Discovered: April 18, 2016 Updated: April 18, 2016 2:51:04 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Ransomcrypt.AK is a Trojan horse that encrypts files on the compromised computer and asks the user […]
It was discovered that fuseiso, a user-space implementation of the ISO 9660 file system based on FUSE, contains several vulnerabilities. CVE-2015-8836 A stack-based buffer overflow may allow attackers who can trick a user into mounting a crafted ISO 9660 file system to cause a denial of service (crash), or, potentially, execute arbitrary code. CVE-2015-8837 An […]
Shayan Sadigh discovered a vulnerability in OpenSSH: If PAM support is enabled and the sshd PAM configuration is configured to read userspecified environment variables and the UseLogin option is enabled, a local user may escalate her privileges to root. In Debian UseLogin is not enabled by default. For the oldstable distribution (wheezy), this problem has […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3549-1 security@debian.org https://www.debian.org/security/ Michael Gilbert April 15, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1651 CVE-2016-1652 CVE-2016-1653 CVE-2016-1654 CVE-2016-1655 CVE-2016-1657 CVE-2016-1658 CVE-2016-1659 Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1651 An out-of-bounds read issue was discovered in the pdfium library. CVE-2016-1652 […]
A heap buffer overflow vulnerability was removed from the poppler library. ——————————————————————————– Fedora Update Notification FEDORA-2016-a97dfe609c 2016-04-15 03:13:35.677680 ——————————————————————————– Name : poppler Product : Fedora 23 Version : 0.34.0 Release : 2.fc23 URL : http://poppler.freedesktop.org/ Summary : PDF rendering library Description : Poppler, a PDF rendering library, is a fork of the xpdf PDF viewer […]
Posted by Anthony Pell Rebased to 0.12.1. ——————————————————————————– Fedora Update Notification FEDORA-2016-e6e8436b98 2016-04-15 03:13:35.679696 ——————————————————————————– Name : qpid-proton Product : Fedora 23 Version : 0.12.1 Release : 1.fc23 URL : http://qpid.apache.org/proton/ Summary : A high performance, lightweight messaging library Description : Proton is a high performance, lightweight messaging library. It can be used in […]
Update to 4.8 ——————————————————————————– Fedora Update Notification FEDORA-2016-048ffb6235 2016-04-15 03:16:06.565301 ——————————————————————————– Name : libtasn1 Product : Fedora 24 Version : 4.8 Release : 1.fc24 URL : http://www.gnu.org/software/libtasn1/ Summary : The ASN.1 library used in GNUTLS Description : A library that provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Debian: 3549-1: chromium-browser: Summary Fedora 23 poppler-0.34.0-2.fc23 Fedora 23 qpid-proton-0.12.1-1.fc23 Fedora 24 libtasn1-4.8-1.fc24 Fedora 24 cryptopp-5.6.3-3.fc24 Fedora 24 samba-4.4.2-1.fc24 Debian: 3548-2: samba: Summary Fedora 22 samba-4.2.11-0.fc22 Community Linux Events Linux […]
Posted by Anthony Pell Security fix for CVE-2015-5370, CVE-2016-2110, CVE-2016-2111, CVE-2016-2112,CVE-2016-2113, CVE-2016-2114, CVE-2016-2115, CVE-2016-2118 ——————————————————————————– Fedora Update Notification FEDORA-2016-383fce04e2 2016-04-15 03:16:06.564657 ——————————————————————————– Name : samba Product : Fedora 24 Version : 4.4.2 Release : 1.fc24 URL : http://www.samba.org/ Summary : Server and Client software to interoperate with Windows machines Description : Samba is the […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1651 An out-of-bounds read issue was discovered in the pdfium library. CVE-2016-1652 A cross-site scripting issue was discovered in extension bindings. CVE-2016-1653 Choongwoo Han discovered an out-of-bounds write issue in the v8 javascript library. CVE-2016-1654 Atte Kettunen discovered an uninitialized memory read condition. CVE-2016-1655 Rob […]
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2015-5370 Jouni Knuutinen from Synopsys discovered flaws in the Samba DCE-RPC code which can lead to denial of service (crashes and high cpu consumption) and man-in-the-middle attacks. CVE-2016-2110 Stefan […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3548-2 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : samba Debian Bug : 820947 The upgrade to Samba 4.2 issued as DSA-3548-1 introduced a packaging regression causing an additional dependency on the samba binary package for the samba-libs, samba-common-bin, python-samba and samba-vfs-modules binary […]
