Fix CVE-2016-1621 in bundled libwebm code. ——————————————————————————– Fedora Update Notification FEDORA-2016-fae59061fe 2016-03-20 22:04:03.376115 ——————————————————————————– Name : libvpx Product : Fedora 23 Version : 1.4.0 Release : 6.fc23 URL : http://www.webmproject.org/code/ Summary : VP8 Video Codec SDK Description : libvpx provides the VP8 SDK, which allows you to integrate your applications with the VP8 video codec, […]
Security fix for CVE-2016-2315, CVE-2016-2324 (by updating to 2.5.5). ——————————————————————————– Fedora Update Notification FEDORA-2016-6554eff611 2016-03-20 22:04:03.375556 ——————————————————————————– Name : git Product : Fedora 23 Version : 2.5.5 Release : 1.fc23 URL : http://git-scm.com/ Summary : Fast Version Control System Description : Git is a fast, scalable, distributed revision control system with an unusually rich command […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3524-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 20, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : activemq CVE ID : CVE-2015-5254 It was discovered that the ActiveMQ Java message broker performs unsafe deserialisation. For additional information, please refer to the upstream advisory at http://activemq.apache.org/security-advisories.data/CVE-2015-5254-announcement.txt For the oldstable distribution (wheezy), this […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3523-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 20, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : iceweasel CVE ID : not available This update disables the Graphite font shaping library in Iceweasel, Debian’s version of the Mozilla Firefox web browser. For the oldstable distribution (wheezy), this problem has been fixed […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 webkitgtk3-2.4.10-1.fc23 Fedora 23 websvn-2.3.3-12.fc23 Fedora 23 proftpd-1.3.5b-1.fc23 Fedora 23 libvpx-1.4.0-6.fc23 Fedora 23 git-2.5.5-1.fc23 Debian: 3524-1: activemq: Summary Debian: 3523-1: iceweasel: Summary Fedora 22 websvn-2.3.3-12.fc22 Community Linux Events Linux […]
Posted by Anthony Pell Cumulative maintenance release from upstream. Highlights are: * SSH RSAhostkeys smaller than 2048 bits now work properly. * MLSD response lines are nowproperly CRLF terminated. * Fixed selection of DH groups from TLSDHParamFile(CVE-2016-3125). Various other bug fixes are also included. ——————————————————————————– Fedora Update Notification FEDORA-2016-f95d8ea3ad 2016-03-20 16:01:37.694775 ——————————————————————————– Name : […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3522-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 20, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : squid3 CVE ID : CVE-2016-2571 Alex Rousskov from The Measurement Factory discovered that Squid3, a fully featured web proxy cache, does not properly handle errors for certain malformed HTTP responses. A remote HTTP server […]
Posted by Anthony Pell Multiple vulnerabilities have been found in OpenSSL, the worst allowing remote attackers to decrypt TLS sessions. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 webkitgtk3-2.4.10-1.fc23 Fedora 23 websvn-2.3.3-12.fc23 Fedora 23 proftpd-1.3.5b-1.fc23 Fedora 23 libvpx-1.4.0-6.fc23 Fedora 23 git-2.5.5-1.fc23 Debian: 3524-1: activemq: Summary Debian: 3523-1: iceweasel: Summary Fedora 22 websvn-2.3.3-12.fc22 Community Linux Events Linux […]
Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors, integer overflows, buffer overflows and other implementation errors may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 38.7.0-1~deb7u1. For the […]
Lael Cellier discovered two buffer overflow vulnerabilities in git, a fast, scalable, distributed revision control system, which could be exploited for remote execution of arbitrary code. For the oldstable distribution (wheezy), these problems have been fixed in version 1:1.7.10.4-1+wheezy3. For the stable distribution (jessie), these problems have been fixed in version 1:2.1.4-2.1+deb8u2. For the unstable […]
