OTR could be made to crash or run programs if it received specially craftednetwork traffic. ========================================================================== Ubuntu Security Notice USN-2926-1 March 10, 2016 libotr vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: OTR could be made to crash or run programs if it received specially […]
In an era when children are becoming digital natives and using and understanding technology from an early age, safety risks that have existed for some time could also, if we fail to take the necessary precautions, now affect them. Minors have also come into the sights of criminals, who have developed into a threat that makes children […]
Discovered: March 11, 2016 Updated: March 11, 2016 1:03:13 PM Type: Trojan Infection Length: varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Pepperat is a Trojan horse that opens a back door and steals information from the compromised […]
Myth: There is no link between your real-life location and your digital one. The truth is that the two are very much connected. Perhaps more importantly, then, is what this means when it comes to your personal security. If the state or city in which you live is a hotbed for cybercriminal activity, your chances of being […]
Markus Vervier of X41 D-Sec GmbH discovered an integer overflow vulnerability in libotr, an off-the-record (OTR) messaging library, in the way how the sizes of portions of incoming messages were stored. A remote attacker can exploit this flaw by sending crafted messages to an application that is using libotr to perform denial of service attacks […]
Two vulnerabilites have been discovered in ISC’s BIND DNS server. CVE-2016-1285 A maliciously crafted rdnc, a way to remotely administer a BIND server, operation can cause named to crash, resulting in denial of service. CVE-2016-1286 An error parsing DNAME resource records can cause named to crash, resulting in denial of service. For the oldstable distribution […]
Multiple security issues have been found in Iceweasel, Debian’s version of the Mozilla Firefox web browser: Multiple memory safety errors, buffer overflows, use-after-frees and other implementation errors may lead to the execution of arbitrary code, denial of service, address bar spoofing and overwriting local files. For the oldstable distribution (wheezy), these problems have been fixed […]
Two vulnerabilities have been discovered in Rails, a web application framework written in Ruby. Both vulnerabilities affect Action Pack, which handles the web requests for Rails. CVE-2016-2097 Crafted requests to Action View, one of the components of Action Pack, might result in rendering files from arbitrary locations, including files beyond the application’s view directory. This […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3513-1 security@debian.org https://www.debian.org/security/ Michael Gilbert March 10, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1643 CVE-2016-1644 CVE-2016-1645 Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1643 cloudfuzzer discovered a type confusion issue in Blink/Webkit. CVE-2016-1644 Atte Kettunen discovered a use-after-free issue in […]
Updated libssh2 packages that fix one security issue are now available for Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: libssh2 security update Advisory ID: RHSA-2016:0428-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0428.html Issue date: […]
Posted by Anthony Pell Updated chromium-browser packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:0429-01 Product: Red Hat Enterprise Linux Supplementary […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Debian: 3513-1: chromium-browser: Summary Red Hat: 2016:0428-01: libssh2: Moderate Advisory Red Hat: 2016:0429-01: chromium-browser: Important Advisory Slackware: 2016-069-02: mozilla-nss: Security Update Slackware: 2016-069-01: bind: Security Update Debian: 3512-1: libotr: Summary […]
Posted by Anthony Pell New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. [More Info…] [slackware-security] bind (SSA:2016-069-01) New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3512-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libotr CVE ID : CVE-2016-2851 Markus Vervier of X41 D-Sec GmbH discovered an integer overflow vulnerability in libotr, an off-the-record (OTR) messaging library, in the way how the sizes of portions of incoming messages […]
