Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3584-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 19, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : librsvg CVE ID : CVE-2015-7558 CVE-2016-4347 CVE-2016-4348 Gustavo Grieco discovered several flaws in the way librsvg, a SAX-based renderer library for SVG files, parses SVG files with circular definitions. A remote attacker can take […]

It was discovered that the swift3 (S3 compatibility) middleware plugin for Swift performed insufficient validation of date headers which might result in replay attacks. For the stable distribution (jessie), this problem has been fixed in version 1.7-5+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 1.9-1. For the unstable distribution (sid), […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3583-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : swift-plugin-s3 CVE ID : CVE-2015-8466 Debian Bug : 822688 It was discovered that the swift3 (S3 compatibility) middleware plugin for Swift performed insufficient validation of date headers which might result in replay attacks. For […]

Developer of anonymous Tor software dodges FBI, leaves US
It’s trivially easy to identify you based on records of your calls and texts
How to empty your bank’s vault with a few clicks and lines of code

Posted by Anthony Pell    USN-2950-1 introduced regressions in Samba. ========================================================================== Ubuntu Security Notice USN-2950-4 May 18, 2016 samba regressions ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: USN-2950-1 introduced regressions in Samba. Software Description: – samba: SMB/CIFS file, print, and login server for Unix Details: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2950-4: Samba regressions Ubuntu: 2983-1: Expat vulnerability Debian: 3582-1: expat: Summary Ubuntu: 2982-1: Libksba vulnerabilities Ubuntu: 2981-1: libarchive vulnerabilities Ubuntu: 2980-1: libndp vulnerability Debian: 3581-1: libndp: Summary Gentoo: 201605-02 […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3582-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : expat CVE ID : CVE-2016-0718 Gustavo Grieco discovered that Expat, an XML parsing C library, does not properly handle certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. […]

Posted by Anthony Pell    Libksba could be made to crash or run programs if it decoded speciallycrafted data. ========================================================================== Ubuntu Security Notice USN-2982-1 May 17, 2016 libksba vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 […]

libarchive could be made to crash or run programs if it opened a speciallycrafted file. ========================================================================== Ubuntu Security Notice USN-2981-1 May 17, 2016 libarchive vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: libarchive could […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2950-4: Samba regressions Ubuntu: 2983-1: Expat vulnerability Debian: 3582-1: expat: Summary Ubuntu: 2982-1: Libksba vulnerabilities Ubuntu: 2981-1: libarchive vulnerabilities Ubuntu: 2980-1: libndp vulnerability Debian: 3581-1: libndp: Summary Gentoo: 201605-02 […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3581-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 17, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libndp CVE ID : CVE-2016-3698 Debian Bug : 824545 Julien Bernard discovered that libndp, a library for the IPv6 Neighbor Discovery Protocol, does not properly perform input and origin checks during the reception of […]

Posted by Anthony Pell    Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2978-2 May 16, 2016 linux-lts-wily vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-wily: Linux hardware enablement kernel from Wily for Trusty […]

Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2978-1 May 16, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: David Matlack discovered that the Kernel-based […]

The system could be made to crash or run programs as an administrator. ========================================================================== Ubuntu Security Notice USN-2979-4 May 16, 2016 linux-snapdragon vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS Summary: The system could be made to crash or run programs as an administrator. Software Description: […]

Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2979-2 May 16, 2016 linux-lts-xenial vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty […]

Gustavo Grieco discovered that Expat, an XML parsing C library, does not properly handle certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. A remote attacker can take advantage of this flaw to cause an application using the Expat library to crash, or potentially, to execute arbitrary code with […]

Nikolay Ermishkin from the Mail.Ru Security Team and Stewie discovered several vulnerabilities in ImageMagick, a program suite for image manipulation. These vulnerabilities, collectively known as ImageTragick, are the consequence of lack of sanitization of untrusted input. An attacker with control on the image input could, with the privileges of the user running the application, execute […]