Multiple security issues have been found in the Xen virtualisation solution, which may result in denial of service or information disclosure. The oldstable distribution (wheezy) will be updated in a separate DSA. For the stable distribution (jessie), these problems have been fixed in version 4.4.1-9+deb8u4. For the unstable distribution (sid), these problems will be fixed […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Slackware: 2016-077-01: mozilla-firefox: Security Update Debian: 3519-1: xen: Summary Fedora 22 jenkins-1.609.3-6.fc22 Fedora 22 jenkins-remoting-2.53.3-1.fc22 Fedora 22 python-django-1.8.11-1.fc22 Fedora 22 rubygem-actionpack-4.2.0-4.fc22 Fedora 22 rubygem-actionview-4.2.0-5.fc22 Fedora 23 jenkins-remoting-2.53.3-1.fc23 Community Linux Events […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3519-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 17, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xen CVE ID : CVE-2015-8339 CVE-2015-8340 CVE-2015-8341 CVE-2015-8550 CVE-2015-8555 CVE-2016-1570 CVE-2016-1571 CVE-2016-2270 CVE-2016-2271 Multiple security issues have been found in the Xen virtualisation solution, which may result in denial of service or information disclosure. […]
Posted by Anthony Pell Fixes CVE-2016-0788, CVE-2016-0789, CVE-2016-0790, CVE-2016-0791, CVE-2016-0792 ——————————————————————————– Fedora Update Notification FEDORA-2016-0f490eea10 2016-03-17 16:03:22.862356 ——————————————————————————– Name : jenkins Product : Fedora 22 Version : 1.609.3 Release : 6.fc22 URL : http://jenkins-ci.org Summary : An extendable open source continuous integration server Description : Jenkins is an award-winning application that monitors executions of […]
Posted by Anthony Pell Fixes CVE-2016-0788, CVE-2016-0789, CVE-2016-0790, CVE-2016-0791, CVE-2016-0792 ——————————————————————————– Fedora Update Notification FEDORA-2016-0f490eea10 2016-03-17 16:03:22.862356 ——————————————————————————– Name : jenkins-remoting Product : Fedora 22 Version : 2.53.3 Release : 1.fc22 URL : https://github.com/jenkinsci/remoting Summary : Jenkins remoting module Description : This package is primarily used by Jenkins for slave node management, but it […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Slackware: 2016-077-01: mozilla-firefox: Security Update Debian: 3519-1: xen: Summary Fedora 22 jenkins-1.609.3-6.fc22 Fedora 22 jenkins-remoting-2.53.3-1.fc22 Fedora 22 python-django-1.8.11-1.fc22 Fedora 22 rubygem-actionpack-4.2.0-4.fc22 Fedora 22 rubygem-actionview-4.2.0-5.fc22 Fedora 23 jenkins-remoting-2.53.3-1.fc23 Community Linux Events […]
* Fix rails-html-sanitizer v1.0.3 compatibility. * Fix code injectionvulnerability (CVE-2016-2098). ——————————————————————————– Fedora Update Notification FEDORA-2016-3954061e32 2016-03-17 16:03:22.861593 ——————————————————————————– Name : rubygem-actionpack Product : Fedora 22 Version : 4.2.0 Release : 4.fc22 URL : http://www.rubyonrails.org Summary : Web-flow and rendering framework putting the VC in MVC Description : Eases web-request routing, handling, and response as a […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Slackware: 2016-077-01: mozilla-firefox: Security Update Debian: 3519-1: xen: Summary Fedora 22 jenkins-1.609.3-6.fc22 Fedora 22 jenkins-remoting-2.53.3-1.fc22 Fedora 22 python-django-1.8.11-1.fc22 Fedora 22 rubygem-actionpack-4.2.0-4.fc22 Fedora 22 rubygem-actionview-4.2.0-5.fc22 Fedora 23 jenkins-remoting-2.53.3-1.fc23 Community Linux Events […]
Posted by Anthony Pell Fixes CVE-2016-0788, CVE-2016-0789, CVE-2016-0790, CVE-2016-0791, CVE-2016-0792,and possible NoClassDefFoundError: org/codehaus/stax2/XMLInputFactory2 exceptionbug. ——————————————————————————– Fedora Update Notification FEDORA-2016-641c8b4eb2 2016-03-17 16:03:46.458729 ——————————————————————————– Name : jenkins-remoting Product : Fedora 23 Version : 2.53.3 Release : 1.fc23 URL : https://github.com/jenkinsci/remoting Summary : Jenkins remoting module Description : This package is primarily used by Jenkins for slave […]