Bind could be made to crash if it received specially crafted networktraffic. ========================================================================== Ubuntu Security Notice USN-2925-1 March 09, 2016 bind9 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Bind could be made to crash if it received […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3511-1 security@debian.org https://www.debian.org/security/ Michael Gilbert March 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : bind9 CVE ID : CVE-2016-1285 CVE-2016-1286 Two vulnerabilites have been discovered in ISC’s BIND DNS server. CVE-2016-1285 A maliciously crafted rdnc, a way to remotely administer a BIND server, operation can cause named to […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Debian: 3513-1: chromium-browser: Summary Red Hat: 2016:0428-01: libssh2: Moderate Advisory Red Hat: 2016:0429-01: chromium-browser: Important Advisory Slackware: 2016-069-02: mozilla-nss: Security Update Slackware: 2016-069-01: bind: Security Update Debian: 3512-1: libotr: Summary […]
This is an update to 5.6.29 that delivers also all fixes for CVE-2015-4766,CVE-2015-4791, CVE-2015-4792, CVE-2015-4800, CVE-2015-4802, CVE-2015-4807,CVE-2015-4815, CVE-2015-4819, CVE-2015-4826, CVE-2015-4830, CVE-2015-4833,CVE-2015-4836, CVE-2015-4858, CVE-2015-4861, CVE-2015-4862, CVE-2015-4864,CVE-2015-4866, CVE-2015-4870, CVE-2015-4879, CVE-2015-4890, CVE-2015-4895,CVE-2015-4904, CVE-2015-4905, CVE-2015-4910, CVE-2015-4913, CVE-2015-7744,CVE-2016-0502, CVE-2016-0503, CVE-2016-0504, CVE-2016-0505, CVE-2016-0546,CVE-2016-0594, CVE-2016-0595, CVE-2016-0596, CVE-2016-0597, CVE-2016-0598,CVE-2016-0599, CVE-2016-0600, CVE-2016-0601, CVE-2016-0605, CVE-2016-0606,CVE-2016-0607, CVE-2016-0608, CVE-2016-0609, CVE-2016-0610, CVE-2016-0611,CVE-2016-0616 (some of them were fixed in […]
Fix CVE-2015-7758 (rhbz#1270816, rhbz#1270816) ——————————————————————————– Fedora Update Notification FEDORA-2016-94b0b50351 2016-03-09 20:10:53.639868 ——————————————————————————– Name : gummi Product : Fedora 23 Version : 0.6.6 Release : 1.fc23 URL : http://gummi.midnightcoding.org Summary : A simple LaTeX editor Description : Gummi is a LaTeX editor written in the C programming language using the GTK+ interface toolkit. It was designed […]
https://www.drupal.org/SA-CORE-2016-001 ——————————————————————————– Fedora Update Notification FEDORA-2016-eeb0f0c94f 2016-03-09 20:10:53.638976 ——————————————————————————– Name : drupal7 Product : Fedora 23 Version : 7.43 Release : 1.fc23 URL : http://www.drupal.org Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1643 cloudfuzzer discovered a type confusion issue in Blink/Webkit. CVE-2016-1644 Atte Kettunen discovered a use-after-free issue in Blink/Webkit. CVE-2016-1645 An out-of-bounds write issue was discovered in the pdfium library. For the stable distribution (jessie), these problems have been fixed in version 49.0.2623.87-1~deb8u1. For the testing […]
Discovered: March 10, 2016 Updated: March 10, 2016 4:37:23 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Infostealer.Nemeot is a Trojan horse that steals information from the compromised computer. Antivirus Protection Dates Initial Rapid Release version […]
Posted by Anthony Pell Multiple vulnerabilities have been found in Roundcube allowing remote authenticated users to execute arbitrary code, inject arbitrary web scripts, and perform cross-site scripting (XSS). – – – – – – – – – – – – – – – – – – – – – – – – – – […]
Posted by Anthony Pell Updated nss packages that fix one security issue are now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having Critical security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: nss security update Advisory ID: RHSA-2016:0371-01 Product: Red Hat Enterprise Linux Advisory URL: […]
Posted by Anthony Pell Updated nss-util packages that fix one security issue are now available for Red Hat Enterprise 6 and 7. Red Hat Product Security has rated this update as having Critical security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: nss-util security update Advisory ID: RHSA-2016:0370-01 Product: Red Hat Enterprise Linux Advisory […]