Julien Bernard discovered that libndp, a library for the IPv6 Neighbor Discovery Protocol, does not properly perform input and origin checks during the reception of a NDP message. An attacker in a non-local network could use this flaw to advertise a node as a router, and cause a denial of service attack, or act as […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3579-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 16, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xerces-c CVE ID : CVE-2016-2099 Debian Bug : 823863 Gustavo Grieco discovered an use-after-free vulnerability in xerces-c, a validating XML parser library for C++, due to not properly handling invalid characters in XML input […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3578-1 security@debian.org https://www.debian.org/security/ Alessandro Ghedini May 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libidn CVE ID : CVE-2015-2059 It was discovered that libidn, the GNU library for Internationalized Domain Names (IDNs), did not correctly handle invalid UTF-8 input, causing an out-of-bounds read. This could allow attackers to […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3577-1 security@debian.org https://www.debian.org/security/ Alessandro Ghedini May 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : jansson CVE ID : CVE-2016-4425 Debian Bug : 823238 Gustavo Grieco discovered that jansson, a C library for encoding, decoding and manipulating JSON data, did not limit the recursion depth when parsing JSON arrays […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3576-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : icedove CVE ID : CVE-2016-1979 CVE-2016-2805 CVE-2016-2807 Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary […]

Gustavo Grieco discovered an use-after-free vulnerability in xerces-c, a validating XML parser library for C++, due to not properly handling invalid characters in XML input documents in the DTDScanner. For the stable distribution (jessie), this problem has been fixed in version 3.1.1-5.1+deb8u2. For the testing distribution (stretch), this problem has been fixed in version 3.1.3+debian-2. […]

It was discovered that libidn, the GNU library for Internationalized Domain Names (IDNs), did not correctly handle invalid UTF-8 input, causing an out-of-bounds read. This could allow attackers to disclose sensitive information from an application using the libidn library. For the stable distribution (jessie), this problem has been fixed in version 1.29-1+deb8u1. For the testing […]

Gustavo Grieco discovered that jansson, a C library for encoding, decoding and manipulating JSON data, did not limit the recursion depth when parsing JSON arrays and objects. This could allow remote attackers to cause a denial of service (crash) via stack exhaustion, using crafted JSON data. For the stable distribution (jessie), this problem has been […]

Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service. For the stable distribution (jessie), these problems have been fixed in version 38.8.0-1~deb8u1. For the unstable distribution (sid), these problems will be fixed […]

Severe 7-Zip vulnerabilities cause top security, software tools patch panic
The sport of threat hunting, and who should be in the game
Panama paper trail goes online with massive searchable database

It was discovered that XStream, a Java library to serialize objects to XML and back again, was susceptible to XML External Entity attacks. For the stable distribution (jessie), this problem has been fixed in version 1.4.7-2+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 1.4.9-1. For the unstable distribution (sid), this […]

Posted by Anthony Pell    An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1080-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1080.html […]

An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2016:1079-01 Product: Red Hat Enterprise Linux Supplementary Advisory […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3575-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 12, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libxstream-java CVE ID : CVE-2016-3674 It was discovered that XStream, a Java library to serialize objects to XML and back again, was susceptible to XML External Entity attacks. For the stable distribution (jessie), this […]

An update for docker is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: docker security, bug fix, and enhancement update Advisory ID: RHSA-2016:1034-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1034.html Issue […]

Several security issues were fixed in QEMU. ========================================================================== Ubuntu Security Notice USN-2974-1 May 12, 2016 qemu, qemu-kvm vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in QEMU. Software Description: […]

Twitter May Have Cut Spy Agencies Off From Its Flood of Data
Mozilla Wants More Details on Browser Bug Exploited in an FBI Probe

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1033-01 Product: Red […]

Posted by Anthony Pell    An update for kernel-rt is now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security and bug fix update […]

Posted by Anthony Pell    An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security, bug fix, and enhancement […]

An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2016:1041-01 Product: Red Hat Enterprise […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:1033-01: kernel: Important Advisory Red Hat: 2016:1055-01: kernel-rt: Important Advisory Red Hat: 2016:1051-01: kernel-rt: Important Advisory Red Hat: 2016:1041-01: thunderbird: Important Advisory Slackware: 2016-132-01: mozilla-thunderbird: Security Update Red […]

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-ibm security update Advisory ID: RHSA-2016:1039-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1039.html Issue date: 2016-05-11 CVE Names: […]

Updated openshift packages that fix one security issue are now available for Red Hat OpenShift Enterprise 3.1. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openshift security update Advisory ID: RHSA-2016:1038-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2016:1038 Issue date: 2016-05-11 CVE […]

An update for pcre is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: pcre security update Advisory ID: RHSA-2016:1025-01 Product: Red Hat Enterprise Linux […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3565-2 security@debian.org https://www.debian.org/security/ Sebastien Delafond May 11, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : monotone ovito pdns qtcreator softhsm Debian Bug : 823823 This updates fixes a regression introduced in botan1.10 by DSA-3565-1: packages depending on libbotan1.10 needed to be rebuilt against the latest version to function properly. […]

