Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]
Welcome to this week’s security review, which includes insight into Remaiten, bolstering Trident’s cybersecurity, the value of backing up your data and why banks, according to some, should not compensate victims of online fraud. Remaiten: The Linux bot that targets routers and other IoT devices Researchers at ESET revealed that they were actively monitoring a […]
In recent months, there has been a significant increase in the number of networks and users affected by ransomware known as Locky, which is used to encrypt a victim’s files and then demand a ransom to be paid in bitcoins. But, how does this threat manage to infiltrate computer systems and hijack data? From the ESET Research Lab in […]
Marcin Noga discovered an integer underflow in Lhasa, a lzh archive decompressor, which might result in the execution of arbitrary code if a malformed archive is processed. For the oldstable distribution (wheezy), this problem has been fixed in version 0.0.7-2+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 0.2.0+git3fe46-1+deb8u1. For the […]
Randell Jesup and the Firefox team discovered that srtp, Cisco’s reference implementation of the Secure Real-time Transport Protocol (SRTP), does not properly handle RTP header CSRC count and extension header length. A remote attacker can exploit this vulnerability to crash an application linked against libsrtp, resulting in a denial of service. For the oldstable distribution […]
An update for libssh is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: libssh security update Advisory ID: RHSA-2016:0566-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0566.html Issue date: 2016-03-31 CVE Names: […]
An update for mariadb is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: mariadb security and bug fix update Advisory ID: RHSA-2016:0534-01 Product: […]
Posted by Anthony Pell An update for krb5 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: krb5 security update Advisory ID: […]
Posted by Anthony Pell Update to origin 1.1.3, disable v1beta1, v1beta3, fix application/json contenttype, don’t let hyperkube to parse flags for all commands (make it optional)—- Update to origin 1.1.3, disable v1beta1, v1beta3, fix application/jsoncontent type, don’t let hyperkube to parse flags —- Update to origin 1.1.3,disable v1beta1, v1beta3, fix application/json content type —- […]
New upstream release with security bug fix ——————————————————————————– Fedora Update Notification FEDORA-2016-6dc5678273 2016-03-31 20:29:07.231134 ——————————————————————————– Name : python-rsa Product : Fedora 24 Version : 3.4.1 Release : 1.fc24 URL : http://stuvel.eu/rsa Summary : Pure-Python RSA implementation Description : Python-RSA is a pure-Python RSA implementation. It supports encryption and decryption, signing and verifying signatures, and key […]
Posted by Anthony Pell An update for bind is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 Extended Update Support. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: bind security update Advisory ID: RHSA-2016:0562-01 Product: Red Hat […]
APPLE-SA-2016-03-31-1 iBooks Author 2.4.1 Subject: APPLE-SA-2016-03-31-1 iBooks Author 2.4.1 From: Apple Product Security <email@hidden> Date: Thu, 31 Mar 2016 14:14:32 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-31-1 iBooks Author 2.4.1 iBooks Author 2.4.1 is now available and addresses the following: iBooks Author Available for: OS X Yosemite v10.10 or later Impact: Parsing a maliciously […]
A lot happens in the security world and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. MedStar Health, Latest Medical Services Ransomware Target Early this week, MedStar Health, one of the […]
