Gustavo Grieco discovered that jansson, a C library for encoding, decoding and manipulating JSON data, did not limit the recursion depth when parsing JSON arrays and objects. This could allow remote attackers to cause a denial of service (crash) via stack exhaustion, using crafted JSON data. For the stable distribution (jessie), this problem has been […]
Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service. For the stable distribution (jessie), these problems have been fixed in version 38.8.0-1~deb8u1. For the unstable distribution (sid), these problems will be fixed […]
It was discovered that XStream, a Java library to serialize objects to XML and back again, was susceptible to XML External Entity attacks. For the stable distribution (jessie), this problem has been fixed in version 1.4.7-2+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 1.4.9-1. For the unstable distribution (sid), this […]
Risk High Date Discovered February 21, 2006 Description Apple Mac OS X is prone to an arbitrary command-execution vulnerability when processing metadata in archive files. Commands would be executed in the context of the user opening the archive file. Attackers can reportedly use Safari and Apple Mail as exploitation vectors for this vulnerability. Mac OS […]
Posted by Anthony Pell An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1080-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1080.html […]
An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2016:1079-01 Product: Red Hat Enterprise Linux Supplementary Advisory […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3575-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 12, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libxstream-java CVE ID : CVE-2016-3674 It was discovered that XStream, a Java library to serialize objects to XML and back again, was susceptible to XML External Entity attacks. For the stable distribution (jessie), this […]
An update for docker is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: docker security, bug fix, and enhancement update Advisory ID: RHSA-2016:1034-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1034.html Issue […]
Several security issues were fixed in QEMU. ========================================================================== Ubuntu Security Notice USN-2974-1 May 12, 2016 qemu, qemu-kvm vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in QEMU. Software Description: […]
Parenting has changed. In the digital age there are now more opportunities, through technology, to create experiences that were previously impossible and to enrich the lives of your children. Yet, at the same time, there are even greater and more complex risks, threats that were non-existent half a decade ago. For many moms and dads, […]
On the 14th of May, more than two dozen talented musicians from Europe will compete in Stockholm in one of the longest-running television shows in history – Eurovision. For the 61th time, contestants representing members of the European Broadcasting Union will perform an original piece to compete for the jury’s and public’s favor in the […]
An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1033-01 Product: Red […]
Posted by Anthony Pell An update for kernel-rt is now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security and bug fix update […]
Posted by Anthony Pell An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security, bug fix, and enhancement […]
An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2016:1041-01 Product: Red Hat Enterprise […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Red Hat: 2016:1033-01: kernel: Important Advisory Red Hat: 2016:1055-01: kernel-rt: Important Advisory Red Hat: 2016:1051-01: kernel-rt: Important Advisory Red Hat: 2016:1041-01: thunderbird: Important Advisory Slackware: 2016-132-01: mozilla-thunderbird: Security Update Red […]
An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-ibm security update Advisory ID: RHSA-2016:1039-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1039.html Issue date: 2016-05-11 CVE Names: […]