SPF (SpeedPhish Framework) – E-mail Phishing Toolkit
Hacker Lexicon: SQL Injections, an Everyday Hacker’s Favorite Attack

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]

Posted by Anthony Pell    Several security issues were fixed in OpenJDK 6. ========================================================================== Ubuntu Security Notice USN-2972-1 May 10, 2016 openjdk-6 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in OpenJDK 6. Software Description: – openjdk-6: Open Source Java […]

Posted by Anthony Pell    An update for icedtea-web is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: icedtea-web security, bug fix, and […]

An update for openssh is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openssh security, bug fix, and enhancement update Advisory ID: RHSA-2016:0741-01 […]

An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:0855-01 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]

Security fix for CVE-2016-1548, CVE-2016-2516, CVE-2016-2518, CVE-2016-1550 ——————————————————————————– Fedora Update Notification FEDORA-2016-5b2eb0bf9c 2016-05-10 11:45:44.970959 ——————————————————————————– Name : ntp Product : Fedora 23 Version : 4.2.6p5 Release : 40.fc23 URL : http://www.ntp.org Summary : The NTP daemon and utilities Description : The Network Time Protocol (NTP) is used to synchronize a computer’s time with another reference […]

Posted by Anthony Pell    This update contains minor security fixes (for CVE-2016-3075, CVE-2016-1234,CVE-2015-8778, CVE-2015-8776, CVE-2014-9761, CVE-2015-8779) and collects fixesfor bugs encountered by Fedora users. ——————————————————————————– Fedora Update Notification FEDORA-2016-68abc0be35 2016-05-10 11:45:44.966689 ——————————————————————————– Name : glibc Product : Fedora 23 Version : 2.22 Release : 15.fc23 URL : http://www.gnu.org/software/glibc/ Summary : The GNU libc libraries […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]

Security fix for CVE-2016-2108, CVE-2016-2107, CVE-2016-2105, CVE-2016-2106 ——————————————————————————– Fedora Update Notification FEDORA-2016-1e39d934ed 2016-05-10 11:43:00.963747 ——————————————————————————– Name : openssl Product : Fedora 22 Version : 1.0.1k Release : 15.fc22 URL : http://www.openssl.org/ Summary : Utilities from the general purpose cryptography library with TLS implementation Description : The OpenSSL toolkit provides support for secure communications between machines. […]

CVE-2016-3710: QEMU: out-of-bounds memory access issue

Several vulnerabilities were discovered in qemu, a fast processor emulator. CVE-2016-3710 Wei Xiao and Qinghao Tang of 360.cn Inc discovered an out-of-bounds read and write flaw in the QEMU VGA module. A privileged guest user could use this flaw to execute arbitrary code on the host with the privileges of the hosting QEMU process. CVE-2016-3712 […]

Nitin Venkatesh discovered that websvn, a web viewer for Subversion repositories, is susceptible to cross-site scripting attacks via specially crafted file and directory names in repositories. For the stable distribution (jessie), this problem has been fixed in version 2.3.3-1.2+deb8u2. We recommend that you upgrade your websvn packages.

WordPress Patches SOME, XSS Flaws in Version 4.5.2
Garbage in, garbage out: Why Ars ignored this week’s massive password breach
Security researcher arrested for disclosing US election website vulnerabilities
This unusual botnet targets scientists, engineers, and academics
Founder of virtual currency sentenced to 20 years in prison

Rock Stevens, Andrew Ruef and Marcin Icewall Noga discovered a heap-based buffer overflow vulnerability in the zip_read_mac_metadata function in libarchive, a multi-format archive and compression library, which may lead to the execution of arbitrary code if a user or automated system is tricked into processing a specially crafted ZIP file. For the stable distribution (jessie), […]

Simon McVittie discovered a cross-site scripting vulnerability in the error reporting of Ikiwiki, a wiki compiler. This update also hardens ikiwiki’s use of imagemagick in the img plugin. For the stable distribution (jessie), this problem has been fixed in version 3.20141016.3. For the unstable distribution (sid), this problem has been fixed in version 3.20160506. We […]

