arbitrary code if a malformed media file is opened. For the stable distribution (jessie), this problem has been fixed in version 2.2.4-1~deb8u1. For the unstable distribution (sid), this problem has been fixed in […]

Two related issues have been discovered in Expat, a C library for parsing XML. CVE-2012-6702 It was introduced when CVE-2012-0876 was addressed. Stefan Sørensen discovered that the use of the function XML_Parse() seeds the random number generator generating repeated outputs for rand() calls. CVE-2016-5300 It is the product of an incomplete solution for CVE-2012-0876. The […]

Debian: 3598-1: vlc: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3598-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 07, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : vlc CVE ID : CVE-2016-5108 Patrick Coleman discovered that missing input sanitising in the ADPCM decoder of the VLC media player may result in the […]

Debian: 3597-1: expat: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3597-1 security@debian.org https://www.debian.org/security/ Luciano Bello June 07, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : expat CVE ID : CVE-2012-6702 CVE-2016-5300 Two related issues have been discovered in Expat, a C library for parsing XML. CVE-2012-6702 It was introduced when […]

Several vulnerabilities were discovered in spice, a SPICE protocol client and server library. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-0749 Jing Zhao of Red Hat discovered a memory allocation flaw, leading to a heap-based buffer overflow in spice’s smartcard interaction. A user connecting to a guest VM via spice can take […]

Red Hat: 2016:1207-01: glibc: Moderate Advisory Posted by Anthony Pell    An update for glibc is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: glibc security update Advisory ID: RHSA-2016:1207-01 Product: […]

Red Hat: 2016:1206-01: jenkins: Moderate Advisory Posted by Anthony Pell    An updated Jenkins package and image that includes security fixes are now available for Red Hat OpenShift Enterprise 3.2. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jenkins security update Advisory […]

Debian: 3596-1: spice: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3596-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 06, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : spice CVE ID : CVE-2016-0749 CVE-2016-2150 Several vulnerabilities were discovered in spice, a SPICE protocol client and server library. The Common Vulnerabilities and Exposures project […]

Red Hat: 2016:1205-01: spice: Important Advisory Posted by Anthony Pell    An update for spice is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: […]

Red Hat: 2016:1204-01: spice-server: Important Advisory Posted by Anthony Pell    An update for spice-server is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: […]

NTP Patches Flaws That Enable DDoS
WordPress plugin with 10,000+ installations being exploited in the wild
Key Tor developer Jacob Appelbaum leaves amidst sexual misconduct claims

Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.0.25. Please see the MariaDB 10.0 Release Notes for further details: For the stable distribution (jessie), these problems have been fixed in version 10.0.25-0+deb8u1. We recommend that you upgrade your mariadb-10.0 packages.

Gentoo: 201606-04 GnuPG: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in GnuPG and libgcrypt, the worst of which may allow a local attacker to obtain confidential key information. – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201606-03 libjpeg-turbo: Multiple vulnerabilities Posted by Anthony Pell    Two vulnerabilities have been discovered in libjpeg-turbo, the worse of which could allow remote attackers access to sensitive information. – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Debian: 3595-1: mariadb-10.0: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3595-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mariadb-10.0 CVE ID : CVE-2016-0640 CVE-2016-0641 CVE-2016-0643 CVE-2016-0644 CVE-2016-0646 CVE-2016-0647 CVE-2016-0648 CVE-2016-0649 CVE-2016-0650 CVE-2016-0655 CVE-2016-0666 CVE-2016-0668 Debian Bug : 823325 Several issues have been discovered […]

Gentoo: 201606-02 Puppet Server and Agent: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Puppet Server and Agent, the worst of which could lead to arbitrary code execution. – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201606-01 PuTTY: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in PuTTY, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – […]

Debian: 3548-3: samba: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3548-3 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : samba Debian Bug : 821002 822937 The upgrade to Samba 4.2 issued as DSA-3548-1 introduced several upstream regressions and as well a packaging regression causing […]

Debian: 3594-1: chromium-browser: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3594-1 security@debian.org https://www.debian.org/security/ Michael Gilbert June 04, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1696 CVE-2016-1697 CVE-2016-1698 CVE-2016-1699 CVE-2016-1700 CVE-2016-1701 CVE-2016-1702 Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1696 A cross-origin bypass […]

