Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Hacker explains how he put “backdoor” in hundreds of Linux Mint downloads
Linux Mint hacked: Compromised data up for sale, ISO downloads backdoored
Decrypting an iPhone for the FBI

Alexander Izmailov discovered that didiwiki, a wiki implementation, failed to correctly validate user-supplied input, thus allowing a malicious user to access any part of the filesystem. For the oldstable distribution (wheezy), this problem has been fixed in version 0.5-11+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 0.5-11+deb8u1. For the testing […]

Stepan Golosunov discovered that xdelta3, a diff utility which works with binary files, is affected by a buffer overflow vulnerability within the main_get_appheader function, which may lead to the execution of arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 3.0.0.dfsg-1+deb7u1. For the stable distribution (jessie), this problem has been […]

Gustavo Grieco discovered an out-of-bounds write vulnerability in cpio, a tool for creating and extracting cpio archive files, leading to a denial of service (application crash). For the oldstable distribution (wheezy), this problem has been fixed in version 2.11+dfsg-0.1+deb7u2. For the stable distribution (jessie), this problem has been fixed in version 2.11+dfsg-4.1+deb8u1. For the unstable […]

Exposed VNC Server Discovered in Comodo Gear
Encryption isn’t at stake, the FBI knows Apple already has the desired key
Hopelessly broken wireless burglar alarm lets intruders go undetected

An anonymous contributor working with VeriSign iDefense Labs discovered that libreoffice, a full-featured office productivity suite, did not correctly handle Lotus WordPro files. This would enable an attacker to crash the program, or execute arbitrary code, by supplying a specially crafted LWP file. For the oldstable distribution (wheezy), these problems have been fixed in version […]

And as for actual WordPress pingbacks …. you should probably switch ’em off
Why Tim Cook is right to call court-ordered iPhone hack a “backdoor”
Twitter admits to password recovery bug affecting thousands of users
Critical glibc Vulnerability Puts All Linux Machines at Risk
Apple will oppose court order rather than hack customers
Massive US-planned cyberattack against Iran went well beyond Stuxnet
U.S. Encryption Ban Would Force Companies To Migrate, Say Researchers
Teenage alleged hacker ‘Cracka’ arrested by UK police for CIA, FBI data breaches
Web surveillance plans need more clarity around encryption, government told
Monitor Server Logs in Real-Time with “Log.io” Tool
As promised, hacker named Penis leaks contact info of 20,000 FBI employees
New Survey Suggests U.S. Encryption Ban Would Just Send Market Overseas
New report contends mandatory crypto backdoors would be futile
New bipartisan bill would prevent states from weakening encryption

Several vulnerabilities have been fixed in the GNU C Library, glibc. The first vulnerability listed below is considered to have critical impact. CVE-2015-7547 The Google Security Team and Red Hat discovered that the glibc host name resolver function, getaddrinfo, when processing AF_UNSPEC queries (for dual A/AAAA lookups), could mismanage its internal buffers, leading to a […]

Several vulnerabilities have been fixed in the GNU C Library, eglibc. The CVE-2015-7547 vulnerability listed below is considered to have critical impact. CVE-2014-8121 Robin Hack discovered that the nss_files database did not correctly implement enumeration interleaved with name-based or ID-based lookups. This could cause the enumeration enter an endless loop, leading to a denial of […]

Holger Fuhrmannek discovered that missing input sanitising in the Graphite font rendering engine could result in the execution of arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 38.6.1esr-1~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 38.6.1esr-1~deb8u1. For the unstable distribution (sid), this problem has […]

Several vulnerabilities have been found in PostgreSQL-9.4, a SQL database system. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. Certain custom configuration settings (GUCs) for PL/Java will now be modifiable only by the database superuser to mitigate this issue. CVE-2016-0773 Tom Lane and Greg Stark discovered a flaw in the way PostgreSQL […]

Several vulnerabilities have been found in PostgreSQL-9.1, a SQL database system. CVE-2015-5288 Josh Kupershmidt discovered a vulnerability in the crypt() function in the pgCrypto extension. Certain invalid salt arguments can cause the server to crash or to disclose a few bytes of server memory. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. […]

Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered that the ECDH secret decryption keys in applications using the libgcrypt20 library could be leaked via a side-channel attack. See https://www.cs.tau.ac.IL/~tromer/ecdh/ for details. For the stable distribution (jessie), this problem has been fixed in version 1.6.3-2+deb8u1. For the unstable distribution (sid), this problem has been […]

Several vulnerabilities were discovered in the resolver in nginx, a small, powerful, scalable web/proxy server, leading to denial of service or, potentially, to arbitrary code execution. These only affect nginx if the resolver directive is used in a configuration file. For the oldstable distribution (wheezy), these problems have been fixed in version 1.2.1-2.2+wheezy4. For the […]

Two vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2221 Shailesh Suthar discovered an open redirection vulnerability. CVE-2016-2222 Ronni Skansing discovered a server-side request forgery (SSRF) vulnerability. For the oldstable distribution (wheezy), these problems have been fixed in version 3.6.1+dfsg-1~deb7u10. For the stable distribution […]

Several vulnerabilities were discovered in qemu, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service, that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. discovered that the […]

Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service (via resource exhaustion), that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. […]

CVE-2015-7547: glibc getaddrinfo stack-based buffer overflow
Mandated encryption backdoors? Such a bad idea, says cybersecurity agency
Online security? Just let me Google that, say puzzled bosses
The CSI Effect comes to RSA Conference
U.S. Encryption Ban Would Force Companies To Migrate, Say Researchers
Teenage alleged hacker ‘Cracka’ arrested by UK police for CIA, FBI data breaches
Web surveillance plans need more clarity around encryption, government told
Monitor Server Logs in Real-Time with “Log.io” Tool
As promised, hacker named Penis leaks contact info of 20,000 FBI employees
New Survey Suggests U.S. Encryption Ban Would Just Send Market Overseas
New report contends mandatory crypto backdoors would be futile
New bipartisan bill would prevent states from weakening encryption
Gmail to warn you if your friends aren’t using secure e-mail
Senator McCain Calls For End-To-End Encryption Ban In US
Hacker Plans to Dump Alleged Details of 20,000 FBI, 9,000 DHS Employees
Snowden leaks furor still spilling over into courts

Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered that the ECDH secret decryption keys in applications using the libgcrypt11 library could be leaked via a side-channel attack. See https://www.cs.tau.ac.IL/~tromer/ecdh/ for details. For the oldstable distribution (wheezy), this problem has been fixed in version 1.5.0-5+deb7u4. We recommend that you upgrade your libgcrypt11 packages.

Several vulnerabilities have been found in PostgreSQL-9.4, a SQL database system. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. Certain custom configuration settings (GUCs) for PL/Java will now be modifiable only by the database superuser to mitigate this issue. CVE-2016-0773 Tom Lane and Greg Stark discovered a flaw in the way PostgreSQL […]

Several vulnerabilities have been found in PostgreSQL-9.1, a SQL database system. CVE-2015-5288 Josh Kupershmidt discovered a vulnerability in the crypt() function in the pgCrypto extension. Certain invalid salt arguments can cause the server to crash or to disclose a few bytes of server memory. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. […]

Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered that the ECDH secret decryption keys in applications using the libgcrypt20 library could be leaked via a side-channel attack. See https://www.cs.tau.ac.IL/~tromer/ecdh/ for details. For the stable distribution (jessie), this problem has been fixed in version 1.6.3-2+deb8u1. For the unstable distribution (sid), this problem has been […]

Several vulnerabilities were discovered in the resolver in nginx, a small, powerful, scalable web/proxy server, leading to denial of service or, potentially, to arbitrary code execution. These only affect nginx if the resolver directive is used in a configuration file. For the oldstable distribution (wheezy), these problems have been fixed in version 1.2.1-2.2+wheezy4. For the […]

Two vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2221 Shailesh Suthar discovered an open redirection vulnerability. CVE-2016-2222 Ronni Skansing discovered a server-side request forgery (SSRF) vulnerability. For the oldstable distribution (wheezy), these problems have been fixed in version 3.6.1+dfsg-1~deb7u10. For the stable distribution […]

Several vulnerabilities were discovered in qemu, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service, that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. discovered that the […]

Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service (via resource exhaustion), that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. […]

Several vulnerabilities were discovered in qemu, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service (via resource exhaustion), that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. […]

