Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Posted by Anthony Pell    An update for krb5 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: krb5 security update Advisory ID: […]

Posted by Anthony Pell    Update to origin 1.1.3, disable v1beta1, v1beta3, fix application/json contenttype, don’t let hyperkube to parse flags for all commands (make it optional)—- Update to origin 1.1.3, disable v1beta1, v1beta3, fix application/jsoncontent type, don’t let hyperkube to parse flags —- Update to origin 1.1.3,disable v1beta1, v1beta3, fix application/json content type —- […]

New upstream release with security bug fix ——————————————————————————– Fedora Update Notification FEDORA-2016-6dc5678273 2016-03-31 20:29:07.231134 ——————————————————————————– Name : python-rsa Product : Fedora 24 Version : 3.4.1 Release : 1.fc24 URL : http://stuvel.eu/rsa Summary : Pure-Python RSA implementation Description : Python-RSA is a pure-Python RSA implementation. It supports encryption and decryption, signing and verifying signatures, and key […]

Posted by Anthony Pell    An update for bind is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 Extended Update Support. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: bind security update Advisory ID: RHSA-2016:0562-01 Product: Red Hat […]

Feds tackle open source code quality
Your Linux-based home router could succumb to a new Telnet worm, Remaiten
CloudFlare: 94 percent of the Tor traffic we see is “per se malicious”
Magento becomes fresh target for KimcilWare ransomware

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3538-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 31, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libebml CVE ID : CVE-2015-8789 CVE-2015-8790 CVE-2015-8791 Several vulnerabilities were discovered in libebml, a library for manipulating Extensible Binary Meta Language files. CVE-2015-8789 Context-dependent attackers could trigger a use-after-free vulnerability by providing a maliciously […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3537-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 31, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imlib2 CVE ID : CVE-2014-9762 CVE-2014-9763 CVE-2014-9764 Several vulnerabilities were discovered in imlib2, an image manipulation library. CVE-2014-9762 A segmentation fault could occur when opening GIFs without a colormap. CVE-2014-9763 Several divisions by zero, […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3536-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 31, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libstruts1.2-java CVE ID : CVE-2015-0899 It was discovered that libstruts1.2-java, a Java framework for MVC applications, contains a bug in its multi-page validation code. This allows input validation to be bypassed, even if MPV […]

Security fix for CVE-2016-2315, CVE-2016-2324 (by updating to 2.4.11). ——————————————————————————– Fedora Update Notification FEDORA-2016-cee7647200 2016-03-30 17:30:15.403378 ——————————————————————————– Name : git Product : Fedora 22 Version : 2.4.11 Release : 1.fc22 URL : http://git-scm.com/ Summary : Fast Version Control System Description : Git is a fast, scalable, distributed revision control system with an unusually rich command […]

Multiple CVEs ——————————————————————————– Fedora Update Notification FEDORA-2016-b91d895e5a 2016-03-30 17:30:15.402965 ——————————————————————————– Name : moodle Product : Fedora 22 Version : 2.8.11 Release : 1.fc22 URL : http://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) – a free, Open Source software package designed using sound pedagogical principles, to help […]

An update for openvswitch is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openvswitch security update Advisory ID: RHSA-2016:0537-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: […]

Multiple CVEs ——————————————————————————– Fedora Update Notification FEDORA-2016-403715aaec 2016-03-30 17:35:06.232672 ——————————————————————————– Name : moodle Product : Fedora 23 Version : 2.9.5 Release : 1.fc23 URL : http://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) – a free, Open Source software package designed using sound pedagogical principles, to help […]

FBI fights back against court order demanding Tor exploit source code
How one hacker exposed thousands of insecure desktops that anyone can remotely view

It was discovered that libstruts1.2-java, a Java framework for MVC applications, contains a bug in its multi-page validation code. This allows input validation to be bypassed, even if MPV is not used directly. For the oldstable distribution (wheezy), this problem has been fixed in version 1.2.9-5+deb7u2. We recommend that you upgrade your libstruts1.2-java packages.