Updated openshift packages that fix one security issue are now available for Red Hat OpenShift Enterprise 3.1. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openshift security update Advisory ID: RHSA-2016:1038-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2016:1038 Issue date: 2016-05-11 CVE […]
An update for pcre is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: pcre security update Advisory ID: RHSA-2016:1025-01 Product: Red Hat Enterprise Linux […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3565-2 security@debian.org https://www.debian.org/security/ Sebastien Delafond May 11, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : monotone ovito pdns qtcreator softhsm Debian Bug : 823823 This updates fixes a regression introduced in botan1.10 by DSA-3565-1: packages depending on libbotan1.10 needed to be rebuilt against the latest version to function properly. […]
The UK-based telecommunications company TalkTalk has seen its profits more than halve, following last year’s “significant and sustained cyberattack”. Profits were down to $20 million compared with $46 million for the same period last year, which has largely been attributed to the financial fallout of the high-profile incident. The cost of the cyberattack, which was […]
As I write this, if you’re running Adobe Flash on your Windows, Mac, Linux or Chrome OS computer you’re potentially at risk. Adobe has issued a security advisory, warning of an as-yet unpatched critical security hole in its popular Flash player software that is reported to being actively exploited by criminals in the wild. No […]
Discovered: May 12, 2016 Updated: May 12, 2016 10:56:36 AM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Wortrik is a Trojan horse that sends spam email messages from the compromised computer. Antivirus Protection […]
Risk High Date Discovered May 10, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted […]
Risk Medium Date Discovered May 10, 2016 Description Microsoft Windows is prone to a local security-bypass vulnerability. A local attacker can leverage this issue to bypass certain security restrictions and perform unauthorized actions. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. Allow only trusted individuals to have […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]
Posted by Anthony Pell Several security issues were fixed in OpenJDK 6. ========================================================================== Ubuntu Security Notice USN-2972-1 May 10, 2016 openjdk-6 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in OpenJDK 6. Software Description: – openjdk-6: Open Source Java […]
Posted by Anthony Pell An update for icedtea-web is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: icedtea-web security, bug fix, and […]
An update for openssh is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openssh security, bug fix, and enhancement update Advisory ID: RHSA-2016:0741-01 […]
An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:0855-01 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]
Security fix for CVE-2016-1548, CVE-2016-2516, CVE-2016-2518, CVE-2016-1550 ——————————————————————————– Fedora Update Notification FEDORA-2016-5b2eb0bf9c 2016-05-10 11:45:44.970959 ——————————————————————————– Name : ntp Product : Fedora 23 Version : 4.2.6p5 Release : 40.fc23 URL : http://www.ntp.org Summary : The NTP daemon and utilities Description : The Network Time Protocol (NTP) is used to synchronize a computer’s time with another reference […]
Posted by Anthony Pell This update contains minor security fixes (for CVE-2016-3075, CVE-2016-1234,CVE-2015-8778, CVE-2015-8776, CVE-2014-9761, CVE-2015-8779) and collects fixesfor bugs encountered by Fedora users. ——————————————————————————– Fedora Update Notification FEDORA-2016-68abc0be35 2016-05-10 11:45:44.966689 ——————————————————————————– Name : glibc Product : Fedora 23 Version : 2.22 Release : 15.fc23 URL : http://www.gnu.org/software/glibc/ Summary : The GNU libc libraries […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Slackware: 2016-132-01: imagemagick: Security Update Red Hat: 2016:1019-01: qemu-kvm-rhev: Important Advisory Ubuntu: 2972-1: OpenJDK 6 vulnerabilities Red Hat: 2016:0778-01: icedtea-web: Moderate Advisory Red Hat: 2016:0741-01: openssh: Moderate Advisory Red Hat: […]