Discovered: April 1, 2016 Updated: April 1, 2016 2:17:04 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Huntpos is a Trojan horse that steals information from the compromised computer. Antivirus Protection Dates Initial […]
Discovered: April 1, 2016 Updated: April 1, 2016 3:49:26 PM Type: Worm Infection Length: 526,336 bytes Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP W32.Woniore is a worm that spreads through removable drives. It also downloads potentially […]
If you’ve ever been infected with serious malware, you may have assumed the culprit is a person sitting in the basement of their mom’s house, or a small group of people huddled in a garage somewhere. It’s really not that simple. There’s a whole global cyber underground network that’s working diligently to make all this happen […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3538-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 31, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libebml CVE ID : CVE-2015-8789 CVE-2015-8790 CVE-2015-8791 Several vulnerabilities were discovered in libebml, a library for manipulating Extensible Binary Meta Language files. CVE-2015-8789 Context-dependent attackers could trigger a use-after-free vulnerability by providing a maliciously […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3537-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 31, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imlib2 CVE ID : CVE-2014-9762 CVE-2014-9763 CVE-2014-9764 Several vulnerabilities were discovered in imlib2, an image manipulation library. CVE-2014-9762 A segmentation fault could occur when opening GIFs without a colormap. CVE-2014-9763 Several divisions by zero, […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3536-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 31, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libstruts1.2-java CVE ID : CVE-2015-0899 It was discovered that libstruts1.2-java, a Java framework for MVC applications, contains a bug in its multi-page validation code. This allows input validation to be bypassed, even if MPV […]
Security fix for CVE-2016-2315, CVE-2016-2324 (by updating to 2.4.11). ——————————————————————————– Fedora Update Notification FEDORA-2016-cee7647200 2016-03-30 17:30:15.403378 ——————————————————————————– Name : git Product : Fedora 22 Version : 2.4.11 Release : 1.fc22 URL : http://git-scm.com/ Summary : Fast Version Control System Description : Git is a fast, scalable, distributed revision control system with an unusually rich command […]
Multiple CVEs ——————————————————————————– Fedora Update Notification FEDORA-2016-b91d895e5a 2016-03-30 17:30:15.402965 ——————————————————————————– Name : moodle Product : Fedora 22 Version : 2.8.11 Release : 1.fc22 URL : http://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) – a free, Open Source software package designed using sound pedagogical principles, to help […]
An update for openvswitch is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openvswitch security update Advisory ID: RHSA-2016:0537-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: […]
Multiple CVEs ——————————————————————————– Fedora Update Notification FEDORA-2016-403715aaec 2016-03-30 17:35:06.232672 ——————————————————————————– Name : moodle Product : Fedora 23 Version : 2.9.5 Release : 1.fc23 URL : http://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) – a free, Open Source software package designed using sound pedagogical principles, to help […]