Slackware: 2016-155-01: ntp: Security Update Posted by Anthony Pell    New ntp packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. [More Info…] [slackware-security] ntp (SSA:2016-155-01) New ntp packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. Here are the details […]

Debian: 3593-1: libxml2: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3593-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libxml2 CVE ID : CVE-2015-8806 CVE-2016-1762 CVE-2016-1833 CVE-2016-1834 CVE-2016-1835 CVE-2016-1836 CVE-2016-1837 CVE-2016-1838 CVE-2016-1839 CVE-2016-1840 CVE-2016-2073 CVE-2016-3627 CVE-2016-3705 CVE-2016-4447 CVE-2016-4449 CVE-2016-4483 Debian Bug : 812807 813613 […]

Red Hat: 2016:1201-01: chromium-browser: Important Advisory Posted by Anthony Pell    An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1201-01 Product: Red Hat […]

Ubuntu: 2991-1: nginx vulnerability Posted by Anthony Pell    nginx could be made to crash if it received specially crafted networktraffic. ========================================================================== Ubuntu Security Notice USN-2991-1 June 02, 2016 nginx vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: […]

Ubuntu: 2990-1: ImageMagick vulnerabilities Posted by Anthony Pell    Several security issues were fixed in ImageMagick. ========================================================================== Ubuntu Security Notice USN-2990-1 June 02, 2016 imagemagick vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several […]

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1696 A cross-origin bypass was found in the bindings to extensions. CVE-2016-1697 Mariusz Mlynski discovered a cross-origin bypass in Blink/Webkit. CVE-2016-1698 Rob Wu discovered an information leak. CVE-2016-1699 Gregory Panakkal discovered an issue in the Developer Tools feature. CVE-2016-1700 Rob Wu discovered a use-after-free issue […]

Several vulnerabilities were discovered in libxml2, a library providing support to read, modify and write XML and HTML files. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause a denial-of-service against the application, or potentially the execution of arbitrary code with the […]

How the Top 5 PC Makers Open Your Laptop to Hackers
Hackers Find Bugs, Extort Ransom and Call it a Public Service

Debian: 3592-1: nginx: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3592-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : nginx CVE ID : CVE-2016-4450 It was discovered that a NULL pointer dereference in the Nginx code responsible for saving client request bodies to a […]

Judge Tosses Evidence Gathered by FBI’s Tor Exploit
The Romanian Teen Hacker Who Hunts Bugs to Resist the Dark Side

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1190-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2016:1190 Issue date: 2016-06-01 CVE Names: […]

Debian: 3591-1: imagemagick: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3591-1 security@debian.org https://www.debian.org/security/ Luciano Bello June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imagemagick CVE ID : CVE-2016-5118 Debian Bug : 825799 Bob Friesenhahn from the GraphicsMagick project discovered a command injection vulnerability in ImageMagick, a program suite […]

Ubuntu: 2989-1: Linux kernel vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2989-1 June 01, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: […]

Debian: 3590-1: chromium-browser: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3590-1 security@debian.org https://www.debian.org/security/ Michael Gilbert June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1667 CVE-2016-1668 CVE-2016-1669 CVE-2016-1670 CVE-2016-1672 CVE-2016-1673 CVE-2016-1674 CVE-2016-1675 CVE-2016-1676 CVE-2016-1677 CVE-2016-1678 CVE-2016-1679 CVE-2016-1680 CVE-2016-1681 CVE-2016-1682 CVE-2016-1683 CVE-2016-1684 CVE-2016-1685 CVE-2016-1686 CVE-2016-1687 CVE-2016-1688 […]

Ubuntu: 2988-1: LXD vulnerabilities Posted by Anthony Pell    Several security issues were fixed in LXD. ========================================================================== Ubuntu Security Notice USN-2988-1 May 31, 2016 lxd vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 Summary: Several security issues were fixed in LXD. Software Description: […]

Ubuntu: 2987-1: GD library vulnerabilities Posted by Anthony Pell    The GD library could be made to crash or run programs if it processed aspecially crafted image file. ========================================================================== Ubuntu Security Notice USN-2987-1 May 31, 2016 libgd2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – […]

Ubuntu: 2986-1: dosfstools vulnerabilities Posted by Anthony Pell    dosfstools could be made to crash or run programs if it processed aspecially crafted filesystem. ========================================================================== Ubuntu Security Notice USN-2986-1 May 31, 2016 dosfstools vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu […]