Posted by Anthony Pell Fixes CVE-2016-0788, CVE-2016-0789, CVE-2016-0790, CVE-2016-0791, CVE-2016-0792,and possible NoClassDefFoundError: org/codehaus/stax2/XMLInputFactory2 exceptionbug. ——————————————————————————– Fedora Update Notification FEDORA-2016-641c8b4eb2 2016-03-17 16:03:46.458729 ——————————————————————————– Name : jenkins Product : Fedora 23 Version : 1.625.3 Release : 3.fc23 URL : http://jenkins-ci.org Summary : An extendable open source continuous integration server Description : Jenkins is an award-winning, cross-platform, […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Slackware: 2016-077-01: mozilla-firefox: Security Update Debian: 3519-1: xen: Summary Fedora 22 jenkins-1.609.3-6.fc22 Fedora 22 jenkins-remoting-2.53.3-1.fc22 Fedora 22 python-django-1.8.11-1.fc22 Fedora 22 rubygem-actionpack-4.2.0-4.fc22 Fedora 22 rubygem-actionview-4.2.0-5.fc22 Fedora 23 jenkins-remoting-2.53.3-1.fc23 Community Linux Events […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Slackware: 2016-077-01: mozilla-firefox: Security Update Debian: 3519-1: xen: Summary Fedora 22 jenkins-1.609.3-6.fc22 Fedora 22 jenkins-remoting-2.53.3-1.fc22 Fedora 22 python-django-1.8.11-1.fc22 Fedora 22 rubygem-actionpack-4.2.0-4.fc22 Fedora 22 rubygem-actionview-4.2.0-5.fc22 Fedora 23 jenkins-remoting-2.53.3-1.fc23 Community Linux Events […]
* Fix rails-html-sanitizer v1.0.3 compatiblity. * Fix code injectionvulnerability (CVE-2016-2098). ——————————————————————————– Fedora Update Notification FEDORA-2016-f6af14570f 2016-03-17 16:03:46.457347 ——————————————————————————– Name : rubygem-actionpack Product : Fedora 23 Version : 4.2.3 Release : 5.fc23 URL : http://www.rubyonrails.org Summary : Web-flow and rendering framework putting the VC in MVC Description : Eases web-request routing, handling, and response as a […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2935-2: PAM regression Red Hat: 2016:0458-01: bind97: Important Advisory Red Hat: 2016:0459-01: bind: Important Advisory Ubuntu: 2935-1: PAM vulnerabilities Ubuntu: 2930-3: Linux kernel (Raspberry Pi 2) vulnerabilities Debian: 3518-1: […]
Posted by Anthony Pell Updated bind97 packages that fix two security issues are now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: bind97 security update Advisory ID: RHSA-2016:0458-01 Product: Red Hat Enterprise Linux Advisory URL: […]
Updated bind packages that fix two security issues are now available for Red Hat Enterprise Linux 5, 6, and 7. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: bind security update Advisory ID: RHSA-2016:0459-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0459.html Issue […]
Several security issues were fixed in PAM. ========================================================================== Ubuntu Security Notice USN-2935-1 March 16, 2016 pam vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in PAM. Software Description: – pam: Pluggable Authentication Modules […]
Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2930-3 March 16, 2016 linux-raspi2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux-raspi2: Linux kernel for Raspberry […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3518-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 16, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : spip CVE ID : CVE-2016-3153 CVE-2016-3154 Several vulnerabilities were found in SPIP, a website engine for publishing, resulting in code injection. CVE-2016-3153 g0uZ et sambecks, from team root-me, discovered that arbitrary PHP code could […]
Posted by Anthony Pell New git packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. [More Info…] [slackware-security] git (SSA:2016-075-01) New git packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2935-1: PAM vulnerabilities Ubuntu: 2930-3: Linux kernel (Raspberry Pi 2) vulnerabilities Debian: 3518-1: spip: Summary Slackware: 2016-075-01: git: Security Update Slackware: 2016-075-02: seamonkey: Security Update Fedora 22 pcre-8.38-3.fc22 Fedora […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2935-1: PAM vulnerabilities Ubuntu: 2930-3: Linux kernel (Raspberry Pi 2) vulnerabilities Debian: 3518-1: spip: Summary Slackware: 2016-075-01: git: Security Update Slackware: 2016-075-02: seamonkey: Security Update Fedora 22 pcre-8.38-3.fc22 Fedora […]