Posted by Anthony Pell Security fix for CVE-2015-5370, CVE-2016-2110, CVE-2016-2111, CVE-2016-2112,CVE-2016-2113, CVE-2016-2114, CVE-2016-2115, CVE-2016-2118 ——————————————————————————– Fedora Update Notification FEDORA-2016-48b3761baa 2016-04-14 00:52:48.149054 ——————————————————————————– Name : samba Product : Fedora 22 Version : 4.2.11 Release : 0.fc22 URL : http://www.samba.org/ Summary : Server and Client software to interoperate with Windows machines Description : Samba is the […]
Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3548-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : samba CVE ID : CVE-2015-5370 CVE-2016-2110 CVE-2016-2111 CVE-2016-2112 CVE-2016-2113 CVE-2016-2114 CVE-2016-2115 CVE-2016-2118 Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The […]
Posted by Anthony Pell Security fix for CVE-2015-5370, CVE-2016-2110, CVE-2016-2111, CVE-2016-2112,CVE-2016-2113, CVE-2016-2114, CVE-2016-2115, CVE-2016-2118 ——————————————————————————– Fedora Update Notification FEDORA-2016-be53260726 2016-04-13 16:54:31.873262 ——————————————————————————– Name : samba Product : Fedora 23 Version : 4.3.8 Release : 0.fc23 URL : http://www.samba.org/ Summary : Server and Client software to interoperate with Windows machines Description : Samba is the […]
Not even a week has passed since ESET warned users worldwide about an active Ray-Ban scam campaign on Facebook, which tricks users into sending their payment card details to the attackers. Today we bring you information on yet another malicious activity targeting the world’s largest social network. This time, malicious links are disguised as a […]
Discovered: April 14, 2016 Updated: April 14, 2016 8:27:22 AM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Vista, Windows XP Packed.Generic.500 is a heuristic detection for files that may have been obfuscated or encrypted in order to conceal them from antivirus software. […]
Risk High Date Discovered April 12, 2016 Description Microsoft Windows is prone to a remote code-execution vulnerability. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will result in a denial of service condition. Technologies Affected Microsoft .NET Framework 4.6 Microsoft .NET Framework […]
Risk High Date Discovered April 12, 2016 Description Microsoft Edge is prone to a remote privilege-escalation vulnerability. An attacker can exploit this issue to gain elevated privileges. Successful exploits may aid in further attacks. Recommendations Block external access at the network boundary, unless external parties require service. Filter access to the affected computer at the […]
Risk High Date Discovered April 12, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]
Risk High Date Discovered April 12, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]
Posted by Anthony Pell Rebase to the new upstream bugfix-only version. Add security fixes for thereferenced bugs. ——————————————————————————– Fedora Update Notification FEDORA-2016-f8eee2e628 2016-04-13 03:26:08.777154 ——————————————————————————– Name : imlib2 Product : Fedora 23 Version : 1.4.8 Release : 1.fc23 URL : http://docs.enlightenment.org/api/imlib2/html/ Summary : Image loading, saving, rendering, and manipulation library Description : Imlib 2 […]
Posted by Anthony Pell Update to xerces-c 3.1.3, fixing CVE-2016-0729 ——————————————————————————– Fedora Update Notification FEDORA-2016-ae9ac16cf3 2016-04-13 03:26:08.776399 ——————————————————————————– Name : xerces-c Product : Fedora 23 Version : 3.1.3 Release : 1.fc23 URL : http://xml.apache.org/xerces-c/ Summary : Validating XML Parser Description : Xerces-C is a validating XML parser written in a portable subset of C++. […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 imlib2-1.4.8-1.fc23 Fedora 23 xerces-c-3.1.3-1.fc23 Fedora 23 libreswan-3.17-1.fc23 Red Hat: 2016:0612-01: samba and samba4: Critical Advisory Red Hat: 2016:0618-01: samba: Critical Advisory Red Hat: 2016:0625-01: samba: Important Advisory Red […]
An update for samba4 and samba is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7, respectively. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba and samba4 security, bug fix, and enhancement update Advisory ID: RHSA-2016:0612-01 […]
An update for samba is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba security, bug fix, and enhancement update Advisory ID: RHSA-2016:0618-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0618.html […]
An update for samba is now available for Red Hat Enterprise Linux 4 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: samba security update Advisory ID: RHSA-2016:0625-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0625.html Issue date: 2016-04-12 CVE […]
An update for samba4 is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 Extended Update Support. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba4 security, bug fix, and enhancement […]