Several vulnerabilities were discovered in imlib2, an image manipulation library. CVE-2014-9762 A segmentation fault could occur when opening GIFs without a colormap. CVE-2014-9763 Several divisions by zero, resulting in a program crash, could occur when handling PNM files. CVE-2014-9764 A segmentation fault could occur when opening GIFs with feh. For the oldstable distribution (wheezy), these […]

Several vulnerabilities were discovered in libebml, a library for manipulating Extensible Binary Meta Language files. CVE-2015-8789 Context-dependent attackers could trigger a use-after-free vulnerability by providing a maliciously crafted EBML document. CVE-2015-8790 Context-dependent attackers could obtain sensitive information from the process’ heap memory by using a maliciously crafted UTF-8 string. CVE-2015-8791 Context-dependent attackers could obtain sensitive […]

Stelios Tsampas discovered a buffer overflow in the Kamailio SIP proxy which might result in the execution of arbitrary code. For the stable distribution (jessie), this problem has been fixed in version 4.2.0-2+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 4.3.4-2. For the unstable distribution (sid), this problem has been […]

Posted by Anthony Pell    An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:0525-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0525.html […]

An update for openvswitch is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openvswitch security update Advisory ID: RHSA-2016:0524-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: […]

An update for openvswitch is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openvswitch security update Advisory ID: RHSA-2016:0523-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3535-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : kamailio CVE ID : CVE-2016-2385 Stelios Tsampas discovered a buffer overflow in the Kamailio SIP proxy which might result in the execution of arbitrary code. For the stable distribution (jessie), this problem has been […]

This update provides recent upstrem fix published with openssh-7.2p2 (#1316529). ——————————————————————————– Fedora Update Notification FEDORA-2016-d339d610c1 2016-03-29 15:13:21.929232 ——————————————————————————– Name : openssh Product : Fedora 22 Version : 6.9p1 Release : 11.fc22 URL : http://www.openssh.com/portable.html Summary : An open source implementation of SSH protocol versions 1 and 2 Description : SSH (Secure SHell) is a program […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0525-01: chromium-browser: Important Advisory Red Hat: 2016:0524-01: openvswitch: Important Advisory Red Hat: 2016:0523-01: openvswitch: Important Advisory Debian: 3535-1: kamailio: Summary Fedora 22 openssh-6.9p1-11.fc22 Fedora 22 webkitgtk-2.4.10-1.fc22 Debian: 3534-1: […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3534-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : dhcpcd CVE ID : CVE-2012-6698 CVE-2012-6699 CVE-2012-6700 Guido Vranken discovered several vulnerabilities in dhcpcd, a DHCP client, which may result in denial of service. For the oldstable distribution (wheezy), these problems have been fixed […]

PCRE could be made to crash or run programs if it processed aspecially-crafted regular expression. ========================================================================== Ubuntu Security Notice USN-2943-1 March 29, 2016 pcre3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: PCRE could be made to crash […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3533-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openvswitch CVE ID : CVE-2016-2074 Kashyap Thimmaraju and Bhargava Shastry discovered a remotely triggerable buffer overflow vulnerability in openvswitch, a production quality, multilayer virtual switch implementation. Specially crafted MPLS packets could overflow the buffer […]

FBI Breaks into iPhone. We Have Some Questions.
How one developer just broke Node, Babel and thousands of projects in 11 lines of JavaScript
Snowden ‘more helpful than dangerous’ says ex-Colin Powell aide
Way to Go, FCC. Now Manufacturers Are Locking Down Routers
Google Fixes Four Critical Vulnerabilities in Latest Chrome Build

Kashyap Thimmaraju and Bhargava Shastry discovered a remotely triggerable buffer overflow vulnerability in openvswitch, a production quality, multilayer virtual switch implementation. Specially crafted MPLS packets could overflow the buffer reserved for MPLS labels in an OVS internal data structure. A remote attacker can take advantage of this flaw to cause a denial of service, or […]

Guido Vranken discovered several vulnerabilities in dhcpcd, a DHCP client, which may result in denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 1:3.2.3-11+deb7u1. We recommend that you upgrade your dhcpcd packages.