– Update to the latest upstream – 45.0 ——————————————————————————– Fedora Update Notification FEDORA-2016-5b2c402bb1 2016-03-15 19:46:12.477825 ——————————————————————————– Name : firefox Product : Fedora 22 Version : 45.0 Release : 4.fc22 URL : https://www.mozilla.org/projects/firefox/ Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. ——————————————————————————– […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2935-1: PAM vulnerabilities Ubuntu: 2930-3: Linux kernel (Raspberry Pi 2) vulnerabilities Debian: 3518-1: spip: Summary Slackware: 2016-075-01: git: Security Update Slackware: 2016-075-02: seamonkey: Security Update Fedora 22 pcre-8.38-3.fc22 Fedora […]
Posted by Anthony Pell Updated rh-php56-php packages that fix multiple security issues are now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-php56-php security update Advisory ID: RHSA-2016:0457-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0457.html […]
Posted by Anthony Pell Updated rh-ror41-rubygem-actionview packages that fix two security issues are now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: rh-ror41 security update Advisory ID: RHSA-2016:0456-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0456.html […]
Updated ruby193-rubygem-actionpack and ruby193-rubygem-activerecord packages that fix multiple security issues are now available for Red Hat Software Collections. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: ruby193 security update Advisory ID: RHSA-2016:0455-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0455.html Issue date: 2016-03-15 CVE Names: CVE-2015-7576 CVE-2015-7577 CVE-2016-0751 CVE-2016-0752 CVE-2016-2097 CVE-2016-2098 ===================================================================== 1. Summary: Updated […]
Updated ror40-rubygem-actionpack and ror40-rubygem-activerecord packages that fix multiple security issues are now available for Red Hat Software Collections. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: ror40 security update Advisory ID: RHSA-2016:0454-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0454.html Issue date: 2016-03-15 CVE Names: CVE-2015-7576 CVE-2015-7577 CVE-2015-7581 CVE-2016-0751 CVE-2016-0752 CVE-2016-2097 CVE-2016-2098 ===================================================================== 1. Summary: […]
Several vulnerabilities were found in SPIP, a website engine for publishing, resulting in code injection. CVE-2016-3153 g0uZ et sambecks, from team root-me, discovered that arbitrary PHP code could be injected when adding content. CVE-2016-3154 Gilles Vincent discovered that deserializing untrusted content could result in arbitrary objects injection. For the oldstable distribution (wheezy), these problems have […]
Several security issues were fixed in Exim. ========================================================================== Ubuntu Security Notice USN-2933-1 March 15, 2016 exim4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in Exim. Software Description: – exim4: Exim is a […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2932-1 March 14, 2016 linux-lts-vivid vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-vivid: Linux hardware enablement kernel from Vivid for Trusty […]
Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2931-1 March 14, 2016 linux-lts-utopic vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-utopic: Linux hardware enablement […]
Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2930-2 March 14, 2016 linux-lts-wily vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-wily: Linux hardware enablement […]
Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2930-1 March 14, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: Ben […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2929-1 March 14, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: Ben Hawkes discovered that the […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2929-2 March 14, 2016 linux-lts-trusty vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise […]
The system could be made to crash or run programs as an administrator bysomeone with physical access. ========================================================================== Ubuntu Security Notice USN-2928-1 March 14, 2016 linux vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: The system could be made to crash or run programs as […]