It was discovered that polarssl, a library providing SSL and TLS support, contained two heap-based buffer overflows that could allow a remote attacker to trigger denial of service (via application crash) or arbitrary code execution. For the oldstable distribution (wheezy), these problems have been fixed in version 1.2.9-1~deb7u6. For the stable distribution (jessie), these problems […]

Holger Fuhrmannek discovered that missing input sanitising in the Graphite font rendering engine could result in the execution of arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 38.6.1esr-1~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 38.6.1esr-1~deb8u1. For the unstable distribution (sid), this problem has […]

Several vulnerabilities have been found in PostgreSQL-9.4, a SQL database system. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. Certain custom configuration settings (GUCs) for PL/Java will now be modifiable only by the database superuser to mitigate this issue. CVE-2016-0773 Tom Lane and Greg Stark discovered a flaw in the way PostgreSQL […]

Several vulnerabilities have been found in PostgreSQL-9.1, a SQL database system. CVE-2015-5288 Josh Kupershmidt discovered a vulnerability in the crypt() function in the pgCrypto extension. Certain invalid salt arguments can cause the server to crash or to disclose a few bytes of server memory. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. […]

Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered that the ECDH secret decryption keys in applications using the libgcrypt20 library could be leaked via a side-channel attack. See https://www.cs.tau.ac.IL/~tromer/ecdh/ for details. For the stable distribution (jessie), this problem has been fixed in version 1.6.3-2+deb8u1. For the unstable distribution (sid), this problem has been […]

Several vulnerabilities were discovered in the resolver in nginx, a small, powerful, scalable web/proxy server, leading to denial of service or, potentially, to arbitrary code execution. These only affect nginx if the resolver directive is used in a configuration file. For the oldstable distribution (wheezy), these problems have been fixed in version 1.2.1-2.2+wheezy4. For the […]

Two vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2221 Shailesh Suthar discovered an open redirection vulnerability. CVE-2016-2222 Ronni Skansing discovered a server-side request forgery (SSRF) vulnerability. For the oldstable distribution (wheezy), these problems have been fixed in version 3.6.1+dfsg-1~deb7u10. For the stable distribution […]

Several vulnerabilities were discovered in qemu, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service, that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. discovered that the […]

Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service (via resource exhaustion), that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. […]

Several vulnerabilities were discovered in qemu, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service (via resource exhaustion), that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. […]

It was discovered that polarssl, a library providing SSL and TLS support, contained two heap-based buffer overflows that could allow a remote attacker to trigger denial of service (via application crash) or arbitrary code execution. For the oldstable distribution (wheezy), these problems have been fixed in version 1.2.9-1~deb7u6. For the stable distribution (jessie), these problems […]

U.S. Encryption Ban Would Force Companies To Migrate, Say Researchers
Source: tomsHardware – Posted by Anthony Pell    Harvard researchers Bruce Schneier and Saranya Vijayakumar teamed up with independent researcher [...]
Teenage alleged hacker ‘Cracka’ arrested by UK police for CIA, FBI data breaches
Source: ZDNet Security – Posted by Anthony Pell    A 16-year-old has been arrested on suspicion of being “Cracka,” the hacker believed to [...]
Monitor Server Logs in Real-Time with “Log.io” Tool
Posted by Alex    Log.io is a small simple but effective application build on top of Node.js and Socket.io, which allows to monitor Linux servers log files [...]
Gmail to warn you if your friends aren’t using secure e-mail
Source: arsTechnica – Posted by Anthony Pell    Google has confirmed a number of changes to Gmail with the arrival of two new features that will let [...]

Holger Fuhrmannek discovered that missing input sanitising in the Graphite font rendering engine could result in the execution of arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 38.6.1esr-1~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 38.6.1esr-1~deb8u1. For the unstable distribution (sid), this problem has […]

Several vulnerabilities have been found in PostgreSQL-9.4, a SQL database system. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. Certain custom configuration settings (GUCs) for PL/Java will now be modifiable only by the database superuser to mitigate this issue. CVE-2016-0773 Tom Lane and Greg Stark discovered a flaw in the way PostgreSQL […]