Posted by Anthony Pell Updated rabbitmq-server packages that fix two security issues and one bug are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rabbitmq-server security and bug fix update Advisory ID: RHSA-2016:0369-01 Product: Red Hat Enterprise Linux OpenStack Platform […]
Posted by Anthony Pell Updated rabbitmq-server packages that fix two security issues are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rabbitmq-server security update Advisory ID: RHSA-2016:0368-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0368.html Issue date: 2016-03-08 […]
Posted by Anthony Pell Updated rabbitmq-server packages that fix two security issues are now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rabbitmq-server security and bugfix update Advisory ID: RHSA-2016:0367-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0367.html Issue […]
Posted by Anthony Pell Updated openstack-nova packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openstack-nova security update Advisory ID: RHSA-2016:0365-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0365.html Issue date: 2016-03-08 […]
Posted by Anthony Pell Updated openstack-nova packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openstack-nova security update Advisory ID: RHSA-2016:0366-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0366.html Issue date: 2016-03-08 […]
Posted by Anthony Pell Updated openstack-nova packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openstack-nova security update Advisory ID: RHSA-2016:0363-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0363.html Issue date: 2016-03-08 […]
Posted by Anthony Pell Updated openstack-nova packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openstack-nova security update Advisory ID: RHSA-2016:0364-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0364.html Issue date: 2016-03-08 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Gentoo: 201603-03 Roundcube: Multiple Vulnerabilities Red Hat: 2016:0371-01: nss: Critical Advisory Red Hat: 2016:0370-01: nss-util: Critical Advisory Red Hat: 2016:0369-01: rabbitmq-server: Moderate Advisory Red Hat: 2016:0368-01: rabbitmq-server: Moderate Advisory Red […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Gentoo: 201603-03 Roundcube: Multiple Vulnerabilities Red Hat: 2016:0371-01: nss: Critical Advisory Red Hat: 2016:0370-01: nss-util: Critical Advisory Red Hat: 2016:0369-01: rabbitmq-server: Moderate Advisory Red Hat: 2016:0368-01: rabbitmq-server: Moderate Advisory Red […]
Discovered: March 9, 2016 Updated: March 9, 2016 2:02:32 PM Type: Trojan Systems Affected: Linux Linux.Tsunami is a Trojan horse for Linux computers that may perform malicious activity. Symantec Security Response is currently investigating this threat and will post more information as it becomes available. Antivirus Protection Dates Initial Rapid Release version March 9, 2016 […]
Discovered: March 8, 2016 Updated: March 8, 2016 11:30:37 AM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Downloader.Poshedo is a Trojan horse that downloads malicious files to the compromised computer. Antivirus Protection Dates Initial Rapid Release […]
Seemingly every day, we’re reminded that companies need to work harder to stay secure during a time where cybercrime is rampant and many organizations remain vulnerable to attack. I’ve recently been speaking to the press about what can and should be done to mitigate these risks. I hope the following questions and answers will help shed some […]
Posted by Anthony Pell Several security issues were fixed in Thunderbird. ========================================================================== Ubuntu Security Notice USN-2904-1 March 08, 2016 thunderbird vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in Thunderbird. Software Description: […]
Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 7.0 Operational Tools. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0360-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0360.html Issue date: 2016-03-08 CVE Names: CVE-2015-8213 ===================================================================== 1. Summary: Updated […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2904-1: Thunderbird vulnerabilities Red Hat: 2016:0360-01: python-django: Moderate Advisory Slackware: 2016-067-01: php: Security Update Ubuntu: 2915-3: Django regression Ubuntu: 2921-1: Squid vulnerabilities Ubuntu: 2915-2: Django regression Red Hat: 2016:0359-01: […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2904-1: Thunderbird vulnerabilities Red Hat: 2016:0360-01: python-django: Moderate Advisory Slackware: 2016-067-01: php: Security Update Ubuntu: 2915-3: Django regression Ubuntu: 2921-1: Squid vulnerabilities Ubuntu: 2915-2: Django regression Red Hat: 2016:0359-01: […]
Several security issues were fixed in Squid. ========================================================================== Ubuntu Security Notice USN-2921-1 March 07, 2016 squid3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in Squid. Software Description: – squid3: Web proxy cache […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2904-1: Thunderbird vulnerabilities Red Hat: 2016:0360-01: python-django: Moderate Advisory Slackware: 2016-067-01: php: Security Update Ubuntu: 2915-3: Django regression Ubuntu: 2921-1: Squid vulnerabilities Ubuntu: 2915-2: Django regression Red Hat: 2016:0359-01: […]
Updated chromium-browser packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:0359-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0359.html Issue date: […]
Posted by Anthony Pell Updated openstack-glance packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Low: openstack-glance security update Advisory ID: RHSA-2016:0358-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0358.html Issue date: 2016-03-07 […]
x86: inconsistent cachability flags on guest mappings [XSA-154, CVE-2016-2270](#1309324) VMX: guest user mode may crash guest with non-canonical RIP [XSA-170,CVE-2016-2271] (#1309323) ——————————————————————————– Fedora Update Notification FEDORA-2016-f8121efdac 2016-03-06 19:17:26.629611 ——————————————————————————– Name : xen Product : Fedora 22 Version : 4.5.2 Release : 8.fc22 URL : http://xen.org/ Summary : Xen is a virtual machine monitor Description : […]
Avoid possible XML entity expansion security issue. ——————————————————————————– Fedora Update Notification FEDORA-2016-ff39572e31 2016-03-06 19:17:26.629243 ——————————————————————————– Name : exiv2 Product : Fedora 22 Version : 0.24 Release : 5.fc22 URL : http://www.exiv2.org/ Summary : Exif and Iptc metadata manipulation library Description : A command line utility to access image metadata, allowing one to: * print the […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2904-1: Thunderbird vulnerabilities Red Hat: 2016:0360-01: python-django: Moderate Advisory Slackware: 2016-067-01: php: Security Update Ubuntu: 2915-3: Django regression Ubuntu: 2921-1: Squid vulnerabilities Ubuntu: 2915-2: Django regression Red Hat: 2016:0359-01: […]
GIMP is vulnerable to multiple buffer overflows which could result in the execution of arbitrary code or Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]
Verizon Wireless will pay a $1.35 million fine after the company inserted undeletable ‘supercookies’ into its users’ browsing sessions without consent, reports Reuters. Unlike regular tracking cookies, the so-called supercookies are much harder to delete and can’t be bypassed within private browsing sessions. These cookies can anonymously collect information about users’ web activity, either to be […]
��}��Ʋ�o���0�ND�”��ҮH]i%ۺ�,Ż�ﹶ�5�$vA��riYU��’�J��+�S�’p���DS�9��5��ߞh��Ⱦ�k��M��?l���oLE� �kP�������`�g߿��X�Y�����k̶�5�k�s�|�`Γ� h�1iO��^���g����’ԇs=��kL=�����%�[Svy h��Z�E�������4“��Hr��1[E���k_z������n��>�Gg�=Wn”K�x�Dɿ[$Lӱp�}ˮ/��ӮBG۷�)X��v�u����D�dK}�%�@�> ������3��C���0 ���ޡ_5I��z:�9��^G��E07���5c���*�ac/�o�ߊ���a�0l����@���&ϲ��u9�CG���L]�$�?K�c���g�/�TteW�w�E�q�n�^���J/��5gQ�”�ҙCϱ����70���u^� �b��1y=.�A�����eߜ����f_a�=�W������:M,3t�m��2���fuAl@k�1te���?�>K����_Y=��~�q$��#V��o �
Security isn’t black and white. It isn’t a choice between full security and no security — it’s a continuum with a lot of gray in between. Full security, even if achievable, would “secure” things beyond the realm of reasonable usability. But even then hackers would find a way in. Usable security comes down to a single […]