��}ے�F���(A�”i�o���Z�X�H����Y�E� ƥٴ���}ٍ8’b�6b7b��?�/�̬��l6%�Ҍ%����������z|��wǧ{�}{���ૻ�’��e�����N4�|��51>d�(�[-1�)oy�} ��y<�=�O���)�L*��c粯/�^���}�1K��k��Z��51��G�8�k ������f��,��/���|UϜ�v��/�(Sz��Ѥo�K��:�h2�s"�t��2]��TA1v�:�/y�^�ٰk^���`���=�u�m����r��|������{ջ�ja^��c�7ڝ����݃�;{{���N�v�����gO;= ��?�u�p�������s @�Wd��PcSn;f_�ǃ�辦�x6�3�:�z���! ��%������8~a�N’���!r�1�M���r<�9w���;{�v���=�%h}AMp�nz�눖�zJ��"��ќԁ+PV2���j���Q^�� r,�/-��)~+~X���%�t%�L~c�@!?C�ˠDy���Ie]���naP㿲�]��}�%���s�GF���6�T���O��Z�13D0��E$ jY”�?���O����~��Ԡ)�f��~��Q�?h����tj5!BJ����-���*�0��S��y�����5���[�F�Gڰn6�M��!�����pi�� �2�Q�Eu��:Z�i�-c�#2�����Z��G���=x`#�uO�ӓ�m`�g�X Hs�kM( p��d��Ş��Mm�c���X1R?���@L���?6����v�{�n3}n�7��f�Ѵ�H<����W��roM=�k�wa�v��~����F���^���4��w�����ǔ�|M�5�,#����V�cs���z��9~"Q�p��5�U��}���ǵ�V�#�8j�r��j%���a��az��D*��v�# �����y�^~�xl�.j�~�8�قm��4cH���+����q@v�m���.�rBl<����5hY-_���7�uM��,��FJ�D0�BuMx�s��!���֒��fyV�$(Z�С�� ��n��2��HI����###�Ox=�q82��y�`dD3�X�r�W��?T�F��.uU�V�<�����$[ H �*����u�c���S���&�$@���;��9?�9%�݃�q6��E`��f��(}��É hU}�p��Y�O�h9]�&|�燬͌�~�#(�6:�~�PHo%8���B��Xטc�kտ�}ư��u,����2���)�,X ] �p�P��,�V�10����&���oM��k�5�Z�’��?ow���uf���#�ȋnד�Lȭ”��a�9�B’�%i�h�*��óm̕���#3v���-2�����y����Vb�* ھ �>���4�#0�#���ɖp�%���>( ��md��T�ݑq(DF��o;� iŰ5LG�g�A귇���1�FX� R�1v�o���è`��E0�ފ���Q�0lO� ,�����g���P�̡�}�PW��v:u�z�(�,#w�=�s=��^��4t%�@��Ƣn;�6��̽���^�=gQ�”�C�:X����+����.�/kzf���j��p1y=-�A�m����U��z�F�J�ɸ8�������;PrhTo��p�+acӾ��a~�f`M�&��u���@ֆ �oM��̌#��@��ؒ�8�sO:b��w�>���a�’�Ȇ��Ӆ���K6Ua�~�5`�?��O�<���EQk~��RşT�7���.��nvL7�g��S���}Wm���0|x5u�:`˾M��� �m� �vaG�*4��ax�a�a�� w�U�νȼJ��{�q$�8#V��o ��#), m4�ч��r�)US��cT�0�+Ԋ��翀���Z�L�]����0���}#ln���J���ױ�&�gh�G���q8����r��s�ݗv��j���A�ѣ^�`�ޣ�”��F]>�i_�w�e�V�̲.�ٖ�]kx��j$eq�� ��33�&�k�ɠ|��k#��k�{})D��Pi�tx���� �i��̩�/�oĉT����hQ�>�<���sI��w��� ���ۆQjBabL���btN,Q��b���B��/�:k0�w�B T���5�� 78�*�X[��}�{�j4������!t��5z�ܗ����T�(�E� tk��s���9��G���� �J������C�=-g���Qrݦ|��Y[�U��/侠@�� �i_��7�2A@ɟl�@�4��*�)�S�B�p��է����)�z�+��B��Rb����G�PGb*B�R�Aq�1� �hyA�+%5��5K1��ak�Ij/D�v5�9��� �{�����+?�X�ת��(�&�v�%�8�x�,�fܚ���j��J`�Ki��Wn�G�L���O�M���-Z��0��qJ9F�f��0�zRܩ��6����l���9X���|���rSН�G�v�w�s�G���|���2������Ϫ4�Bd1��Ѫՙ���q|’Zn���IM��K�_0��8ňf�& Z�!(�56�W03���!9�K�s���` M� �@��-k3�W��0��’w�� ���i�~`&ٙ� ��Z��c��a�O�$F�d�����ႁ��0�F�]��L�a� QJ���P���U1S�f�)��S�?n!i٩�2Ճ���-��Nyc^jl��C+3��C���?��U�&Q�p�l,��W19���`�O�s���>,��l�1|�M�^8Ski$/���BP�ɫ’���8����[�� p�dL�}��[����2��C�_���U�v.��K�@���{*i��/�)��M`9�:�B��k��-I~5=���VO�˿�YS��ʒ:Y��L�/�d��/��J��lXhP��R�2��b�”�h�K`p�4�N�<'�IE�G�eע���}��N߲�w��n�a$�o��Ê����yF?q*g�hէ����ފ0 �ۣ�UpR!]D�-w������J�d�������C'��R�C�̈��'�N�$�3bԚ <�&+6���[a[�ںM��Wu�OI�l����R����������p����[f �S��N��MFp,sz?1b�j�ל�8�k�-b� ��*$d����u%�����X�_*�n�x�”���Ւ-��X�-�q�**�X���8��,v��?W��4}�#�������čJh���8gw햜M�mu:i-�Ld�]����|���O}�����?�;ӷ�|��M��* 8�}7)NQj��@�����(E��M�>}�O���x 0�+?����Za�]C�^J���TD-,ؙ�V_��wY8MС���Z.h�����t�̕��ܒ��U��r�~^�� �6c�u�h�V�� […]
Several vulnerabilities were discovered in libebml, a library for manipulating Extensible Binary Meta Language files. CVE-2015-8789 Context-dependent attackers could trigger a use-after-free vulnerability by providing a maliciously crafted EBML document. CVE-2015-8790 Context-dependent attackers could obtain sensitive information from the process’ heap memory by using a maliciously crafted UTF-8 string. CVE-2015-8791 Context-dependent attackers could obtain sensitive […]
Several vulnerabilities were discovered in imlib2, an image manipulation library. CVE-2014-9762 A segmentation fault could occur when opening GIFs without a colormap. CVE-2014-9763 Several divisions by zero, resulting in a program crash, could occur when handling PNM files. CVE-2014-9764 A segmentation fault could occur when opening GIFs with feh. For the oldstable distribution (wheezy), these […]
It was discovered that libstruts1.2-java, a Java framework for MVC applications, contains a bug in its multi-page validation code. This allows input validation to be bypassed, even if MPV is not used directly. For the oldstable distribution (wheezy), this problem has been fixed in version 1.2.9-5+deb7u2. We recommend that you upgrade your libstruts1.2-java packages.