Several vulnerabilities have been found in PostgreSQL-9.1, a SQL database system. CVE-2015-5288 Josh Kupershmidt discovered a vulnerability in the crypt() function in the pgCrypto extension. Certain invalid salt arguments can cause the server to crash or to disclose a few bytes of server memory. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 nodejs-is-my-json-valid-2.12.4-1.fc22 Fedora 22 python-pymongo-2.5.2-8.fc22 Fedora 23 python-pymongo-2.5.2-8.fc23 Slackware: 2016-042-01: mozilla-firefox: Security Update Ubuntu: 2893-1: Firefox vulnerability Debian: 3473-1: nginx: Summary Ubuntu: 2894-1: PostgreSQL vulnerabilities Fedora 22 php-PHPMailer-5.2.14-1.fc22 Community […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 nodejs-is-my-json-valid-2.12.4-1.fc22 Fedora 22 python-pymongo-2.5.2-8.fc22 Fedora 23 python-pymongo-2.5.2-8.fc23 Slackware: 2016-042-01: mozilla-firefox: Security Update Ubuntu: 2893-1: Firefox vulnerability Debian: 3473-1: nginx: Summary Ubuntu: 2894-1: PostgreSQL vulnerabilities Fedora 22 php-PHPMailer-5.2.14-1.fc22 Community […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 nodejs-is-my-json-valid-2.12.4-1.fc22 Fedora 22 python-pymongo-2.5.2-8.fc22 Fedora 23 python-pymongo-2.5.2-8.fc23 Slackware: 2016-042-01: mozilla-firefox: Security Update Ubuntu: 2893-1: Firefox vulnerability Debian: 3473-1: nginx: Summary Ubuntu: 2894-1: PostgreSQL vulnerabilities Fedora 22 php-PHPMailer-5.2.14-1.fc22 Community […]

Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3473-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso February 11, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : nginx CVE ID : CVE-2016-0742 CVE-2016-0746 CVE-2016-0747 Debian Bug : 812806 Several vulnerabilities were discovered in the resolver in nginx, a small, powerful, scalable web/proxy server, leading to denial […]

Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered that the ECDH secret decryption keys in applications using the libgcrypt20 library could be leaked via a side-channel attack. See https://www.cs.tau.ac.IL/~tromer/ecdh/ for details. For the stable distribution (jessie), this problem has been fixed in version 1.6.3-2+deb8u1. For the unstable distribution (sid), this problem has been […]

Several vulnerabilities were discovered in the resolver in nginx, a small, powerful, scalable web/proxy server, leading to denial of service or, potentially, to arbitrary code execution. These only affect nginx if the resolver directive is used in a configuration file. For the oldstable distribution (wheezy), these problems have been fixed in version 1.2.1-2.2+wheezy4. For the […]

Source: ZDNet Security – Posted by Anthony Pell    The government’s web snooping plans have come in for yet more criticism, this time for lacking clarity around its stance on encryption and plans to record everyone’s web surfing history for a year. Lord Murphy of Torfaen, chairman of a parliamentary committee that has just published […]

<div>Gmail to warn you if your friends aren't using secure e-mail</div>
Source: arsTechnica – Posted by Anthony Pell    Google has confirmed a number of changes to Gmail with the arrival of two new features that will let [...]
<div>Gmail to warn you if your friends aren't using secure e-mail</div>
Source: arsTechnica – Posted by Anthony Pell    Google has confirmed a number of changes to Gmail with the arrival of two new features that will let [...]

Posted by Alex    Log.io is a small simple but effective application build on top of Node.js and Socket.io, which allows to monitor Linux servers log files in real time through web interface screen widgets. This tutorial will guide you on how you can install and monitor any local log files in real time with […]

Source: arsTechnica – Posted by Anthony Pell    Google has confirmed a number of changes to Gmail with the arrival of two new features that will let you know if the people you�re corresponding with aren�t hip with TLS encryption. The alterations are fairly subtle: when you receive a message from, or are on the […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 nodejs-is-my-json-valid-2.12.4-1.fc22 Fedora 22 python-pymongo-2.5.2-8.fc22 Fedora 23 python-pymongo-2.5.2-8.fc23 Slackware: 2016-042-01: mozilla-firefox: Security Update Ubuntu: 2893-1: Firefox vulnerability Debian: 3473-1: nginx: Summary Ubuntu: 2894-1: PostgreSQL vulnerabilities Fedora 22 php-PHPMailer-5.2.14-1.fc22 Community […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 nodejs-is-my-json-valid-2.12.4-1.fc22 Fedora 22 python-pymongo-2.5.2-8.fc22 Fedora 23 python-pymongo-2.5.2-8.fc23 Slackware: 2016-042-01: mozilla-firefox: Security Update Ubuntu: 2893-1: Firefox vulnerability Debian: 3473-1: nginx: Summary Ubuntu: 2894-1: PostgreSQL vulnerabilities Fedora 22 php-PHPMailer-5.2.14-1.fc22 Community […]