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3532-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 27, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : quagga CVE ID : CVE-2016-2342 Debian Bug : 819179 Kostya Kortchinsky discovered a stack-based buffer overflow vulnerability in the VPNv4 NLRI parser in bgpd in quagga, a BGP/OSPF/RIP routing daemon. A remote attacker can […]

Posted by Anthony Pell    **Version 2.5.6** * Fix php-bug php#71719: Buffer overflow in HTTP url parsingfunctions (Mike, rc0r) * Fix gh-issue #28: Possible null pointer dereference inphp_http_url_mod() (rc0r) * Fix gh-issue #22: Fix PHP5 config.w32 (Jan Ehrhardt)* Fix gh-issue #20: setSslOptions notice with curl 7.43 (Mike, Vitaliy Demidov) ——————————————————————————– Fedora Update Notification FEDORA-2016-9d6b6d0689 2016-03-27 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

Posted by Anthony Pell    ### 6.x-2.7 Fixes [Embedded Media Field – Moderately Critical – Access Bypass -DRUPAL-SA-CONTRIB-2016-004](https://www.drupal.org/node/2666446) #### Changessince 6.x-2.6: * by dalin: Ensure that width and height are always numbers. *#1868588 by tangent: URL detection regex does not match hyphens / breaks HTMLmarkup ——————————————————————————– Fedora Update Notification FEDORA-2016-f0bb0dad51 2016-03-27 00:00:51.401145 ——————————————————————————– Name : […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

This update provides recent upstrem fix published with openssh-7.2p2 (#1316529). ——————————————————————————– Fedora Update Notification FEDORA-2016-0bcab055a7 2016-03-27 00:00:51.399587 ——————————————————————————– Name : openssh Product : Fedora 24 Version : 7.2p2 Release : 1.fc24 URL : http://www.openssh.com/portable.html Summary : An open source implementation of SSH protocol versions 1 and 2 Description : SSH (Secure SHell) is a program […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

Posted by Anthony Pell    Cumulative maintenance release from upstream. Highlights are: * SSH RSAhostkeys smaller than 2048 bits now work properly. * MLSD response lines are nowproperly CRLF terminated. * Fixed selection of DH groups from TLSDHParamFile(CVE-2016-3125) Various other bug fixes are also included. ——————————————————————————– Fedora Update Notification FEDORA-2016-ac3587be9a 2016-03-27 00:00:51.398858 ——————————————————————————– Name : […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

Kostya Kortchinsky discovered a stack-based buffer overflow vulnerability in the VPNv4 NLRI parser in bgpd in quagga, a BGP/OSPF/RIP routing daemon. A remote attacker can exploit this flaw to cause a denial of service (daemon crash), or potentially, execution of arbitrary code, if bgpd is configured with BGP peers enabled for VPNv4. For the oldstable […]

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1646 Wen Xu discovered an out-of-bounds read issue in the v8 library. CVE-2016-1647 A use-after-free issue was discovered. CVE-2016-1648 A use-after-free issue was discovered in the handling of extensions. CVE-2016-1649 lokihardt discovered a buffer overflow issue in the Almost Native Graphics Layer Engine (ANGLE) library. […]

Multiple security vulnerabilities have been fixed in the Tomcat servlet and JSP engine, which may result on bypass of security manager restrictions, information disclosure, denial of service or session fixation. For the oldstable distribution (wheezy), these problems have been fixed in version 6.0.45+dfsg-1~deb7u1. We recommend that you upgrade your tomcat6 packages.