Security fix for CVE-2016-2108, CVE-2016-2107, CVE-2016-2105, CVE-2016-2106 ——————————————————————————– Fedora Update Notification FEDORA-2016-1e39d934ed 2016-05-10 11:43:00.963747 ——————————————————————————– Name : openssl Product : Fedora 22 Version : 1.0.1k Release : 15.fc22 URL : http://www.openssl.org/ Summary : Utilities from the general purpose cryptography library with TLS implementation Description : The OpenSSL toolkit provides support for secure communications between machines. […]
Several vulnerabilities were discovered in qemu, a fast processor emulator. CVE-2016-3710 Wei Xiao and Qinghao Tang of 360.cn Inc discovered an out-of-bounds read and write flaw in the QEMU VGA module. A privileged guest user could use this flaw to execute arbitrary code on the host with the privileges of the hosting QEMU process. CVE-2016-3712 […]
Nitin Venkatesh discovered that websvn, a web viewer for Subversion repositories, is susceptible to cross-site scripting attacks via specially crafted file and directory names in repositories. For the stable distribution (jessie), this problem has been fixed in version 2.3.3-1.2+deb8u2. We recommend that you upgrade your websvn packages.
��}�r�Ȓ���P��d�x�(Y2�e���moKݽ=�E�(��@ ��x܊��݈}݇}؈����ͬ*�)�����9m�@UVVVfVVVV��/�����%�����W�N�K�{��O4�l��4|@&qX�?�)���u�=�0j������Ŕ5د3粧�^̼�8]L#C���*����ᄆ�{�xd�k��W����GƱ? h���=f�Y��G���]:l�a���;v��s�:�,b�Y��s�O�y`H��x¦,��;�f����E���O9�8A���bg���d���A��i��.뿼 F���1X@��l4b!��#ןGO-Q�J@�E�� ������iD����&P��_$� -��EH�.�”gXl����t�@�2�8C�:@��Pz7�Z���Gh8p␆��f�f��0 �y��]o��V�j�Z���RJ�R���H)e�XH2��0^pyv}dv�P�;C��.祗��3t���88J�t�?ј.��,t�?�Ȣ���H(����h����*��Q=� �A��ʺ�l�:�r�3�q���5Z����A�y���l4�+�M}T������pԬw��L阭=��ʜ�xR;�c�S��K#k�c�}��bЕ�C�J��l:Ԗ���ϒl�K�@B�P�c~��RПR�[%JK*~6NY�(!����c��-�O����|Gw6vj��A���l�lE�������O�5�C����l��?[ZC����xc��pȴ��t/^Z�ZM՟���7tg6�t���3/��)���n=�<�k�1h���Į���K ��������p*�h���cs��*~�H�U�ڶV?Y=��&y����4��|A��H����U �ȥc���Q�����`���Q�O��>���vv����~��H��{�F�Ѭ7�f쿠1���7���2oO�֩�wauv%��^����F��V���o��&�a��K�~�u�Ҕ���d���Ќ�a�”����`��^�|qJ�߂H�4�huhդA�<�x�vmX��G�1B��P�z#g��cC�� ��/8��׀�wo���ރ� ���/z)��?��X/i���/�W��j�0�m���.�A� :�Y��A�r��� ��Ƹ�UoЊ��p�wq(�t8�j����ul;��c�0���@�5�AX���u�C�”X�]�W�2#$��>^7F�”��X-�~02��y�hd�s�X�r�W��?d�z�~]��a���Hc�xj ��s5����ߙ��M�-�’D>g;Q���̌(���8�3�b�>�Ct4ÿ��ʈ&Ъ�:a�x���?�l�{0@��&1�{ŏ��bw��C!�i���C��U��K@1������T� �u��-Gu��=�`��{�>cXY�%$�U’b��=a�9V��W��4�� ��5���K�L��bx�dxu�DցGub��T՟�;���:3��`����L�;�$т �*���s�.J JҖ���T8s�ʶ1����̍���4�+z�ҹ#� K��� �6�i�v7U�_���8D�dK�XȢ��6���T�Ñq��q��`;ء�3�W[�tD���~{���:c��LTAjZ�����v찱.���dz w{F#����s�C�����g���P���endHE}7����=H����-�k�n�Y��Kp��@����*�����w#�rVz9���C�����P���~x�p���SMO�y�V�:���ʹL��y”Z���’�k�̶�����]c�C�%R<��Q���sn������3�w��Шދ��nS��Ծ��`~d4N�&�.�ބ��kC�ŘY�(:���OV�bWj�`˘'^�³T����-j���W��1=�~�O�ӄ0��c-��n۴K ��@;�U^P�Q^b�i�r#� ����ԅO�q.�y�w”�m6�+��B’F�*2���,�p*�.py�>��W{P�j�����`!0���~���ҌӀ��!��: ~%=��4��o����G>�R?U��=����C),m4�х�0y�’�KE�#��I�+C��3�� ��2��̓!����H|����#�P�#�D�w/��C�jd 3�[�Z����9�!�a+ e�+4ȣ~-��߃Y4�}Щm�w�����Do��O�t��;`Wu�蒸��x�Ӿ02~)�IZ+sx� ��Dp�û�ײ�T��ϗ��:�1^���҈w�’`����R=-�N�KG����HJd:<��q����Gt����Ў��V�ƆX<8�p�۹�!L���� ���ۆQj@aΘ����蜳D5/D� {���/^�5V'���IPy�ր����ز�d`m%G���ë�`��Z�@=EБ�e��hྔ/e�pp�ӹx@r7 ���繤��xjF1 c�����0��:���Po0�Q�T`R�j���s_�?��a�=�AOǭ�7h����G`�?vt������|���� � ����c����3Ec��^��|�`�г�����ҳ�s��{r�`h{f��i̿�n���6�[����!�o�a������+�!������MRX4��Ô�Q���0�b�b9�*�h�]cjO�C4���UT� n���K�N�)%k2t��bc��4,�� �pH��Z�@o��n�},�q��s<� ����tQa�����H�����'/O��wo�~��M ȱa`��a��/0L�O�~��^UVO7PGԍ�a�PN3b�^�mjQ�|*} _��#��$V�� ����2A��+� ��3���D'�pt[��� +��ʁ��G��P����#���c`jPy�G���T�����'t�R�����)OlF~|sB�G^F����z�g���h�Y 'Y�������6=/�roM5*K�,Pd�3�2��@��o��*]v�aლ(���X;�)F���w�0�3��uR��p���qb65v�O���[�}G��Y��[p�`�Yz�v�y��TN�m�5��.y�Gq���� ��~�C���^k+]}��A=�.”G�hI���(&߱D��門&����2C*� �Q9�7t�����;�qF*�H�΄��˚�����-Cc��#v��?�T��M+$�yX�V�ZI��,LCh �`��g ���4�!���Iz��X㴝_�-0��L��~s�fNZ��g@Rl@!�0�����wߺ�5��DՌ���go���#������!][����)�����/�n���NW ���BÕ”��2�����w:�m2 �#y� ��}oĀ�CFނrăk2�tKrd,��-]);��v{�!y�J���A����x���]|z��b]�&��?��T �R����’�)�cM%`�d����`P�r��g%��@���:��iT��� �F.�;c�Ya��jB����A��N��[`6�ӯtG�D�J�L,g����N����2�x����s���h+��>w�����’�� ��wv� ���%|��`���k�[���aa3KG[Ɬ�;��:��2FOǽ�n�^M���p�&v�[P�m�0����K@�X�|��a&���P� […]