IPv6 support finally coming to Fail2Ban with next major release
A Car’s Computer Can ‘Fingerprint’ You in Minutes Based on How You Drive
65 million Tumblr account records are up for sale on the underground market

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1667 Mariusz Mylinski discovered a cross-origin bypass. CVE-2016-1668 Mariusz Mylinski discovered a cross-origin bypass in bindings to v8. CVE-2016-1669 Choongwoo Han discovered a buffer overflow in the v8 javascript library. CVE-2016-1670 A race condition was found that could cause the renderer process to reuse ids […]

Bob Friesenhahn from the GraphicsMagick project discovered a command injection vulnerability in ImageMagick, a program suite for image manipulation. An attacker with control on input image or the input filename can execute arbitrary commands with the privileges of the user running the application. This update removes the possibility of using pipe (|) in filenames to […]

It was discovered that a NULL pointer dereference in the Nginx code responsible for saving client request bodies to a temporary file might result in denial of service: Malformed requests could crash worker processes. For the stable distribution (jessie), this problem has been fixed in version 1.6.2-5+deb8u2. For the unstable distribution (sid), this problem has […]

Several vulnerabilities have been discovered in gdk-pixbuf, a toolkit for image loading and pixel buffer manipulation. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using gdk-pixbuf (application crash), or potentially, to execute arbitrary code with the privileges of the user running the application, if a malformed image […]

An update for ntp is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ntp security update Advisory ID: RHSA-2016:1141-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1141 Issue […]

Slackware: 2016-152-01: imagemagick: Security Update Posted by Anthony Pell    New imagemagick packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. [More Info…] [slackware-security] imagemagick (SSA:2016-152-01) New imagemagick packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 […]

Slackware: 2016-152-02: mozilla-thunderbird: Security Update Posted by Anthony Pell    New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. [More Info…] [slackware-security] mozilla-thunderbird (SSA:2016-152-02) New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ patches/packages/mozilla-thunderbird-45.1.1-i486-1_slack14.1.txz: Upgraded. […]

An update for squid is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: squid security update Advisory ID: RHSA-2016:1139-01 Product: Red Hat Enterprise […]

An update for squid is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: squid security update Advisory ID: RHSA-2016:1138-01 Product: Red Hat Enterprise […]

An update for squid34 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: squid34 security update Advisory ID: RHSA-2016:1140-01 Product: Red Hat Enterprise […]

Multiple vulnerabilities have been found in Firefox, Thunderbird, Network Security Services (NSS), and NetScape Portable Runtime (NSPR) with the worst of which may allow remote execution of arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201605-05 Linux-PAM: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Linux-PAM, allowing remote attackers to bypass the auth process and cause Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201605-04 rsync: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in rsync, the worst of which could allow remote attackers to write arbitrary files. – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201605-03 libfpx: Denial of Service Posted by Anthony Pell    A double free vulnerability has been discovered in libfpx that allows remote attackers to cause a Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – […]

Debian: 3589-1: gdk-pixbuf: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3589-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 30, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : gdk-pixbuf CVE ID : CVE-2015-7552 CVE-2015-8875 Several vulnerabilities have been discovered in gdk-pixbuf, a toolkit for image loading and pixel buffer manipulation. A remote attacker […]

Debian: 3588-1: symfony: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3588-1 security@debian.org https://www.debian.org/security/ Luciano Bello May 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : symfony CVE ID : CVE-2016-1902 CVE-2016-4423 Two vulnerabilities were discovered in Symfony, a PHP framework. CVE-2016-1902 Lander Brandt discovered that the class SecureRandom might generate […]

Two vulnerabilities were discovered in Symfony, a PHP framework. CVE-2016-1902 Lander Brandt discovered that the class SecureRandom might generate weak random numbers for cryptographic use under certain settings. If the functions random_bytes() or openssl_random_pseudo_bytes() are not available, the output of SecureRandom should not be consider secure. CVE-2016-4423 Marek Alaksa from Citadelo discovered that it is […]

Researcher Pockets $30,000 in Chrome Bounties
Reddit forces password reset of 100,000 users

Ubuntu: 2985-2: GNU C Library regression Posted by Anthony Pell    USN-2985-1 introduced a regression in the GNU C Library. ========================================================================== Ubuntu Security Notice USN-2985-2 May 26, 2016 eglibc, glibc regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: […]