Posted by Anthony Pell    Security fix for CVE-2015-8869 ——————————————————————————– Fedora Update Notification FEDORA-2016-1c4e616564 2016-05-09 00:02:50.053328 ——————————————————————————– Name : ocaml Product : Fedora 24 Version : 4.02.3 Release : 3.fc24 URL : http://www.ocaml.org Summary : OCaml compiler and programming environment Description : OCaml is a high-level, strongly-typed, functional and object-oriented programming language from the ML […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3571-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 08, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : ikiwiki CVE ID : CVE-2016-4561 Simon McVittie discovered a cross-site scripting vulnerability in the error reporting of Ikiwiki, a wiki compiler. This update also hardens ikiwiki’s use of imagemagick in the img plugin. For […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Posted by Anthony Pell    Update to version 20160222-1 to fix bugs(#1285888,1307846,1320511,1320956,1320958) ——————————————————————————– Fedora Update Notification FEDORA-2016-6c03d31846 2016-05-07 11:36:53.859231 ——————————————————————————– Name : parallel Product : Fedora 24 Version : 20160222 Release : 1.fc24 URL : http://www.gnu.org/software/parallel/ Summary : Shell tool for executing jobs in parallel Description : GNU Parallel is a shell tool for executing […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

10-year-old gets $10,000 bounty for finding Instagram vulnerability
Another breach, another dollar: Is it time to kill the password?
Millions of stolen email credentials shared online by Russian hacker

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3570-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mercurial CVE ID : CVE-2016-3105 Blake Burkhart discovered an arbitrary code execution flaw in Mercurial, a distributed version control system, when using the convert extension on Git repositories with specially crafted names. This flaw […]

Posted by Anthony Pell    Don’t export background images from deleted slides. ——————————————————————————– Fedora Update Notification FEDORA-2016-34f9ed9753 2016-05-05 10:04:33.646885 ——————————————————————————– Name : libreoffice Product : Fedora 23 Version : 5.0.6.2 Release : 3.fc23 URL : http://www.libreoffice.org/ Summary : Free Software Productivity Suite Description : LibreOffice is an Open Source, community-developed, office productivity suite. It includes […]

– new upstream version (46.0.1) – fixed focus on TWM (rhbz#1322626) ——————————————————————————– Fedora Update Notification FEDORA-2016-25843fda6b 2016-05-05 10:04:33.645657 ——————————————————————————– Name : firefox Product : Fedora 23 Version : 46.0.1 Release : 1.fc23 URL : https://www.mozilla.org/firefox/ Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance […]

Hitler’s “unbreakable” encryption machine – and the Bletchley Park devices which cracked the code
Big data breaches found at major email services – expert

It was discovered that libpam-sshauth, a PAM module to authenticate using an SSH server, does not correctly handle system users. In certain configurations an attacker can take advantage of this flaw to gain root privileges. For the stable distribution (jessie), this problem has been fixed in version 0.3.1-1+deb8u1. For the testing distribution (stretch), this problem […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3569-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openafs CVE ID : CVE-2015-8312 CVE-2016-2860 Two vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-8312 Potential denial of service […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3568-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libtasn1-6 CVE ID : CVE-2016-4008 Pascal Cuoq and Miod Vallat discovered that Libtasn1, a library to manage ASN.1 structures, does not correctly handle certain malformed DER certificates. A remote attacker can take advantage of […]

Posted by Anthony Pell    Several security issues were fixed in OpenJDK 7. ========================================================================== Ubuntu Security Notice USN-2964-1 May 05, 2016 openjdk-7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: Several security issues were fixed in OpenJDK 7. Software Description: – openjdk-7: […]

Posted by Anthony Pell    Several security issues were fixed in OpenJDK 8. ========================================================================== Ubuntu Security Notice USN-2963-1 May 05, 2016 openjdk-8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS Summary: Several security issues were fixed in OpenJDK 8. Software Description: – openjdk-8: Open Source Java […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3569-1: openafs: Summary Debian: 3568-1: libtasn1-6: Summary Ubuntu: 2964-1: OpenJDK 7 vulnerabilities Ubuntu: 2963-1: OpenJDK 8 vulnerabilities Ubuntu: 2961-1: Little CMS vulnerability Debian: 3567-1: libpam-sshauth: Summary Fedora 23 obs-signd-2.2.1-8.fc23 […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3567-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 04, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libpam-sshauth CVE ID : CVE-2016-4422 It was discovered that libpam-sshauth, a PAM module to authenticate using an SSH server, does not correctly handle system users. In certain configurations an attacker can take advantage of […]