Posted by Anthony Pell Update to xerces-c 3.1.3, fixing CVE-2016-0729 ——————————————————————————– Fedora Update Notification FEDORA-2016-9ff972ca42 2016-04-12 09:36:30.965273 ——————————————————————————– Name : xerces-c Product : Fedora 24 Version : 3.1.3 Release : 1.fc24 URL : http://xml.apache.org/xerces-c/ Summary : Validating XML Parser Description : Xerces-C is a validating XML parser written in a portable subset of C++. […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 postgresql-9.5.2-1.fc24 Fedora 24 xerces-c-3.1.3-1.fc24 Fedora 24 libreswan-3.17-1.fc24 Red Hat: 2016:0617-01: kernel: Moderate Advisory Debian: 3485-2: didiwiki: Summary Red Hat: 2016:0615-01: openvswitch: Important Advisory Ubuntu: 2948-2: Linux kernel (Utopic […]
An update for kernel is now available for Red Hat Enterprise Linux 6.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security and bug fix update Advisory ID: RHSA-2016:0617-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0617.html Issue […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3485-2 security@debian.org https://www.debian.org/security/ Sebastien Delafond April 12, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : didiwiki Debian Bug : 818708 The update for didiwiki issued as DSA-3485-1 introduced a regression that caused a large number of valid pages to not be accessible anymore. This occurred mostly for pages whose […]
Updated openvswitch packages that fix one security issue are now available for Red Hat OpenShift Enterprise 3.1. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openvswitch security update Advisory ID: RHSA-2016:0615-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2016:0615 Issue date: 2016-04-11 CVE […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 postgresql-9.5.2-1.fc24 Fedora 24 xerces-c-3.1.3-1.fc24 Fedora 24 libreswan-3.17-1.fc24 Red Hat: 2016:0617-01: kernel: Moderate Advisory Debian: 3485-2: didiwiki: Summary Red Hat: 2016:0615-01: openvswitch: Important Advisory Ubuntu: 2948-2: Linux kernel (Utopic […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3547-1 security@debian.org https://www.debian.org/security/ Luciano Bello April 11, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imagemagick Debian Bug : 811308 Several vulnerabilities were discovered in Imagemagick, a program suite for image manipulation. This update fixes a large number of potential security problems such as null-pointer access and buffer-overflows that […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 pulp-rpm-2.8.2-1.fc24 Fedora 24 pulp-puppet-2.8.2-1.fc24 Fedora 24 pulp-2.8.2-1.fc24 Fedora 23 python-pillow-3.0.0-4.fc23 Fedora 22 python-pillow-2.8.2-5.fc22 Fedora 23 xen-4.5.3-1.fc23 Fedora 23 latex2rtf-2.3.10-1.fc23 Fedora 23 php-5.6.20-1.fc23 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 pulp-rpm-2.8.2-1.fc24 Fedora 24 pulp-puppet-2.8.2-1.fc24 Fedora 24 pulp-2.8.2-1.fc24 Fedora 23 python-pillow-3.0.0-4.fc23 Fedora 22 python-pillow-2.8.2-5.fc22 Fedora 23 xen-4.5.3-1.fc23 Fedora 23 latex2rtf-2.3.10-1.fc23 Fedora 23 php-5.6.20-1.fc23 Community Linux Events Linux User Groups […]
Update to 2.8.2 for CVE-2016-3095. ——————————————————————————– Fedora Update Notification FEDORA-2016-f75bd73891 2016-04-11 09:11:06.297385 ——————————————————————————– Name : pulp Product : Fedora 24 Version : 2.8.2 Release : 1.fc24 URL : https://github.com/pulp/pulp Summary : An application for managing software repositories Description : Pulp provides replication, access, and accounting for software repositories. ——————————————————————————– Update Information: Update to 2.8.2 for […]
This update fixes an integer overflow in Jpeg2KEncode.c causing a bufferoverflow (CVE-2016-3076). ——————————————————————————– Fedora Update Notification FEDORA-2016-35700c5956 2016-04-10 10:23:15.141497 ——————————————————————————– Name : python-pillow Product : Fedora 23 Version : 3.0.0 Release : 4.fc23 URL : http://python-pillow.github.io/ Summary : Python image processing library Description : Python image processing library, fork of the Python Imaging Library (PIL) […]
This update fixes an integer overflow in Jpeg2KEncode.c causing a bufferoverflow (CVE-2016-3076). ——————————————————————————– Fedora Update Notification FEDORA-2016-6ad4474058 2016-04-10 10:18:57.729299 ——————————————————————————– Name : python-pillow Product : Fedora 22 Version : 2.8.2 Release : 5.fc22 URL : http://python-pillow.github.io/ Summary : Python image processing library Description : Python image processing library, fork of the Python Imaging Library (PIL) […]
