It was discovered that there was a CSRF vulnerability in mailman, a web-based mailing list manager, which could allow an attacker to obtain a user’s password. For the stable distribution (jessie), this problem has been fixed in version 1:2.1.18-2+deb8u1. For the unstable distribution (sid), this problem has been fixed in version 1:2.1.23-1. We recommend that […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-5170 A use-after-free issue was discovered in Blink/Webkit. CVE-2016-5171 Another use-after-free issue was discovered in Blink/Webkit. CVE-2016-5172 Choongwoo Han discovered an information leak in the v8 javascript library. CVE-2016-5173 A resource bypass issue was discovered in extensions. CVE-2016-5174 Andrey Kovalev discoved a way to bypass […]
Discovered: September 15, 2016 Updated: September 15, 2016 3:44:33 PM Type: Trojan Infection Length: Varies Systems Affected: Linux Linux.Trojan is a generic detection used to identify malicious software that targets computers running the Linux operating system. Antivirus Protection Dates Initial Rapid Release version September 15, 2016 Latest Rapid Release version September 15, 2016 Initial Daily […]
Risk High Date Discovered September 13, 2016 Description Microsoft ASP.NET Core MVC is prone to multiple privilege escalation vulnerabilities. Attackers can exploit these issues to gain elevated privileges. Microsoft ASP.NET Core MVC 1.0.0 is vulnerable. Technologies Affected Microsoft ASP.NET Core MVC 1.0.0 Recommendations Block external access at the network boundary, unless external parties require service. […]
Risk Medium Date Discovered September 13, 2016 Description Microsoft Application Virtualization is prone to an information-disclosure vulnerability. An attacker can leverage this issue to obtain sensitive information that may aid in further attacks. Technologies Affected Microsoft Office 2007 SP3 Microsoft Office 2010 Service Pack 2 (32-bit editions) Microsoft Office 2010 Service Pack 2 (64-bit editions) […]
An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2016:1865-01 Product: Red Hat Enterprise Linux Supplementary Advisory […]
Slackware: 2016-257-01: mariadb / mysql: Security Update Posted by Anthony Pell New mariadb or mysql packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…] [slackware-security] mariadb / mysql (SSA:2016-257-01) New mariadb or mysql packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a […]
The World Anti-Doping Agency (WADA) has revealed that it was the victim of a cyberattack, which it has attributed to the Russian cyberespionage group, Tsar Team (APT28). According to the agency, the group, which also goes by the moniker Fancy Bear, was able to gain access to its Anti-Doping Administration and Management System (ADAMS) database. […]
Dawid Golunski discovered that the mysqld_safe wrapper provided by the MySQL database server insufficiently restricted the load path for custom malloc implementations, which could result in privilege escalation. The vulnerability was addressed by upgrading MySQL to the new upstream version 5.5.52, which includes additional changes, such as performance improvements, bug fixes, new features, and possibly […]
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Red Hat: 2016:1858-01: ruby193-rubygem-actionpack: Moderate Advisory Posted by Anthony Pell An update for ruby193-rubygem-actionpack is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ruby193-rubygem-actionpack security update Advisory ID: RHSA-2016:1858-01 Product: Red Hat Software Collections […]
Red Hat: 2016:1857-01: ror40-rubygem-actionpack: Moderate Advisory Posted by Anthony Pell An update for ror40-rubygem-actionpack is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ror40-rubygem-actionpack security update Advisory ID: RHSA-2016:1857-01 Product: Red Hat Software Collections […]
Red Hat: 2016:1855-01: rh-ror42: Moderate Advisory Posted by Anthony Pell An update for rh-ror42-rubygem-actionview, rh-ror42-rubygem-activerecord, and rh-ror42-rubygem-actionpack is now available for Red Hat Software Collections. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-ror42 security update Advisory ID: RHSA-2016:1855-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1855.html Issue date: 2016-09-13 CVE Names: CVE-2016-6316 CVE-2016-6317 […]
Red Hat: 2016:1856-01: rh-ror41-rubygem-actionview: Moderate Advisory Posted by Anthony Pell An update for rh-ror41-rubygem-actionview is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-ror41-rubygem-actionview security update Advisory ID: RHSA-2016:1856-01 Product: Red Hat Software Collections […]
An update for libarchive is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: libarchive security update Advisory ID: RHSA-2016:1844-01 Product: Red Hat Enterprise Linux […]
An update for libarchive is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: libarchive security update Advisory ID: RHSA-2016:1850-01 Product: Red Hat Enterprise Linux […]
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1854-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1854.html Issue date: 2016-09-12 CVE Names: […]
Risk Level: Very Low. Type: Trojan.
Discovered: September 12, 2016 Updated: September 13, 2016 3:19:08 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Riccietex is a Trojan horse that installs potentially malicious software and modifies browser settings […]
Ransomware is a major threat that keeps growing over time. According to Cisco’s recent midyear report, it dominates the malware market and is the most profitable malware type in history. By now, it seems unlikely any regular reader of our blog does not already know something about ransomware. If you do not—or would like a […]
I talk a lot about the security problems and weaknesses of the internet, as well as the devices connected to it. It’s all true, and we badly need improvements. Yet the irony is that security in our online world is actually better than in our physical world. Think of how many people are scammed by […]
��}ے�ƒ��(A�”i/}o��%�:#YZ�|�gdmG(���f��8��O�1���32_��YA6�M��t�%�ʪ�����ʪ|t��룷�}�����Ww����z���5�b��4t��q��? ��0��u�
Risk Medium Date Discovered September 13, 2016 Description Microsoft Office is prone to a security vulnerability that may allow attackers to conduct spoofing attacks. An attacker can exploit this issue to perform unauthorized actions; other attacks are also possible. Technologies Affected Microsoft Outlook 2007 Microsoft Outlook 2010 (32-bit editions) Service Pack 2 Microsoft Outlook 2010 […]
Risk High Date Discovered September 13, 2016 Description Microsoft Windows is prone to a remote code-execution vulnerability. Successful exploits will allow an attacker to execute arbitrary code on the target system. Failed attacks will cause denial of service conditions. Technologies Affected Microsoft Windows 10 Version 1607 for 32-bit Systems Microsoft Windows 10 Version 1607 for […]
Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Multiple vulnerabilities in OpenJPEG, a JPEG 2000 image compression / decompression library, may result in denial of service or the execution of arbitrary code if a malformed JPEG 2000 file is processed. For the stable distribution (jessie), these problems have been fixed in version 2.1.0-2+deb8u1. We recommend that you upgrade your openjpeg2 packages.
