Update Node.js to the 5.x stable branch This update also includes a fix for aman-in-the-middle vulnerability in npm. ——————————————————————————– Fedora Update Notification FEDORA-2016-6ab2d29fba 2016-04-06 14:05:38.729188 ——————————————————————————– Name : nodejs-sqlite3 Product : Fedora 24 Version : 3.1.2 Release : 3.fc24 URL : https://github.com/mapbox/node-sqlite3 Summary : Asynchronous, non-blocking SQLite3 bindings for Node.js Description : Asynchronous, non-blocking SQLite3 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]
Several vulnerabilities were discovered in cgit, a fast web frontend for git repositories written in C. A remote attacker can take advantage of these flaws to perform cross-site scripting, header injection or denial of service attacks. For the stable distribution (jessie), these problems have been fixed in version 0.10.2.git2.0.1-3+deb8u1. For the testing distribution (stretch), these […]
Several vulnerabilities were discovered in Django, a high-level Python web development framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2512 Mark Striemer discovered that some user-supplied redirect URLs containing basic authentication credentials are incorrectly handled, potentially allowing a remote attacker to perform a malicious redirect or a cross-site scripting attack. CVE-2016-2513 Sjoerd […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Red Hat: 2016:0601-01: bind: Important Advisory Ubuntu: 2947-3: Linux kernel (Raspberry Pi 2) vulnerabilities Ubuntu: 2949-1: Linux kernel (Vivid HWE) vulnerabilities Ubuntu: 2948-1: Linux kernel (Utopic HWE) vulnerabilities Ubuntu: 2947-2: […]
Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2947-3 April 06, 2016 linux-raspi2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux-raspi2: Linux kernel for Raspberry […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2949-1 April 06, 2016 linux-lts-vivid vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-vivid: Linux hardware enablement kernel from Vivid for Trusty […]
Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2948-1 April 06, 2016 linux-lts-utopic vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-utopic: Linux hardware enablement […]
Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2947-2 April 06, 2016 linux-lts-wily vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-wily: Linux hardware enablement […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2946-1 April 06, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: Venkatesh Pottem discovered a use-after-free […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2946-2 April 06, 2016 linux-lts-trusty vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise […]
Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2947-1 April 06, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: Ralf […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Red Hat: 2016:0601-01: bind: Important Advisory Ubuntu: 2947-3: Linux kernel (Raspberry Pi 2) vulnerabilities Ubuntu: 2949-1: Linux kernel (Vivid HWE) vulnerabilities Ubuntu: 2948-1: Linux kernel (Utopic HWE) vulnerabilities Ubuntu: 2947-2: […]
Posted by Anthony Pell An update for graphite2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: graphite2 security, bug fix, and enhancement […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3543-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : oar CVE ID : CVE-2016-1235 Emmanuel Thome discovered that missing sanitising in the oarsh command of OAR, a software used to manage jobs and resources of HPC clusters, could result in privilege escalation. For […]
Posted by Anthony Pell patch to fix #1319858,#1319859,#1319861 ——————————————————————————– Fedora Update Notification FEDORA-2016-0fb6577f07 2016-04-05 13:05:11.637168 ——————————————————————————– Name : vtun Product : Fedora 23 Version : 3.0.3 Release : 15.fc23 URL : http://vtun.sourceforge.net Summary : Virtual tunnel over TCP/IP networks Description : VTun provides a method for creating Virtual Tunnels over TCP/IP networks and allows […]