update to 4.5.3 —- broken AMD FPU FIP/FDP/FOP leak workaround [XSA-172,CVE-2016-3158, CVE-2016-3159] ——————————————————————————– Fedora Update Notification FEDORA-2016-e5432ca977 2016-04-09 10:22:58.046533 ——————————————————————————– Name : xen Product : Fedora 23 Version : 4.5.3 Release : 1.fc23 URL : http://xen.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command […]
Update to 2.3.10 for CVE-2015-8106 ——————————————————————————– Fedora Update Notification FEDORA-2016-b9368247d4 2016-04-09 10:22:58.046350 ——————————————————————————– Name : latex2rtf Product : Fedora 23 Version : 2.3.10 Release : 1.fc23 URL : http://latex2rtf.sourceforge.net/ Summary : LaTeX to RTF converter that handles equations, figures, and cross-references Description : LaTeX2rtf is a translator program which is intended to translate a LaTeX […]
Posted by Anthony Pell 31 Mar 2016, **PHP 5.6.20** **CLI Server:** * Fixed bug php#69953 (SupportMKCALENDAR request method). (Christoph) **Core:** * Fixed bug php#71596(Segmentation fault on ZTS with date function (setlocale)). (Anatol) **Curl:*** Fixed bug php#71694 (Support constant CURLM_ADDED_ALREADY). (mpyw) **Date:*** Fixed bug php#71635 (DatePeriod::getEndDate segfault). (Thomas Punt)**Fileinfo:** * Fixed bug php#71527 (Buffer over-write […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 pulp-rpm-2.8.2-1.fc24 Fedora 24 pulp-puppet-2.8.2-1.fc24 Fedora 24 pulp-2.8.2-1.fc24 Fedora 23 python-pillow-3.0.0-4.fc23 Fedora 22 python-pillow-2.8.2-5.fc22 Fedora 23 xen-4.5.3-1.fc23 Fedora 23 latex2rtf-2.3.10-1.fc23 Fedora 23 php-5.6.20-1.fc23 Community Linux Events Linux User Groups […]
Posted by Anthony Pell 31 Mar 2016, **PHP 5.6.20** **CLI Server:** * Fixed bug php#69953 (SupportMKCALENDAR request method). (Christoph) **Core:** * Fixed bug php#71596(Segmentation fault on ZTS with date function (setlocale)). (Anatol) **Curl:*** Fixed bug php#71694 (Support constant CURLM_ADDED_ALREADY). (mpyw) **Date:*** Fixed bug php#71635 (DatePeriod::getEndDate segfault). (Thomas Punt)**Fileinfo:** * Fixed bug php#71527 (Buffer over-write […]
update to 4.5.3 —- broken AMD FPU FIP/FDP/FOP leak workaround [XSA-172,CVE-2016-3158, CVE-2016-3159] ——————————————————————————– Fedora Update Notification FEDORA-2016-5f196e4e4a 2016-04-09 10:20:41.903381 ——————————————————————————– Name : xen Product : Fedora 22 Version : 4.5.3 Release : 1.fc22 URL : http://xen.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 pulp-rpm-2.8.2-1.fc24 Fedora 24 pulp-puppet-2.8.2-1.fc24 Fedora 24 pulp-2.8.2-1.fc24 Fedora 23 python-pillow-3.0.0-4.fc23 Fedora 22 python-pillow-2.8.2-5.fc22 Fedora 23 xen-4.5.3-1.fc23 Fedora 23 latex2rtf-2.3.10-1.fc23 Fedora 23 php-5.6.20-1.fc23 Community Linux Events Linux User Groups […]
Hans Jerry Illikainen discovered that missing input sanitising in the BMP processing code of the optipng PNG optimiser may result in denial of service or the execution of arbitrary code if a malformed file is processed. For the oldstable distribution (wheezy), this problem has been fixed in version 0.6.4-1+deb7u2. This update also fixes CVE-2015-7801, which […]
An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2016:0610-01 Product: Red Hat Enterprise Linux Supplementary Advisory […]
USN-2917-1 introduced several regressions in Firefox. ========================================================================== Ubuntu Security Notice USN-2917-2 April 07, 2016 firefox regressions ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: USN-2917-1 introduced several regressions in Firefox. Software Description: – firefox: Mozilla Open Source web browser […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3546-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 07, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : optipng CVE ID : CVE-2016-2191 Hans Jerry Illikainen discovered that missing input sanitising in the BMP processing code of the optipng PNG optimiser may result in denial of service or the execution of arbitrary […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3545-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 07, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : cgit CVE ID : CVE-2016-1899 CVE-2016-1900 CVE-2016-1901 Debian Bug : 812411 Several vulnerabilities were discovered in cgit, a fast web frontend for git repositories written in C. A remote attacker can take advantage of […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3544-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 07, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : python-django CVE ID : CVE-2016-2512 CVE-2016-2513 Debian Bug : 816434 Several vulnerabilities were discovered in Django, a high-level Python web development framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2512 Mark […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Red Hat: 2016:0610-01: flash-plugin: Critical Advisory Ubuntu: 2917-2: Firefox regressions Debian: 3546-1: optipng: Summary Debian: 3545-1: cgit: Summary Debian: 3544-1: python-django: Summary Fedora 23 libmaxminddb-1.2.0-1.fc23 Fedora 23 mercurial-3.5.2-1.fc23 Fedora 22 […]
Security fix for CVE-2016-3630, CVE-2016-3068, CVE-2016-3069 and minor upgrade ——————————————————————————– Fedora Update Notification FEDORA-2016-b7f1f8e3bf 2016-04-07 12:06:32.149355 ——————————————————————————– Name : mercurial Product : Fedora 23 Version : 3.5.2 Release : 1.fc23 URL : http://www.selenic.com/mercurial/ Summary : Mercurial — a distributed SCM Description : Mercurial is a fast, lightweight source control management system designed for efficient handling […]
New upstream release with security bug fix ——————————————————————————– Fedora Update Notification FEDORA-2016-15fb7deba0 2016-04-07 12:06:06.793002 ——————————————————————————– Name : python-rsa Product : Fedora 22 Version : 3.4.1 Release : 1.fc22 URL : http://stuvel.eu/rsa Summary : Pure-Python RSA implementation Description : Python-RSA is a pure-Python RSA implementation. It supports encryption and decryption, signing and verifying signatures, and key […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Red Hat: 2016:0610-01: flash-plugin: Critical Advisory Ubuntu: 2917-2: Firefox regressions Debian: 3546-1: optipng: Summary Debian: 3545-1: cgit: Summary Debian: 3544-1: python-django: Summary Fedora 23 libmaxminddb-1.2.0-1.fc23 Fedora 23 mercurial-3.5.2-1.fc23 Fedora 22 […]
Security fix for CVE-2016-3630, CVE-2016-3068, CVE-2016-3069 and minor upgrade ——————————————————————————– Fedora Update Notification FEDORA-2016-79604dde9f 2016-04-07 12:06:06.791542 ——————————————————————————– Name : mercurial Product : Fedora 22 Version : 3.5.2 Release : 1.fc22 URL : http://www.selenic.com/mercurial/ Summary : Mercurial — a distributed SCM Description : Mercurial is a fast, lightweight source control management system designed for efficient handling […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
New upstream release with security bug fix ——————————————————————————– Fedora Update Notification FEDORA-2016-df2529c86c 2016-04-06 14:04:06.632466 ——————————————————————————– Name : python-rsa Product : Fedora 23 Version : 3.4.1 Release : 1.fc23 URL : http://stuvel.eu/rsa Summary : Pure-Python RSA implementation Description : Python-RSA is a pure-Python RSA implementation. It supports encryption and decryption, signing and verifying signatures, and key […]
Update Node.js to the 5.x stable branch This update also includes a fix for aman-in-the-middle vulnerability in npm. ——————————————————————————– Fedora Update Notification FEDORA-2016-6ab2d29fba 2016-04-06 14:05:38.729188 ——————————————————————————– Name : nodejs Product : Fedora 24 Version : 5.10.0 Release : 1.fc24 URL : http://nodejs.org/ Summary : JavaScript runtime Description : Node.js is a platform built on Chrome’s […]
Update Node.js to the 5.x stable branch This update also includes a fix for aman-in-the-middle vulnerability in npm. ——————————————————————————– Fedora Update Notification FEDORA-2016-6ab2d29fba 2016-04-06 14:05:38.729188 ——————————————————————————– Name : nodejs-sqlite3 Product : Fedora 24 Version : 3.1.2 Release : 3.fc24 URL : https://github.com/mapbox/node-sqlite3 Summary : Asynchronous, non-blocking SQLite3 bindings for Node.js Description : Asynchronous, non-blocking SQLite3 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Several vulnerabilities were discovered in Django, a high-level Python web development framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2512 Mark Striemer discovered that some user-supplied redirect URLs containing basic authentication credentials are incorrectly handled, potentially allowing a remote attacker to perform a malicious redirect or a cross-site scripting attack. CVE-2016-2513 Sjoerd […]