Stelios Tsampas discovered a buffer overflow in the Kamailio SIP proxy which might result in the execution of arbitrary code. For the stable distribution (jessie), this problem has been fixed in version 4.2.0-2+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 4.3.4-2. For the unstable distribution (sid), this problem has been […]
Posted by Anthony Pell An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:0525-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0525.html […]
An update for openvswitch is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openvswitch security update Advisory ID: RHSA-2016:0524-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: […]
An update for openvswitch is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openvswitch security update Advisory ID: RHSA-2016:0523-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3535-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : kamailio CVE ID : CVE-2016-2385 Stelios Tsampas discovered a buffer overflow in the Kamailio SIP proxy which might result in the execution of arbitrary code. For the stable distribution (jessie), this problem has been […]
This update provides recent upstrem fix published with openssh-7.2p2 (#1316529). ——————————————————————————– Fedora Update Notification FEDORA-2016-d339d610c1 2016-03-29 15:13:21.929232 ——————————————————————————– Name : openssh Product : Fedora 22 Version : 6.9p1 Release : 11.fc22 URL : http://www.openssh.com/portable.html Summary : An open source implementation of SSH protocol versions 1 and 2 Description : SSH (Secure SHell) is a program […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Red Hat: 2016:0525-01: chromium-browser: Important Advisory Red Hat: 2016:0524-01: openvswitch: Important Advisory Red Hat: 2016:0523-01: openvswitch: Important Advisory Debian: 3535-1: kamailio: Summary Fedora 22 openssh-6.9p1-11.fc22 Fedora 22 webkitgtk-2.4.10-1.fc22 Debian: 3534-1: […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3534-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : dhcpcd CVE ID : CVE-2012-6698 CVE-2012-6699 CVE-2012-6700 Guido Vranken discovered several vulnerabilities in dhcpcd, a DHCP client, which may result in denial of service. For the oldstable distribution (wheezy), these problems have been fixed […]
PCRE could be made to crash or run programs if it processed aspecially-crafted regular expression. ========================================================================== Ubuntu Security Notice USN-2943-1 March 29, 2016 pcre3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: PCRE could be made to crash […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3533-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openvswitch CVE ID : CVE-2016-2074 Kashyap Thimmaraju and Bhargava Shastry discovered a remotely triggerable buffer overflow vulnerability in openvswitch, a production quality, multilayer virtual switch implementation. Specially crafted MPLS packets could overflow the buffer […]
Discovered: March 30, 2016 Updated: March 30, 2016 10:56:21 AM Type: Trojan Infection Length: 32,743 bytes Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Annieco is a Trojan horse that steals information from the compromised computer. Antivirus Protection Dates […]
Trojan.Ransomcrypt.AG is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt them. For more information on ransomware threats, please see the following resource: The dawn of ransomwear: How ransomware could move to wearable devices
Risk Medium Date Discovered August 12, 2008 Description Microsoft Windows Messenger is prone to an information-disclosure vulnerability. An attacker can exploit this issue by enticing an unsuspecting victim to visit a malicious HTML page. Successfully exploiting this issue allows remote attackers to obtain sensitive information that may aid in further attacks. Technologies Affected Microsoft Windows […]
Risk High Date Discovered June 17, 2008 Description Microsoft Word is prone to a remote memory-corruption vulnerability. An attacker could exploit this issue by enticing a victim to open and interact with malicious Word files. Successfully exploiting this issue will corrupt memory and crash the application. Given the nature of this issue, attackers may also […]