An update for samba3x is now available for Red Hat Enterprise Linux 5.6 Long Life and Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba3x security update Advisory ID: RHSA-2016:0624-01 Product: Red Hat Enterprise Linux […]
An update for samba is now available for Red Hat Enterprise Linux 5.6 Long Life and Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: samba security update Advisory ID: RHSA-2016:0623-01 Product: Red Hat Enterprise Linux […]
An update for samba is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 Extended Update Support. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba security update Advisory ID: RHSA-2016:0619-01 […]
An update for samba is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba security update Advisory ID: RHSA-2016:0611-01 Product: Red Hat Enterprise […]
An update for samba3x is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba3x security update Advisory ID: RHSA-2016:0613-01 Product: Red Hat Enterprise […]
Discovered: April 12, 2016 Updated: April 13, 2016 8:56:48 AM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Zbot.D is a Trojan horse that opens a back door and steals information from the compromised […]
Several vulnerabilities were discovered in Imagemagick, a program suite for image manipulation. This update fixes a large number of potential security problems such as null-pointer access and buffer-overflows that might lead to memory leaks or denial of service. None of these security problems have a CVE number assigned. For the oldstable distribution (wheezy), this problem […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 postgresql-9.5.2-1.fc24 Fedora 24 xerces-c-3.1.3-1.fc24 Fedora 24 libreswan-3.17-1.fc24 Red Hat: 2016:0617-01: kernel: Moderate Advisory Debian: 3485-2: didiwiki: Summary Red Hat: 2016:0615-01: openvswitch: Important Advisory Ubuntu: 2948-2: Linux kernel (Utopic […]
Posted by Anthony Pell Update to xerces-c 3.1.3, fixing CVE-2016-0729 ——————————————————————————– Fedora Update Notification FEDORA-2016-9ff972ca42 2016-04-12 09:36:30.965273 ——————————————————————————– Name : xerces-c Product : Fedora 24 Version : 3.1.3 Release : 1.fc24 URL : http://xml.apache.org/xerces-c/ Summary : Validating XML Parser Description : Xerces-C is a validating XML parser written in a portable subset of C++. […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 postgresql-9.5.2-1.fc24 Fedora 24 xerces-c-3.1.3-1.fc24 Fedora 24 libreswan-3.17-1.fc24 Red Hat: 2016:0617-01: kernel: Moderate Advisory Debian: 3485-2: didiwiki: Summary Red Hat: 2016:0615-01: openvswitch: Important Advisory Ubuntu: 2948-2: Linux kernel (Utopic […]
An update for kernel is now available for Red Hat Enterprise Linux 6.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security and bug fix update Advisory ID: RHSA-2016:0617-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0617.html Issue […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3485-2 security@debian.org https://www.debian.org/security/ Sebastien Delafond April 12, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : didiwiki Debian Bug : 818708 The update for didiwiki issued as DSA-3485-1 introduced a regression that caused a large number of valid pages to not be accessible anymore. This occurred mostly for pages whose […]
Updated openvswitch packages that fix one security issue are now available for Red Hat OpenShift Enterprise 3.1. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openvswitch security update Advisory ID: RHSA-2016:0615-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2016:0615 Issue date: 2016-04-11 CVE […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 postgresql-9.5.2-1.fc24 Fedora 24 xerces-c-3.1.3-1.fc24 Fedora 24 libreswan-3.17-1.fc24 Red Hat: 2016:0617-01: kernel: Moderate Advisory Debian: 3485-2: didiwiki: Summary Red Hat: 2016:0615-01: openvswitch: Important Advisory Ubuntu: 2948-2: Linux kernel (Utopic […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3547-1 security@debian.org https://www.debian.org/security/ Luciano Bello April 11, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imagemagick Debian Bug : 811308 Several vulnerabilities were discovered in Imagemagick, a program suite for image manipulation. This update fixes a large number of potential security problems such as null-pointer access and buffer-overflows that […]
Discovered: April 11, 2016 Updated: April 11, 2016 8:41:53 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Downloader.Orcalata is a Trojan horse that downloads potentially malicious files onto the compromised computer. Antivirus Protection Dates Initial Rapid […]