Iranians charged with cyberattacks on US banks, New York dam

Posted by Anthony Pell    **Version 2.5.6** * Fix php-bug php#71719: Buffer overflow in HTTP url parsingfunctions (Mike, rc0r) * Fix gh-issue #28: Possible null pointer dereference inphp_http_url_mod() (rc0r) * Fix gh-issue #22: Fix PHP5 config.w32 (Jan Ehrhardt)* Fix gh-issue #20: setSslOptions notice with curl 7.43 (Mike, Vitaliy Demidov) ——————————————————————————– Fedora Update Notification FEDORA-2016-474c1d8264 2016-03-25 […]

Fix signature verification bypass attack, reported by Jann Horn ——————————————————————————– Fedora Update Notification FEDORA-2016-b98995ae24 2016-03-25 01:07:07.545267 ——————————————————————————– Name : torbrowser-launcher Product : Fedora 23 Version : 0.2.4 Release : 1.fc23 URL : https://github.com/micahflee/torbrowser-launcher Summary : Tor Browser Bundle managing tool Description : Tor Browser Launcher is intended to make Tor Browser easier to install and […]

OpenJDK could be made to crash or run programs as your login if it receivedspecially crafted input. ========================================================================== Ubuntu Security Notice USN-2942-1 March 24, 2016 openjdk-7 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: OpenJDK could be made to crash or run […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 php-pecl-http-2.5.6-1.fc23 Fedora 23 torbrowser-launcher-0.2.4-1.fc23 Ubuntu: 2942-1: OpenJDK 7 vulnerability Red Hat: 2016:0516-01: java-1.8.0-oracle: Critical Advisory Red Hat: 2016:0513-01: java-1.8.0-openjdk: Critical Advisory Red Hat: 2016:0515-01: java-1.7.0-oracle: Critical Advisory Red […]

Posted by Anthony Pell    An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-openjdk security update Advisory ID: RHSA-2016:0513-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0513.html Issue date: […]

Posted by Anthony Pell    An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-oracle security update Advisory ID: RHSA-2016:0515-01 Product: Oracle Java […]

Posted by Anthony Pell    An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: java-1.7.0-openjdk security update Advisory ID: RHSA-2016:0512-01 Product: Red Hat Enterprise […]

Posted by Anthony Pell    An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: java-1.8.0-openjdk security update Advisory ID: RHSA-2016:0514-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0514.html Issue date: […]

Posted by Anthony Pell    An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-openjdk security update Advisory ID: RHSA-2016:0511-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0511.html Issue date: […]

Quagga could be made to crash or run programs if it received speciallycrafted network traffic. ========================================================================== Ubuntu Security Notice USN-2941-1 March 24, 2016 quagga vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Quagga could be made to crash […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3527-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 24, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : inspircd CVE ID : CVE-2015-8702 It was discovered that inspircd, an IRC daemon, incorrectly handled PTR lookups of connecting users. This flaw allowed a remote attacker to crash the application by setting up malformed […]

An update for python-django is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0505-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: […]

Bruce Schneier on the Integration of Privacy and Security
Only 0.1% of you are doing web server security right

Multiple vulnerabilities have been found in Redmine, a project management web application, which may result in information disclosure. For the stable distribution (jessie), these problems have been fixed in version 3.0~20140825-8~deb8u2. For the testing distribution (stretch), these problems have been fixed in version 3.2.0-1. For the unstable distribution (sid), these problems have been fixed in […]

Stefan Sperling discovered that pidgin-otr, a Pidgin plugin implementing Off-The-Record messaging, contained a use-after-free bug. This could be used by a malicious remote user to intentionally crash the application, thus causing a denial-of-service. For the stable distribution (jessie), this problem has been fixed in version 4.0.1-1+deb8u1. For the testing (stretch) and unstable (sid) distributions, this […]

It was discovered that libmatroska, an extensible open standard audio/video container format, incorrectly processed EBML lacing. By providing maliciously crafted input, an attacker could use this flaw to force some leakage of information located in the process heap memory. For the oldstable distribution (wheezy), this problem has been fixed in version 1.3.0-2+deb7u1. For the stable […]