Major DNS provider hit by mysterious, focused DDoS attack
Hacker faces 10 years in prison for hacking highway sign with “Drive Crazy Yall”
FBI refuses to release Tor exploit details, evidence thrown out of court

Several vulnerabilities were discovered in libgd2, a library for programmatic graphics creation and manipulation. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using the libgd2 library. For the stable distribution (jessie), these problems have been fixed in version 2.1.0-5+deb8u3. For the unstable distribution (sid), these problems have […]

An update for rh-mariadb100-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: rh-mariadb100-mariadb security update Advisory ID: RHSA-2016:1132-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2016:1132 Issue date: 2016-05-26 CVE Names: CVE-2015-3210 CVE-2015-3217 CVE-2015-4792 […]

Ubuntu: 2985-1: GNU C Library vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the GNU C Library. ========================================================================== Ubuntu Security Notice USN-2985-1 May 25, 2016 eglibc, glibc vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS […]

Ubuntu: 2950-5: Samba regression Posted by Anthony Pell    USN-2950-1 introduced a regression in Samba. ========================================================================== Ubuntu Security Notice USN-2950-5 May 25, 2016 samba regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: USN-2950-1 introduced a regression in Samba. […]

Slackware: 2016-145-01: libarchive: Security Update Posted by Anthony Pell    New libarchive packages are available for Slackware 14.1 and -current to fix a security issue. [More Info…] [slackware-security] libarchive (SSA:2016-145-01) New libarchive packages are available for Slackware 14.1 and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ […]

Red Hat: 2016:1106-01: jq: Moderate Advisory Posted by Anthony Pell    An update for jq is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jq security update Advisory ID: RHSA-2016:1106-01 Product: Red Hat […]

Several security issues were fixed in PHP. ========================================================================== Ubuntu Security Notice USN-2984-1 May 24, 2016 php5, php7.0 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in PHP. Software Description: […]

An update for kernel is now available for Red Hat Enterprise Linux 6.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:1100-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1100.html […]

Paul Vixie on IPv6 NAT, IPv6 security and Internet of Things
PGP co-founder rejoins Apple to bring better encryption to the masses
The Answer is always the same: Layers of Security
Linux 4.7 Gets a Security Boost with ChromeOS Feature

It was discovered that a buffer overflow in the XMLRPC response encoding code of the Atheme IRC services may result in denial of service. For the stable distribution (jessie), this problem has been fixed in version 6.0.11-2+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 7.0.7-2. For the unstable distribution (sid), […]

Red Hat: 2016:1098-01: jq: Moderate Advisory Posted by Anthony Pell    An update for jq is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jq security update Advisory […]

Red Hat: 2016:1099-01: jq: Moderate Advisory Posted by Anthony Pell    An update for jq is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jq security update Advisory […]

Debian: 3586-1: atheme-services: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3586-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 23, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : atheme-services CVE ID : CVE-2016-4478 It was discovered that a buffer overflow in the XMLRPC response encoding code of the Atheme IRC services may result […]

An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1096-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1096.html Issue […]

New Surveillance System May Let Cops Use All of the Cameras
Boston BSides needs more space to grow
Where Should Security Keys be Kept in the Cloud?

Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP which could result in denial of service. For the stable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u6. For the testing distribution (stretch), these problems have been fixed in version 2.0.3+geed34f0-1. For the unstable distribution (sid), these problems have […]

Debian: 3585-1: wireshark: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3585-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 22, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wireshark CVE ID : CVE-2016-4006 CVE-2016-4079 CVE-2016-4080 CVE-2016-4081 CVE-2016-4082 CVE-2016-4085 Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP which […]

Slackware: 2016-141-01: curl: Security Update Posted by Anthony Pell    New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. [More Info…] [slackware-security] curl (SSA:2016-141-01) New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are […]

Everything We Know About How the FBI Hacks People
Hacker fans give Mr. Robot website free security checkup
Hidden Microphones Exposed As Part of Government Surveillance Program In The Bay Area

Gustavo Grieco discovered several flaws in the way librsvg, a SAX-based renderer library for SVG files, parses SVG files with circular definitions. A remote attacker can take advantage of these flaws to cause an application using the librsvg library to crash. For the stable distribution (jessie), these problems have been fixed in version 2.40.5-1+deb8u2. For […]