Several vulnerabilities were discovered in cgit, a fast web frontend for git repositories written in C. A remote attacker can take advantage of these flaws to perform cross-site scripting, header injection or denial of service attacks. For the stable distribution (jessie), these problems have been fixed in version 0.10.2.git2.0.1-3+deb8u1. For the testing distribution (stretch), these […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Red Hat: 2016:0601-01: bind: Important Advisory Ubuntu: 2947-3: Linux kernel (Raspberry Pi 2) vulnerabilities Ubuntu: 2949-1: Linux kernel (Vivid HWE) vulnerabilities Ubuntu: 2948-1: Linux kernel (Utopic HWE) vulnerabilities Ubuntu: 2947-2: […]
Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2947-3 April 06, 2016 linux-raspi2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux-raspi2: Linux kernel for Raspberry […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2949-1 April 06, 2016 linux-lts-vivid vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-vivid: Linux hardware enablement kernel from Vivid for Trusty […]
Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2948-1 April 06, 2016 linux-lts-utopic vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-utopic: Linux hardware enablement […]
Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2947-2 April 06, 2016 linux-lts-wily vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-wily: Linux hardware enablement […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2946-1 April 06, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: Venkatesh Pottem discovered a use-after-free […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2946-2 April 06, 2016 linux-lts-trusty vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise […]
Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2947-1 April 06, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: Ralf […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Red Hat: 2016:0601-01: bind: Important Advisory Ubuntu: 2947-3: Linux kernel (Raspberry Pi 2) vulnerabilities Ubuntu: 2949-1: Linux kernel (Vivid HWE) vulnerabilities Ubuntu: 2948-1: Linux kernel (Utopic HWE) vulnerabilities Ubuntu: 2947-2: […]
Posted by Anthony Pell An update for graphite2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: graphite2 security, bug fix, and enhancement […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3543-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : oar CVE ID : CVE-2016-1235 Emmanuel Thome discovered that missing sanitising in the oarsh command of OAR, a software used to manage jobs and resources of HPC clusters, could result in privilege escalation. For […]
Posted by Anthony Pell patch to fix #1319858,#1319859,#1319861 ——————————————————————————– Fedora Update Notification FEDORA-2016-0fb6577f07 2016-04-05 13:05:11.637168 ——————————————————————————– Name : vtun Product : Fedora 23 Version : 3.0.3 Release : 15.fc23 URL : http://vtun.sourceforge.net Summary : Virtual tunnel over TCP/IP networks Description : VTun provides a method for creating Virtual Tunnels over TCP/IP networks and allows […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Posted by Anthony Pell 31 Mar 2016, **PHP 5.6.20** **CLI Server:** * Fixed bug php#69953 (SupportMKCALENDAR request method). (Christoph) **Core:** * Fixed bug php#71596(Segmentation fault on ZTS with date function (setlocale)). (Anatol) **Curl:*** Fixed bug php#71694 (Support constant CURLM_ADDED_ALREADY). (mpyw) **Date:*** Fixed bug php#71635 (DatePeriod::getEndDate segfault). (Thomas Punt)**Fileinfo:** * Fixed bug php#71527 (Buffer over-write […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3541-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond April 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : roundcube CVE ID : CVE-2015-8770 High-Tech Bridge Security Research Lab discovered that Roundcube, a webmail client, contained a path traversal vulnerability. This flaw could be exploited by an attacker to access sensitive files on […]
Multiple vulnerabilities have been found in Xen, the worst of which cause a Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – Gentoo Linux Security […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Posted by Anthony Pell Libav could be made to crash or run programs as your login if it opened aspecially crafted file. ========================================================================== Ubuntu Security Notice USN-2944-1 April 04, 2016 libav vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Libav could be made to […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Posted by Anthony Pell patch to fix #1319858,#1319859,#1319861 ——————————————————————————– Fedora Update Notification FEDORA-2016-256f700c92 2016-04-04 17:23:29.743823 ——————————————————————————– Name : vtun Product : Fedora 24 Version : 3.0.3 Release : 15.fc24 URL : http://vtun.sourceforge.net Summary : Virtual tunnel over TCP/IP networks Description : VTun provides a method for creating Virtual Tunnels over TCP/IP networks and allows […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