To stop the hackers, security teams need to share more data on attacks
Paris terrorists used burner phones, not encryption, to evade detection

It was discovered that inspircd, an IRC daemon, incorrectly handled PTR lookups of connecting users. This flaw allowed a remote attacker to crash the application by setting up malformed DNS records, thus causing a denial-of-service, For the oldstable distribution (wheezy), this problem has been fixed in version 2.0.5-1+deb7u2. For the stable distribution (jessie), this problem […]

Vincent LE GARREC discovered an integer overflow in pixman, a pixel-manipulation library for X and cairo. A remote attacker can exploit this flaw to cause an application using the pixman library to crash, or potentially, to execute arbitrary code with the privileges of the user running the application. For the oldstable distribution (wheezy), this problem […]

Updated nss-util packages that fix one security issue are now available for Red Hat Enterprise Linux 6.2, 6.4, and 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 and 7.1 Extended Update Support. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: nss-util security update Advisory ID: RHSA-2016:0495-01 Product: Red Hat Enterprise Linux Advisory URL: […]

Posted by Anthony Pell    Updated krb5 packages that fix two security issues are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: krb5 security update Advisory ID: RHSA-2016:0493-01 Product: Red Hat Enterprise Linux Advisory URL: […]

Posted by Anthony Pell    Updated tomcat6 packages that fix one security issue and one bug are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: tomcat6 security and bug fix update Advisory ID: RHSA-2016:0492-01 Product: […]

Posted by Anthony Pell    An updated foomatic package that fixes three security issues is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: foomatic security update Advisory ID: RHSA-2016:0491-01 Product: Red Hat Enterprise Linux Advisory […]

Updated kernel packages that fix one security issue, several bugs, and add one enhancement are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:0494-01 Product: Red […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0495-01: nss-util: Critical Advisory Red Hat: 2016:0493-01: krb5: Moderate Advisory Red Hat: 2016:0492-01: tomcat6: Moderate Advisory Red Hat: 2016:0491-01: foomatic: Moderate Advisory Red Hat: 2016:0494-01: kernel: Moderate Advisory […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0495-01: nss-util: Critical Advisory Red Hat: 2016:0493-01: krb5: Moderate Advisory Red Hat: 2016:0492-01: tomcat6: Moderate Advisory Red Hat: 2016:0491-01: foomatic: Moderate Advisory Red Hat: 2016:0494-01: kernel: Moderate Advisory […]

CVE-2016-3119, NULL dereference in LDAP module. —- Fix an issue with returncodes on `gss_inquire_attrs_for_mech`. This resolves an issue with gss-ntlmssp,and anything else that is interposing but not implementing the correspondingmechglue function. ——————————————————————————– Fedora Update Notification FEDORA-2016-56840babc3 2016-03-22 15:54:44.506003 ——————————————————————————– Name : krb5 Product : Fedora 23 Version : 1.14.1 Release : 3.fc23 URL : http://web.mit.edu/kerberos/www/ […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3525-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 22, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : pixman CVE ID : CVE-2014-9766 Vincent LE GARREC discovered an integer overflow in pixman, a pixel-manipulation library for X and cairo. A remote attacker can exploit this flaw to cause an application using the […]

A Government Error Just Revealed Snowden Was the Target in the Lavabit Case
Pwn2Own Day Two: Safari, Edge Go Down And Winner Crowned
Google’s reverse engineering software BinDiff now free for researchers

It was discovered that the ActiveMQ Java message broker performs unsafe deserialisation. For additional information, please refer to the upstream advisory at http://activemq.apache.org/security-advisories.data/CVE-2015-5254-announcement.txt. For the oldstable distribution (wheezy), this problem has been fixed in version 5.6.0+dfsg-1+deb7u2. For the stable distribution (jessie), this problem has been fixed in version 5.6.0+dfsg1-4+deb8u2. For the testing distribution (stretch), this […]