��}�۶��o�*�ӧL)I}̗g,��c���ڎ�39�s��DBg(���ht�����U��U��or�d���4��${�sS$�ݍF�������O��������7�N�G>$�8-��s�,?z�A�{O’�:�{�$�>������5q/��1�c���� h��<�ׯ���bU�NY_�t�,�a�+=s�x�wإk3C�h�wc�zFdS��;u�Ɯ�=fDňK�#׆�p?�lإ��6�g����ɞ��ҡ�3z������߷zwaw�zu-L�K����������?�<���;��vz������_�x��IXD����_��y}-���&�b�B�E�2ǥ}-]�N`����lfΘ�^���I��s��Sk�SV=k8&y]}q��8� 腤� ����Y@�ȣc���S��i�Ġ��Md�cн������ݽ���A��ʞ���V��n�l3�/iL���4=��ɠ�z��u��#�ޮ��~��;8��8����k��[�� �~l��l>�g8e+p���yd�Qh�)v��[ClUՋ^�O���DC��քVM����sv�[��9 p�?E�4�%Ɓ��L&b_l7��/x����:�+��c�yCj_�3�i~�lc��S�F��^!��~k�� ���� ����ƍ��Y�Q}�Рe�3{��9Zk�z�i�hMY�.�;�8��cjOD���}�m���E1Ll�|n��5�J849��8��vz����1l��#��s���u��ׄ�s3,� �1w=l���C����y8�^��+���0*a,�^?m7��V��O�e��rL��q#C ������FCm��,��R���M C��V&��8��D�^��@��0}@�8z�D��H?��ЉZ�V֗��_���)��w�a&0��_�Y[i�h���]�����AMu��w�����[D��v�O��;�X�� ��͆|(�43)�I[5˾�d[�����ݧk�HF���կ��tL����u4″�� ���iD�T_K�3h�Є@�)��Mr>:-���G����H�TneA� K�N��c�ḗ��GC#��i^� q;0K-(,S�9������H�$�|���N�5��;�B T���4��”5��*�X[I�s���j4�z��#<.���/�fOp��K�R� '�:�@���)m�8��%����c��˩��1Oe1�~d�� ���N��߾���[��)e�3�jג�ѥ�C��y8q��j�x�J�?k9������G�>��߀]�A��’}O�(�a�~s�g3�����?u��-�F�CQ� � B��WQN����*=���=��h�����Lz�c�PΥ���q.l����W�V�Q�?v;��h9Q�F� ��mF�^����U�x�;K)D����(�k3�^���P� *’|�j�P�y��uB>�Ё��N� �K�gL�x��� �ȸ����%ފ�����R��F�y���/�郕���תÒ8�’�v�-� p�듗��1{1��7��֗�b�ܖ��+�BE �=���64��b�k�”>�5(�E��nJ��IQ�RpӣN�l���#�;>�iWGu����X���{�����{0e�)��ř��3|�Rn�iMa�E;�6�6��^�r�����D���Z��B(�]�?�X����.%�e*4D ��}hy�A�J���>yc”�P�j���B��y�H�ւ$��~k~*&�C’���(�6�p�����dΓ���i��rQ�܇�P���U�Rw&�!)u�S�?��)��J��IY�ۖ�Q^����Y&�P�L����w�OjrՠId28������� )7�C��a&�@ߺ5��d�-���dzO� ���;6][����)��� ���_��{���v��ߕ�e����_���n�P)ϡ��#�y���I0rд�����9�t%s��z�q���F��/�Ic��ΰ�b�y8�9������@Rn /���M��TU�����e����m��C��sc���W����@�W�Z�zit�XS���&S��O�7(��6�3TNG��IȜ���uU��P�f}_�=�Y�C>�U��ke���Œ;���T�H��.(�p��ɑ�����v��#u��- �������αֻuI��j���e�:� h��Ӿ����t�=�F���c�xt�<��y��Q،�V��S�W�����g�� gE ��;�D �澄�!4 �� OƓ�d�1��8=��v�!]��`�z-�G<�sD 6alK4��!�� �ê����t��Q@7�$�d�x!���~��&n�q�"xMӐa'I�G��`$x�D�k�^$'��DJB��x�u�H�sX]�u��k /D�@��S�SyT'�s�=��1�B����7�+PT**�y2���M�ZbV�HQ���r&��*��� G�g���C�>R� �g���2�AF���Q�d�?ȸ ��>^�?�b_���vo�-Y9h�.�s&E���EH9�t�Zf���]�)h�<�K��P�6��yq߳p�c�WǢ��E_��:}u,��X�ձh�� ����c�WǢ��E_��:}u,Z�_��:}u,��X�ձ�vf��m2dx�W���� !lo�"�S(o�u� ��,�p����~� =�� 3��=�l[Pd��’����x:aY�|P[�T�d��&/Dm���h���E)�gu�XC�_D��c�00?����k�4��k�����A.�o�E�g��F�,K�h��I�^�щ��^ ���h�� V.Z<��|�� X�X�ľ�zf�g�Hm�t�I�����g��ݝ�����������@�"�y�j�x̹�$_��者���J,�ȡ�2f�)OB.?��F�&�Y<��j�}a��̄�ni^Zw��ȼ�)�r-�5���E���~{��n�Y��J����g"�^�J�,Ⱦ0Ƙ�X��D��`4c��1B�tu��T��,�W�k] (�p R������b|]&*���Fѡ,�����xH�3����E��VZ��K ,T��Imb-p+��Z�j�D���]��2G��֒���=��4Q […]
Discovered: April 6, 2016 Updated: April 6, 2016 1:21:55 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Cryptolocker.AL is a Trojan horse that encrypts files on the compromised computer. It then asks the user to pay […]
Discovered: April 6, 2016 Updated: April 6, 2016 3:00:24 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.AE is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt them. Antivirus […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Posted by Anthony Pell 31 Mar 2016, **PHP 5.6.20** **CLI Server:** * Fixed bug php#69953 (SupportMKCALENDAR request method). (Christoph) **Core:** * Fixed bug php#71596(Segmentation fault on ZTS with date function (setlocale)). (Anatol) **Curl:*** Fixed bug php#71694 (Support constant CURLM_ADDED_ALREADY). (mpyw) **Date:*** Fixed bug php#71635 (DatePeriod::getEndDate segfault). (Thomas Punt)**Fileinfo:** * Fixed bug php#71527 (Buffer over-write […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3541-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond April 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : roundcube CVE ID : CVE-2015-8770 High-Tech Bridge Security Research Lab discovered that Roundcube, a webmail client, contained a path traversal vulnerability. This flaw could be exploited by an attacker to access sensitive files on […]
Multiple vulnerabilities have been found in Xen, the worst of which cause a Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – Gentoo Linux Security […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Posted by Anthony Pell Libav could be made to crash or run programs as your login if it opened aspecially crafted file. ========================================================================== Ubuntu Security Notice USN-2944-1 April 04, 2016 libav vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Libav could be made to […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Posted by Anthony Pell patch to fix #1319858,#1319859,#1319861 ——————————————————————————– Fedora Update Notification FEDORA-2016-256f700c92 2016-04-04 17:23:29.743823 ——————————————————————————– Name : vtun Product : Fedora 24 Version : 3.0.3 Release : 15.fc24 URL : http://vtun.sourceforge.net Summary : Virtual tunnel over TCP/IP networks Description : VTun provides a method for creating Virtual Tunnels over TCP/IP networks and allows […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]
