Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0157-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0157.html Issue date: 2016-02-10 CVE Names: CVE-2015-8213 […]
Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 7.0. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0156-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0156.html […]
Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 6. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0158-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0158.html Issue date: 2016-02-10 CVE Names: CVE-2015-8213 […]
Posted by Anthony Pell This update fixes for security vulnerabilities, including CVE-2016-0775,CVE-2016-0740. ——————————————————————————– Fedora Update Notification FEDORA-2016-4b06195979 2016-02-09 16:33:27.876837 ——————————————————————————– Name : python-pillow Product : Fedora 23 Version : 3.0.0 Release : 2.fc23 URL : http://python-pillow.github.io/ Summary : Python image processing library Description : Python image processing library, fork of the Python Imaging Library […]
Posted by Anthony Pell Several security issues were fixed in nginx. ========================================================================== Ubuntu Security Notice USN-2892-1 February 09, 2016 nginx vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: Several security issues were fixed in nginx. Software Description: – nginx: small, powerful, […]
Source: ZDNet Security – Posted by Dave Wreski A new bill introduced by two congressmen aims to prevent local legislatures from enacting laws weakening security or banning sales of encrypted smartphones in their states. On Wednesday, Rep. Ted Lieu (D-CA, 33rd) introduced the bipartisan draft bill — dubbed the Ensuring National Constitutional Rights of […]
Source: arsTechnica – Posted by Anthony Pell Google has confirmed a number of changes to Gmail with the arrival of two new features that will let you know if the people you�re corresponding with aren�t hip with TLS encryption. The alterations are fairly subtle: when you receive a message from, or are on the […]
Source: tomsHardware – Posted by Dave Wreski After New York and California tried to pass bills that ban phones from using disk encryption that only the device owners can decrypt, senator John McCain wants to ban all encryption that can�t be decrypted by companies and the government at the federal level. McCain called for […]
Source: Motherboard – Posted by Anthony Pell A hacker, who wishes to remain anonymous, plans to dump the apparent names, job titles, email addresses and phone numbers of over 20,000 supposed Federal Bureau of Investigation (FBI) employees, as well as over 9,000 alleged Department of Homeland Security (DHS) employees, Motherboard has learned. The hacker […]
LinuxSecurity.com: New libsndfile packages are available for Slackware 13.37, 14.0, 14.1, and -current to fix security issues. [More Info…]
LinuxSecurity.com: New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. [More Info…]
LinuxSecurity.com: USN-2880-1 introduced a regression in Firefox.
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: Nearly three years after former NSA contractor Edward Snowden first leaked details about massive domestic spying, his revelations have prompted a broader discourse, especially among legal scholars, over the potentially invasive nature of big data cybersurveillance tools.
LinuxSecurity.com: An updated sos package that fixes one security issue and one bug is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…]
LinuxSecurity.com: Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0 for RHEL 7. Red Hat Product Security has rated this update as having Moderate security [More…]
LinuxSecurity.com: Update from 3.13.1 to 3.13.2 for bug-fixes. Includes security fix forCVE-2015-8708.
LinuxSecurity.com: – update to upstream release 1.8.1 – CVE-2016-0747: Insufficient limits ofCNAME resolution in resolver – CVE-2016-0746: Use-after-free during CNAMEresponse processing in resolver – CVE-2016-0742: Invalid pointer dereference inresolver
LinuxSecurity.com: Prosody 0.9.10 ============== A summary of changes in this release: Security——– * mod_dialback: Adopt key generation algorithm from XEP-0185, toprevent impersonation attacks (CVE-2016-0756) Fixes and improvements———————- * Startup: Open /dev/urandom read-only, to fix afailure to start on some systems (fixes #585) * Networking: Improve handling ofthe ‘select’ network backend running out of file descriptors […]
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: Security Report Summary
security update
security update
security update
security update
LinuxSecurity.com: Bring technologists and members of the intelligence community together to figure out what to do about unbreakable encryption and guess what they conclude? They conclude that they don’t really need to worry about it.
LinuxSecurity.com: Three and a half years after he sought temporary asylum in the Ecuadorean embassy in London only to find himself a captive instead, a UN group has ruled that UK and Swedish authorities unlawfully detained WikiLeaks founder Julian Assange in violation of their international human rights obligations.
LinuxSecurity.com: On Sunday, an account on Twitter posted a Department of Homeland Security staff directory with 9,355 names. Shortly after the DHS data was posted, the account went on to claim that an additional data dump focused on 20,000 FBI employees was next.
LinuxSecurity.com: Days after a group of concerned professors raised alarm bells over a new network monitoring system installed at the University of California, Berkeley and the other nine campuses of the University of California system, a separate committee of system-wide faculty has now given its blessing.
security update
security update
LinuxSecurity.com: Updated dnf patch —- Update to bugfix release 2015.5.9, patched with properdnf support
LinuxSecurity.com: This update together with previous releases addresses the followingvulnerabilities: – CVE-2015-7096 – CVE-2015-7098 Additional fixes: – DisableDNS prefetch when a proxy is configured. – Reduce the maximum simultaneousnetwork connections to match other browsers. – Make WebKitWebView alwayspropagate motion-notify-event signal. – Add a way to force acceleratingcompositing mode at runtime using an environment variable. – […]
LinuxSecurity.com: updated to 3.2 (#1301310)
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: Ask one of the foremost cryptographers of the modern generation what the biggest privacy issue is today and you might expect something like backdoored encryption or government spying.