High-Tech Bridge Security Research Lab discovered that Roundcube, a webmail client, contained a path traversal vulnerability. This flaw could be exploited by an attacker to access sensitive files on the server, or even execute arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 0.7.2-9+deb7u2. For the testing (stretch) and unstable […]
Several vulnerabilities have been discovered in Mercurial, a distributed version control system. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2016-3068 Blake Burkhart discovered that Mercurial allows URLs for Git subrepositories that could result in arbitrary code execution on clone. CVE-2016-3069 Blake Burkhart discovered that Mercurial allows arbitrary code execution when converting Git […]
Emmanuel Thome discovered that missing sanitising in the oarsh command of OAR, a software used to manage jobs and resources of HPC clusters, could result in privilege escalation. For the oldstable distribution (wheezy), this problem has been fixed in version 2.5.2-3+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 2.5.4-2+deb8u1. For […]
Posted by Anthony Pell A NetworkManager 1.0.x branch stable update: * Release notes:https://cgit.freedesktop.org/NetworkManager/NetworkManager/tree/NEWS?h=1.0.12 *Release announcement: https://mail.gnome.org/archives/networkmanager-list/2016-April/msg00000.html ——————————————————————————– Fedora Update Notification FEDORA-2016-8201e3fefa 2016-04-03 14:04:39.114316 ——————————————————————————– Name : NetworkManager Product : Fedora 23 Version : 1.0.12 Release : 1.fc23 URL : http://www.gnome.org/projects/NetworkManager/ Summary : Network connection manager and user applications Description : NetworkManager is a system […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3540-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : lhasa CVE ID : CVE-2016-2347 Marcin Noga discovered an integer underflow in Lhasa, a lzh archive decompressor, which might result in the execution of arbitrary code if a malformed archive is processed. For the […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Posted by Anthony Pell Multiple vulnerabilities have been found in QEMU, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – – – – – – […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Posted by Anthony Pell Update to NetworkManager 1.2-beta3. Upstream release announcement:https://mail.gnome.org/archives/networkmanager-list/2016-March/msg00164.html ——————————————————————————– Fedora Update Notification FEDORA-2016-cd218eef79 2016-04-02 15:48:47.755168 ——————————————————————————– Name : NetworkManager Product : Fedora 24 Version : 1.2.0 Release : 0.8.beta3.fc24 URL : http://www.gnome.org/projects/NetworkManager/ Summary : Network connection manager and user applications Description : NetworkManager is a system service that manages network interfaces […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Marcin Noga discovered an integer underflow in Lhasa, a lzh archive decompressor, which might result in the execution of arbitrary code if a malformed archive is processed. For the oldstable distribution (wheezy), this problem has been fixed in version 0.0.7-2+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 0.2.0+git3fe46-1+deb8u1. For the […]
Randell Jesup and the Firefox team discovered that srtp, Cisco’s reference implementation of the Secure Real-time Transport Protocol (SRTP), does not properly handle RTP header CSRC count and extension header length. A remote attacker can exploit this vulnerability to crash an application linked against libsrtp, resulting in a denial of service. For the oldstable distribution […]
An update for libssh is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: libssh security update Advisory ID: RHSA-2016:0566-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0566.html Issue date: 2016-03-31 CVE Names: […]
An update for mariadb is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: mariadb security and bug fix update Advisory ID: RHSA-2016:0534-01 Product: […]
