Red Hat: 2016:1581-01: kernel: Important Advisory Posted by Anthony Pell An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2016:1581-01 Product: […]
Red Hat: 2016:1580-01: chromium-browser: Important Advisory Posted by Anthony Pell An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1580-01 Product: Red Hat […]
Debian: 3645-1: chromium-browser: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3645-1 security@debian.org https://www.debian.org/security/ Michael Gilbert August 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-5139 CVE-2016-5140 CVE-2016-5141 CVE-2016-5142 CVE-2016-5143 CVE-2016-5144 Several vulnerabilites have been discovered in the chromium web browser. CVE-2016-5139 GiWan Go discovered a […]
Debian: 3644-1: fontconfig: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3644-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 08, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : fontconfig CVE ID : CVE-2016-5384 Debian Bug : 833570 Tobias Stoeckmann discovered that cache files are insufficiently validated in fontconfig, a generic font configuration library. […]
Slackware: 2016-219-03: openssh: Security Update Posted by Anthony Pell New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] openssh (SSA:2016-219-03) New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. Here are […]
Slackware: 2016-219-01: curl: Security Update Posted by Anthony Pell New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] curl (SSA:2016-219-01) New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. Here are […]
Slackware: 2016-219-02: mozilla-firefox: Security Update Posted by Anthony Pell New mozilla-firefox packages are available for Slackware 14.1 and 14.2 to fix security issues. [More Info…] [slackware-security] mozilla-firefox (SSA:2016-219-02) New mozilla-firefox packages are available for Slackware 14.1 and 14.2 to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +————————–+ patches/packages/mozilla-firefox-45.3.0esr-i586-1_slack14.2.txz: Upgraded. […]
Slackware: 2016-219-04: stunnel: Security Update Posted by Anthony Pell New stunnel packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] stunnel (SSA:2016-219-04) New stunnel packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. Here are […]
Debian: 3643-1: kde4libs: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3643-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 06, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : kde4libs CVE ID : CVE-2016-6232 Debian Bug : 832620 Andreas Cord-Landwehr discovered that kde4libs, the core libraries for all KDE 4 applications, do not properly […]
Debian: 3642-1: lighttpd: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3642-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond August 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : lighttpd CVE ID : CVE-2016-1000212 Debian Bug : 832571 Dominic Scheirlinck and Scott Geary of Vend reported insecure behavior in the lighttpd web server. Lighttpd […]
The trojan downloader Nemucod is back with a new campaign. This time however, it has changed the payload served to its victims – ransomware is not its go-to malware. Currently the “weapon of choice” is a backdoor detected by ESET as Win32/Kovter, in this instance mainly focusing on ad-clicking. As a backdoor, this trojan allows […]
This year at Defcon, the car hacking village is bigger than ever, with more cars, car hacking adapters and giant snarls of tiny exposed wires tied to demo stations with car parts screwed to plywood stands than ever before. It’s car hacking 101 here, and class is in full force. The first thing you notice […]
SMS-based two-factor authentication (2FA) should be phased out, according to the National Institute of Standards and Technology (NIST) at the US Department of Commerce. In its most recent Digital Authentication Guideline – draft version – the federal technology agency explained that this is because there are risks with this approach. NIST stated that as SMS messages […]
I spend a lot of time working on enterprise Public Key Infrastructure (PKI), especially in light of the coming SHA-1 deprecation deadlines. It’s nearly all I do these days. One question my customers ask all the time is how to provision certificates on non-Windows devices and computers. Microsoft does an excellent job of automating the […]
In years past at Black Hat here in Las Vegas, there was row after row of hardware, then, in later years, row after row of software for your workstation. Now there’s row after row of middleware designed to interpret all that data in real time and try to make sense of it all, to find […]
Risk High Date Discovered August 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Technologies Affected Microsoft Windows 10 Version 1607 for 32-bit Systems Microsoft Windows 10 Version 1607 […]