The system could be made to crash or run programs as an administratorby someone with physical access. ========================================================================== Ubuntu Security Notice USN-2928-2 March 14, 2016 linux-ti-omap4 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: The system could be made to crash or run programs as […]
Posted by Anthony Pell graphite2 could be made to crash or run programs as your login if it openeda specially crafted font. ========================================================================== Ubuntu Security Notice USN-2927-1 March 14, 2016 graphite2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: graphite2 could […]
Multiple vulnerabilities were discovered in the dissectors/parsers for DNP, RSL, LLRP, GSM A-bis OML, ASN 1 BER which could result in denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 1.8.2-5wheezy18. For the stable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u5. For the testing distribution (stretch), […]
Multiple vulnerabilities have been found in the Graphite font rendering engine which might result in denial of service or the execution of arbitrary code if a malformed font file is processed. For the oldstable distribution (wheezy), these problems have been fixed in version 1.3.6-1~deb7u1. For the stable distribution (jessie), these problems have been fixed in […]
Posted by Anthony Pell Updated OpenStack Orchestration packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-heat security advisory Advisory ID: RHSA-2016:0442-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0442.html Issue date: […]
Posted by Anthony Pell Updated OpenStack Orchestration packages that fix one security issue and two bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-heat bug fix and security advisory Advisory ID: RHSA-2016:0440-01 Product: Red Hat Enterprise Linux OpenStack […]
Posted by Anthony Pell Updated OpenStack Orchestration packages that fix one security issue and two bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-heat bug fix and security advisory Advisory ID: RHSA-2016:0441-01 Product: Red Hat Enterprise Linux OpenStack […]
Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3517-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : exim4 CVE ID : CVE-2016-1531 A local root privilege escalation vulnerability was found in Exim, Debian’s default mail transfer agent, in configurations using the ‘perl_startup’ option (Only Exim via […]
phpMyAdmin 4.5.5.1 (2016-02-29) =============================== This releasefixes multiple XSS vulnerabilities, please see PMASA-2016-10, PMASA-2016-11, andPMASA-2016-12 for details; additionally it fixes a vulnerability allowing man-in-the-middle attack on an API call to GitHub, see PMASA-2016-13 for details.It also inclues fixes for the following bugs: – issue #11971 CREATE UNIQUEINDEX index type is not recognized by parser. – issue […]
Posted by Anthony Pell phpMyAdmin 4.5.5.1 (2016-02-29) =============================== This releasefixes multiple XSS vulnerabilities, please see PMASA-2016-10, PMASA-2016-11, andPMASA-2016-12 for details; additionally it fixes a vulnerability allowing man-in-the-middle attack on an API call to GitHub, see PMASA-2016-13 for details.It also inclues fixes for the following bugs: – issue #11971 CREATE UNIQUEINDEX index type is not […]
This update provides recent upstream (security) release, sanitizing X11authentication credentials. ——————————————————————————– Fedora Update Notification FEDORA-2016-bb59db3c86 2016-03-13 19:43:42.937000 ——————————————————————————– Name : openssh Product : Fedora 23 Version : 7.2p2 Release : 1.fc23 URL : http://www.openssh.com/portable.html Summary : An open source implementation of SSH protocol versions 1 and 2 Description : SSH (Secure SHell) is a program […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Red Hat: 2016:0442-01: openstack-heat: Moderate Advisory Red Hat: 2016:0440-01: openstack-heat bug fix and: Moderate Advisory Red Hat: 2016:0441-01: openstack-heat bug fix and: Moderate Advisory Debian: 3517-1: exim4: Summary Fedora 22 […]
Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3516-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wireshark CVE ID : CVE-2015-8731 CVE-2016-2523 CVE-2016-2530 CVE-2016-2531 CVE-2016-2532 Multiple vulnerabilities were discovered in the dissectors/parsers for DNP, RSL, LLRP, GSM A-bis OML, ASN 1 BER which could result […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3515-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : graphite2 CVE ID : CVE-2016-1977 CVE-2016-2790 CVE-2016-2791 CVE-2016-2792 CVE-2016-2793 CVE-2016-2794 CVE-2016-2795 CVE-2016-2796 CVE-2016-2797 CVE-2016-2798 CVE-2016-2799 CVE-2016-2800 CVE-2016-2801 CVE-2016-2802 Multiple vulnerabilities have been found in the Graphite font rendering engine which might result in denial […]
Fix CVE-2016-0739 ——————————————————————————– Fedora Update Notification FEDORA-2016-dc9e8da03c 2016-03-13 09:04:20.341288 ——————————————————————————– Name : libssh Product : Fedora 22 Version : 0.7.3 Release : 1.fc22 URL : http://www.libssh.org Summary : A library implementing the SSH protocol Description : The ssh library was designed to be used by programmers needing a working SSH implementation by the mean of […]
Fix manipulating environment variables to align with how glibc handlesduplicated environment variables. Perl now uses the first variable listed in theenvironment array and it removes any subsequent entries of the same-namedvariable from the array, so that child processes have only one variable instancein its environment. ——————————————————————————– Fedora Update Notification FEDORA-2016-1fb63e3bf3 2016-03-13 09:04:20.340939 ——————————————————————————– Name : […]
A local root privilege escalation vulnerability was found in Exim, Debian’s default mail transfer agent, in configurations using the perl_startup option (Only Exim via exim4-daemon-heavy enables Perl support). To address the vulnerability, updated Exim versions clean the complete execution environment by default, affecting Exim and subprocesses such as transports calling other programs, and thus may […]
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2015-7560 Jeremy Allison of Google, Inc. and the Samba Team discovered that Samba incorrectly handles getting and setting ACLs on a symlink path. An authenticated malicious client can use […]
Posted by Anthony Pell **Version 1.1.21** – 27 February 2016. * Improvement and security fix intransforming ‘font’ element. ——————————————————————————– Fedora Update Notification FEDORA-2016-6b977c4737 2016-03-11 09:31:28.305942 ——————————————————————————– Name : php-htmLawed Product : Fedora 23 Version : 1.1.21 Release : 1.fc23 URL : http://www.bioinformatics.org/phplabware/internal_utilities/htmLawed/ Summary : PHP code to purify and filter HTML Description : PHP […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 php-htmLawed-1.1.21-1.fc23 Fedora 23 kernel-4.4.4-301.fc23 Fedora 23 firefox-45.0-4.fc23 Slackware: 2016-070-01: openssh: Security Update Ubuntu: 2920-1: Oxide vulnerabilities Red Hat: 2016:0430-01: xerces-c: Important Advisory Ubuntu: 2926-1: OTR vulnerability Debian: 3513-1: […]
– Update to the latest upstream – 45.0 ——————————————————————————– Fedora Update Notification FEDORA-2016-be6d3fff4a 2016-03-11 09:31:28.303965 ——————————————————————————– Name : firefox Product : Fedora 23 Version : 45.0 Release : 4.fc23 URL : https://www.mozilla.org/projects/firefox/ Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. ——————————————————————————– […]
Posted by Anthony Pell New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. [More Info…] [slackware-security] openssh (SSA:2016-070-01) New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: […]
Several security issues were fixed in Oxide. ========================================================================== Ubuntu Security Notice USN-2920-1 March 10, 2016 oxide-qt vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: Several security issues were fixed in Oxide. Software Description: – oxide-qt: Web browser engine for Qt (QML plugin) […]
Posted by Anthony Pell Updated xerces-c packages that fix one security issue are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: xerces-c security update Advisory ID: RHSA-2016:0430-01 Product: Red Hat Enterprise Linux Advisory URL: […]