An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2016:0166-01 Product: Red Hat Enterprise Linux Supplementary […]

Sync with latest openssh package. ——————————————————————————– Fedora Update Notification FEDORA-2016-4509765b4b 2016-02-10 13:34:26.230007 ——————————————————————————– Name : gsi-openssh Product : Fedora 23 Version : 7.1p2 Release : 3.fc23 URL : http://www.openssh.com/portable.html Summary : An implementation of the SSH protocol with GSI authentication Description : SSH (Secure SHell) is a program for logging into and executing commands on […]

Source: TechWorm – Posted by Alex    Hacker makes good his promise and leaks contact information of 20000 FBI employees After releasing stolen records of 9000 employee from Department of Homeland Security, the hacker who goes by the Twitter handle of @DotGovs today leaked contact information of 20000 FBI employees. The hacker had promised yesterday […]

Source: TheIntercept – Posted by Anthony Pell    If the U.S. government tries to strong-arm American companies into ending the sale of products or applications with unbreakable encryption, the technology won�t disappear, a group of researchers conclude in a new report. It would still be widely available elsewhere. Some U.S. law enforcement officials argue that […]

Source: arsTechnica – Posted by Anthony Pell    An estimated 63 percent of the encryption products available today are developed outside US borders, according to a new report that takes a firm stance against the kinds of mandated backdoors some federal officials have contended are crucial to ensuring national security. The report, prepared by security […]

Posted by Anthony Pell    New upstream release: fixes CVE-2015-8476. ——————————————————————————– Fedora Update Notification FEDORA-2015-39522bb8c9 2016-02-11 09:49:16.132384 ——————————————————————————– Name : php-PHPMailer Product : Fedora 22 Version : 5.2.14 Release : 1.fc22 URL : http://phpmailer.worxware.com/ Summary : PHP email transport class with a lot of features Description : Full Featured Email Transfer Class for PHP. PHPMailer […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 php-PHPMailer-5.2.14-1.fc22 Fedora 23 firefox-44.0.1-2.fc23 Fedora 23 php-PHPMailer-5.2.14-1.fc23 Fedora 23 firebird-2.5.5.26952.0-1.fc23 Red Hat: 2016:0166-01: flash-plugin: Critical Advisory Fedora 23 gsi-openssh-7.1p2-3.fc23 Fedora 22 claws-mail-3.13.2-1.fc22 Red Hat: 2016:0157-01: python-django: Moderate Advisory […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 php-PHPMailer-5.2.14-1.fc22 Fedora 23 firefox-44.0.1-2.fc23 Fedora 23 php-PHPMailer-5.2.14-1.fc23 Fedora 23 firebird-2.5.5.26952.0-1.fc23 Red Hat: 2016:0166-01: flash-plugin: Critical Advisory Fedora 23 gsi-openssh-7.1p2-3.fc23 Fedora 22 claws-mail-3.13.2-1.fc22 Red Hat: 2016:0157-01: python-django: Moderate Advisory […]

Posted by Anthony Pell    New upstream release: fixes CVE-2015-8476. ——————————————————————————– Fedora Update Notification FEDORA-2015-abf9659276 2016-02-11 09:49:39.042856 ——————————————————————————– Name : php-PHPMailer Product : Fedora 23 Version : 5.2.14 Release : 1.fc23 URL : http://phpmailer.worxware.com/ Summary : PHP email transport class with a lot of features Description : Full Featured Email Transfer Class for PHP. PHPMailer […]

Update from 3.13.1 to 3.13.2 for bug-fixes. Includes security fix forCVE-2015-8708. ——————————————————————————– Fedora Update Notification FEDORA-2016-b211281b8e 2016-02-10 10:19:50.055896 ——————————————————————————– Name : claws-mail Product : Fedora 22 Version : 3.13.2 Release : 1.fc22 URL : http://claws-mail.org Summary : Email client and news reader based on GTK+ Description : Claws Mail is an email client (and news […]