This update disables the Graphite font shaping library in Iceweasel, Debian’s version of the Mozilla Firefox web browser. For the oldstable distribution (wheezy), this problem has been fixed in version 38.7.1esr-1~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 38.7.1esr-1~deb8u1. For the unstable distribution (sid), this problem has been fixed in […]

Posted by Anthony Pell    Update to 2.40 Fixes various security issues, seehttp://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for moreinfo. ——————————————————————————– Fedora Update Notification FEDORA-2016-eacfc58fb9 2016-03-21 19:49:51.272763 ——————————————————————————– Name : seamonkey Product : Fedora 23 Version : 2.40 Release : 1.fc23 URL : http://www.seamonkey-project.org Summary : Web browser, e-mail, news, IRC client, HTML editor Description : SeaMonkey is an all-in-one […]

# Bugs fixed: * 762027 print-preview: Fix possible integer overflow flaw(CVE-2013-7447) # Updated translations: * Gaelic (Scottish) * Portuguese ——————————————————————————– Fedora Update Notification FEDORA-2016-330bfc0338 2016-03-21 19:49:51.272885 ——————————————————————————– Name : gnome-photos Product : Fedora 23 Version : 3.18.3 Release : 1.fc23 URL : https://live.gnome.org/GnomePhotos Summary : Access, organize and share your photos on GNOME Description : […]

Posted by Anthony Pell    Updated openssh packages that fix two security issues are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openssh security update Advisory ID: RHSA-2016:0465-01 Product: Red Hat Enterprise Linux Advisory URL: […]

Posted by Anthony Pell    Updated openssh packages that fix two security issues are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openssh security update Advisory ID: RHSA-2016:0466-01 Product: Red Hat Enterprise Linux Advisory URL: […]

Git could be made to crash or run programs as your login if it receivedchanges from a specially crafted remote repository. ========================================================================== Ubuntu Security Notice USN-2938-1 March 21, 2016 git vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: […]

Several security issues were fixed in WebKitGTK+. ========================================================================== Ubuntu Security Notice USN-2937-1 March 21, 2016 webkitgtk vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: Several security issues were fixed in WebKitGTK+. Software Description: – webkitgtk: Web content engine library for GTK+ Details: […]

Clarke: Precedent-Seeking FBI Won’t Ask NSA to Unlock Phone
Hackers Steal $81 Million from Federal Reserve

Alex Rousskov from The Measurement Factory discovered that Squid3, a fully featured web proxy cache, does not properly handle errors for certain malformed HTTP responses. A remote HTTP server can exploit this flaw to cause a denial of service (assertion failure and daemon exit). For the oldstable distribution (wheezy), this problem has been fixed in […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 webkitgtk3-2.4.10-1.fc23 Fedora 23 websvn-2.3.3-12.fc23 Fedora 23 proftpd-1.3.5b-1.fc23 Fedora 23 libvpx-1.4.0-6.fc23 Fedora 23 git-2.5.5-1.fc23 Debian: 3524-1: activemq: Summary Debian: 3523-1: iceweasel: Summary Fedora 22 websvn-2.3.3-12.fc22 Community Linux Events Linux […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 webkitgtk3-2.4.10-1.fc23 Fedora 23 websvn-2.3.3-12.fc23 Fedora 23 proftpd-1.3.5b-1.fc23 Fedora 23 libvpx-1.4.0-6.fc23 Fedora 23 git-2.5.5-1.fc23 Debian: 3524-1: activemq: Summary Debian: 3523-1: iceweasel: Summary Fedora 22 websvn-2.3.3-12.fc22 Community Linux Events Linux […]

Posted by Anthony Pell    Cumulative maintenance release from upstream. Highlights are: * SSH RSAhostkeys smaller than 2048 bits now work properly. * MLSD response lines are nowproperly CRLF terminated. * Fixed selection of DH groups from TLSDHParamFile(CVE-2016-3125). Various other bug fixes are also included. ——————————————————————————– Fedora Update Notification FEDORA-2016-977d57cf2d 2016-03-20 22:04:03.376869 ——————————————————————————– Name : […]