LinuxSecurity.com: It’s still not clear how, but a disproportionately large number of websites that run on the WordPress content management system are being hacked to deliver crypto ransomware and other malicious software to unwitting end users.
LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which may allow a remote attacker to cause a Denial of Service or gain elevated privileges from a guest VM.
LinuxSecurity.com: New MPlayer packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. [More Info…]
LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, and -current to fix security issues. [More Info…]
LinuxSecurity.com: New openssl packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. [More Info…]
LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.1 and -current to fix security issues. [More Info…]
LinuxSecurity.com: Prosody 0.9.10 ============== A summary of changes in this release: Security——– * mod_dialback: Adopt key generation algorithm from XEP-0185, toprevent impersonation attacks (CVE-2016-0756) Fixes and improvements———————- * Startup: Open /dev/urandom read-only, to fix afailure to start on some systems (fixes #585) * Networking: Improve handling ofthe ‘select’ network backend running out of file descriptors […]
security update
LinuxSecurity.com: The first serious look at the government’s plans for a new internet surveillance law has demonstrated just how much confusion there still remains about the legislation.
LinuxSecurity.com: One of the benefits of the next-generation Internet protocol known as IPv6 is the enhanced privacy it offers over its IPv4 predecessor. With a staggering 2128 (or about 3.4?1038) theoretical addresses available, its IP pool is immune to the types of systematic scans that criminal hackers and researchers routinely perform to locate vulnerable devices […]
LinuxSecurity.com: An open source network utility used by administrators and security professionals contains a cryptographic weakness so severe that it may have been intentionally created to give attackers a surreptitious way to eavesdrop on protected communications, its developer warned Monday.
LinuxSecurity.com: Websites that rely on the Tor anonymity service to cloak their server address may be leaking their geographic location and other sensitive information thanks to a setting that’s turned on by default in many releases of Apache, the world’s most widely used Web server.
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: Updated kernel packages that fix three security issues, multiple bugs, and one enhancement are now available for Red Hat Enterprise Linux 7.1 Extended Update Support. [More…]
security update
LinuxSecurity.com: Breaking encryption technology used by terrorists and criminals poses a frustrating dilemma for intelligence agencies and, most recently, congressional lawmakers.
LinuxSecurity.com: The NSA is publicly moving away from cryptographic algorithms vulnerable to cryptanalysis using a quantum computer. It just published a FAQ about the process: Q: Is there a quantum resistant public-key algorithm that commercial vendors should adopt?
LinuxSecurity.com: Malwarebytes says it could take three to four weeks to fix security flaws found by Google in its popular anti-malware product .
LinuxSecurity.com: Several security issues were fixed in QEMU.
LinuxSecurity.com: There is a big problem brewing in the Internet. You may have noticed that big attacks that disrupt networks or servers’ ability to deliver traffic, called Distributed Denial of Service (DDoS), are showing up in the news more often. You may not know that, officially, documented attacks are happening at the scale of several […]
LinuxSecurity.com: Security fix for CVE-2016-0738
LinuxSecurity.com: Backport of the patch for CVE-2015-5295
LinuxSecurity.com: Updated java-1.7.0-ibm packages that fix several security issues are now available for Red Hat Enterprise Linux 5 Supplementary. Red Hat Product Security has rated this update as having Critical security [More…]
LinuxSecurity.com: Updated java-1.8.0-ibm packages that fix several security issues are now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having Critical security [More…]
LinuxSecurity.com: Updated java-1.6.0-ibm packages that fix several security issues are now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security [More…]
LinuxSecurity.com: Updated java-1.7.1-ibm packages that fix several security issues are now available for Red Hat Enterprise Linux 6 and 7 Supplementary. Red Hat Product Security has rated this update as having Critical security [More…]
LinuxSecurity.com: The government’s use of a controversial invasive technology for tracking phones just got a little more controversial.
LinuxSecurity.com: Meet Adam. He’s a mid-level engineer at a mid-level software company in a cookie-cutter California office park. He can code a handful of languages, has a penchant for computer vision and enjoys soccer and skiing. In short, Adam has little to distinguish him from legions of other programmers in the Bay Area.
security update
security update
security update
security update
security update
security update
security update
security update
security update
security update
security update
security update
LinuxSecurity.com: Update to 2.10.4. Major new features: * New HTTP disk cache for the NetworkProcess. * IndexedDB support. * New Web Inspector UI. * AutomaticScreenServer inhibition when playing fullscreen videos. * Initial Editor API.* Performance improvements. This update addresses the followingvulnerabilities: * CVE-2015-1122 * CVE-2015-1152 * CVE-2015-1155 *CVE-2015-3660 * CVE-2015-3730 * CVE-2015-3738 * CVE-2015-3740 *CVE-2015-3742 […]
LinuxSecurity.com: Sync with latest openssh package.
LinuxSecurity.com: Security update.
LinuxSecurity.com: PV superpage functionality missing sanity checks [XSA-167, CVE-2016-1570] VMX:intercept issue with INVLPG on non-canonical address [XSA-168, CVE-2016-1571]Qemu: pci: null pointer dereference issue CVE-2015-7549 qemu: DoS by infiniteloop in ehci_advance_state CVE-2015-8558 qemu: Heap-based buffer overrun duringVM migration CVE-2015-8666 Qemu: net: vmxnet3: incorrect l2 header validationleads to a crash via assert(2) call CVE-2015-8744 qemu: Support reading […]
LinuxSecurity.com: Patches for CVE-2016-1982,3