Discovered: April 4, 2016 Updated: April 5, 2016 8:48:04 AM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Infostealer.Fakepude is a Trojan horse that steals information from the compromised computer. Antivirus Protection Dates Initial Rapid Release version […]
Discovered: April 1, 2016 Updated: April 4, 2016 9:50:42 AM Type: Trojan Infection Length: Varies Systems Affected: Linux, Solaris, Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP PHP.Ransomcrypt.B is a Trojan horse that encrypts files on the compromised server. Antivirus Protection […]
The Trump Hotel Collection has once again suffered a data breach, according to a security expert. Brian Krebs reported that banking industry sources have informed him that the chain, which belongs to the Republican presidential candidate Donald Trump, has been the victim of another attack. Mr. Krebs said that he was alerted to this story […]
Digital certificates and malware go together like peanut butter and petroleum jelly — they can be sandwiched together easily, but the result is not exactly tasty or good for you. As you may know, digital certificates are used to cryptographically sign executable code and documents. If the digital certificate used for signing the content was […]
Emmanuel Thome discovered that missing sanitising in the oarsh command of OAR, a software used to manage jobs and resources of HPC clusters, could result in privilege escalation. For the oldstable distribution (wheezy), this problem has been fixed in version 2.5.2-3+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 2.5.4-2+deb8u1. For […]
Several vulnerabilities have been discovered in Mercurial, a distributed version control system. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2016-3068 Blake Burkhart discovered that Mercurial allows URLs for Git subrepositories that could result in arbitrary code execution on clone. CVE-2016-3069 Blake Burkhart discovered that Mercurial allows arbitrary code execution when converting Git […]
High-Tech Bridge Security Research Lab discovered that Roundcube, a webmail client, contained a path traversal vulnerability. This flaw could be exploited by an attacker to access sensitive files on the server, or even execute arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 0.7.2-9+deb7u2. For the testing (stretch) and unstable […]
Discovered: April 4, 2016 Updated: April 4, 2016 11:38:57 PM Type: Worm Infection Length: 262,144 bytes Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP W32.Ransomlock.AP is a is a worm that locks the desktop, making the compromised computer unusable. […]
Risk High Date Discovered March 8, 2016 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed […]
Posted by Anthony Pell A NetworkManager 1.0.x branch stable update: * Release notes:https://cgit.freedesktop.org/NetworkManager/NetworkManager/tree/NEWS?h=1.0.12 *Release announcement: https://mail.gnome.org/archives/networkmanager-list/2016-April/msg00000.html ——————————————————————————– Fedora Update Notification FEDORA-2016-8201e3fefa 2016-04-03 14:04:39.114316 ——————————————————————————– Name : NetworkManager Product : Fedora 23 Version : 1.0.12 Release : 1.fc23 URL : http://www.gnome.org/projects/NetworkManager/ Summary : Network connection manager and user applications Description : NetworkManager is a system […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3540-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : lhasa CVE ID : CVE-2016-2347 Marcin Noga discovered an integer underflow in Lhasa, a lzh archive decompressor, which might result in the execution of arbitrary code if a malformed archive is processed. For the […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Posted by Anthony Pell Multiple vulnerabilities have been found in QEMU, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – – – – – – […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Posted by Anthony Pell Update to NetworkManager 1.2-beta3. Upstream release announcement:https://mail.gnome.org/archives/networkmanager-list/2016-March/msg00164.html ——————————————————————————– Fedora Update Notification FEDORA-2016-cd218eef79 2016-04-02 15:48:47.755168 ——————————————————————————– Name : NetworkManager Product : Fedora 24 Version : 1.2.0 Release : 0.8.beta3.fc24 URL : http://www.gnome.org/projects/NetworkManager/ Summary : Network connection manager and user applications Description : NetworkManager is a system service that manages network interfaces […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