Risk High Date Discovered August 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Technologies Affected Microsoft Windows 10 Version 1607 for 32-bit Systems Microsoft Windows 10 Version 1607 […]
Risk High Date Discovered August 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Technologies Affected Microsoft Windows 10 Version 1607 for 32-bit Systems Microsoft Windows 10 Version 1607 […]
Risk High Date Discovered August 9, 2016 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed […]
Risk Medium Date Discovered August 9, 2016 Description Microsoft Internet Explorer and Edge are prone to an information-disclosure vulnerability. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks. Edge and Internet explorer 9, 10 and 11 are vulnerable. Technologies Affected Microsoft Edge Microsoft Internet Explorer 10 Microsoft Internet Explorer […]
Risk Medium Date Discovered August 9, 2016 Description Microsoft Internet Explorer and Edge are prone to an information-disclosure vulnerability. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks. Edge and Internet explorer 9, 10 and 11 are vulnerable. Technologies Affected Microsoft Edge Microsoft Internet Explorer 10 Microsoft Internet Explorer […]
Risk Medium Date Discovered August 9, 2016 Description Microsoft Internet Explorer and Edge are prone to an information-disclosure vulnerability. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks. Edge and Internet explorer 9, 10 and 11 are vulnerable. Technologies Affected Microsoft Edge Microsoft Internet Explorer 10 Microsoft Internet Explorer […]
Risk Medium Date Discovered August 9, 2016 Description Microsoft Internet Explorer is prone to a local information-disclosure vulnerability. An authenticated attacker can leverage this issue to obtain sensitive information that may aid in further attacks. Internet Explorer 10 and 11 are vulnerable. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments […]
Risk High Date Discovered August 9, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]
Risk High Date Discovered August 9, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]
We all know that Internet of Things (IoT) is the future and that everything from your refrigerator to your toaster may eventually connect to the internet. With that being the case, it’s important to remember that these connected devices need to be designed with security in mind. On Saturday at the Def Con hacking conference in […]
Risk Level: Very Low. Type: Trojan.
Andreas Cord-Landwehr discovered that kde4libs, the core libraries for all KDE 4 applications, do not properly handle the extraction of archives with “../” in the file paths. A remote attacker can take advantage of this flaw to overwrite files outside of the extraction folder, if a user is tricked into extracting a specially crafted archive. […]
Ubuntu: 3046-1: LibreOffice vulnerability Posted by Anthony Pell LibreOffice could be made to crash or run programs as your login if itopened a specially crafted file. ========================================================================== Ubuntu Security Notice USN-3046-1 August 04, 2016 libreoffice vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: LibreOffice […]
Debian: 3641-1: openjdk-7: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3641-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 04, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openjdk-7 CVE ID : CVE-2016-3458 CVE-2016-3500 CVE-2016-3508 CVE-2016-3550 CVE-2016-3606 Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in […]
Red Hat: 2016:1573-01: squid: Moderate Advisory Posted by Anthony Pell An update for squid is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: […]
Debian: 3640-1: firefox-esr: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3640-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : firefox-esr CVE ID : CVE-2016-2830 CVE-2016-2836 CVE-2016-2837 CVE-2016-2838 CVE-2016-5252 CVE-2016-5254 CVE-2016-5258 CVE-2016-5259 CVE-2016-5262 CVE-2016-5263 CVE-2016-5264 CVE-2016-5265 Multiple security issues have been found in the Mozilla […]
Discovered: August 4, 2016 Updated: August 5, 2016 3:38:31 PM Type: Trojan, Virus Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP SONAR.BC.CryptDrop!g4 is a heuristic detection to detect suspicious programs that might drop known […]
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Debian: 3639-1: wordpress: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3639-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wordpress CVE ID : CVE-2015-8834 CVE-2016-5832 CVE-2016-5834 CVE-2016-5835 CVE-2016-5837 CVE-2016-5838 CVE-2016-5839 Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote […]