OTR could be made to crash or run programs if it received specially craftednetwork traffic. ========================================================================== Ubuntu Security Notice USN-2926-1 March 10, 2016 libotr vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: OTR could be made to crash or run programs if it received specially […]
Markus Vervier of X41 D-Sec GmbH discovered an integer overflow vulnerability in libotr, an off-the-record (OTR) messaging library, in the way how the sizes of portions of incoming messages were stored. A remote attacker can exploit this flaw by sending crafted messages to an application that is using libotr to perform denial of service attacks […]
Two vulnerabilites have been discovered in ISC’s BIND DNS server. CVE-2016-1285 A maliciously crafted rdnc, a way to remotely administer a BIND server, operation can cause named to crash, resulting in denial of service. CVE-2016-1286 An error parsing DNAME resource records can cause named to crash, resulting in denial of service. For the oldstable distribution […]
Multiple security issues have been found in Iceweasel, Debian’s version of the Mozilla Firefox web browser: Multiple memory safety errors, buffer overflows, use-after-frees and other implementation errors may lead to the execution of arbitrary code, denial of service, address bar spoofing and overwriting local files. For the oldstable distribution (wheezy), these problems have been fixed […]
Two vulnerabilities have been discovered in Rails, a web application framework written in Ruby. Both vulnerabilities affect Action Pack, which handles the web requests for Rails. CVE-2016-2097 Crafted requests to Action View, one of the components of Action Pack, might result in rendering files from arbitrary locations, including files beyond the application’s view directory. This […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3513-1 security@debian.org https://www.debian.org/security/ Michael Gilbert March 10, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1643 CVE-2016-1644 CVE-2016-1645 Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1643 cloudfuzzer discovered a type confusion issue in Blink/Webkit. CVE-2016-1644 Atte Kettunen discovered a use-after-free issue in […]
Updated libssh2 packages that fix one security issue are now available for Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: libssh2 security update Advisory ID: RHSA-2016:0428-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0428.html Issue date: […]
Posted by Anthony Pell Updated chromium-browser packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:0429-01 Product: Red Hat Enterprise Linux Supplementary […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Debian: 3513-1: chromium-browser: Summary Red Hat: 2016:0428-01: libssh2: Moderate Advisory Red Hat: 2016:0429-01: chromium-browser: Important Advisory Slackware: 2016-069-02: mozilla-nss: Security Update Slackware: 2016-069-01: bind: Security Update Debian: 3512-1: libotr: Summary […]
Posted by Anthony Pell New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. [More Info…] [slackware-security] bind (SSA:2016-069-01) New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3512-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libotr CVE ID : CVE-2016-2851 Markus Vervier of X41 D-Sec GmbH discovered an integer overflow vulnerability in libotr, an off-the-record (OTR) messaging library, in the way how the sizes of portions of incoming messages […]
Bind could be made to crash if it received specially crafted networktraffic. ========================================================================== Ubuntu Security Notice USN-2925-1 March 09, 2016 bind9 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Bind could be made to crash if it received […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3511-1 security@debian.org https://www.debian.org/security/ Michael Gilbert March 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : bind9 CVE ID : CVE-2016-1285 CVE-2016-1286 Two vulnerabilites have been discovered in ISC’s BIND DNS server. CVE-2016-1285 A maliciously crafted rdnc, a way to remotely administer a BIND server, operation can cause named to […]
