Mandriva Linux Security Advisory 2014-236 – An out-of-bounds read flaw was found in file’s donote() function in the way the file utility determined the note headers of a elf file. This could possibly lead to file executable crash.
Monthly Archives: November 2014
Mandriva Linux Security Advisory 2014-233
Mandriva Linux Security Advisory 2014-233 – An updated wordpress package fixes cross site scripting, cross site request forgery, and various other vulnerabilities.
Mandriva Linux Security Advisory 2014-232
Mandriva Linux Security Advisory 2014-232 – The function wordexp() fails to properly handle the WRDE_NOCMD flag when processing arithmetic inputs in the form of $((… “)) where … can be anything valid. The backticks in the arithmetic expression are evaluated by in a shell even if WRDE_NOCMD forbade command substitution. This allows an attacker to attempt to pass dangerous commands via constructs of the above form, and bypass the WRDE_NOCMD flag. This update fixes the issue.
Red Hat Security Advisory 2014-1915-01
Red Hat Security Advisory 2014-1915-01 – The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed in the Adobe Security Bulletin APSB14-26, listed in the References section. A flaw was found in the way flash-plugin displayed certain SWF content. An attacker could use this flaw to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content.
5 Tips for secure browsing on International Computer Security Day
Next Sunday, November 30, is International Computer Security Day. As we do not want you to get caught off guard, we give you 5 tips for secure browsing every day of the year.
5 Tips for secure browsing
Increase the security of your passwords
Passwords are, in most cases, the only barrier between cyber-crooks and your personal data. Increase the security of your passwords for accessing all the online services you use.
And remember: Don’t use the same password for all of your services!
Keep your computer’s operating system updated
Viruses and malware exploit security vulnerabilities in outdated versions. If you want to avoid this, you need the latest security patches.
Windows, for example, simplifies the task with automatic updates so that you don’t have to worry about it.
Do not connect to unknown Wi-Fi networks
It is normal when abroad or when you have used up all of your data to look for open Wi-Fi networks to connect and browse the Internet free of charge. We all do it but that does not mean that it is secure.
Take precautions and follow these tips for connecting to a public Wi-Fi network.
Shop on well known websites with a good reputation
When shopping online, make sure that the URL of the website that appears in the browser address coincides with the website you think you are browsing, and that the address starts with HTTPS. Shopping on trusted websites with a good reputation will prevent you from falling victim to data or identity theft.
In addition, it is important to check that the privacy policy is in a visible place and is up-to-date. Knowing how to return what you buy is another important aspect to consider.
Use the best antivirus
A good antivirus does a whole lot more than keep your computer virus-free. It protects your identify, your business and also neutralizes online fraud attempts when shopping online.
Do you know which one best suits your needs? Panda has the best antivirus for you.
The post 5 Tips for secure browsing on International Computer Security Day appeared first on MediaCenter Panda Security.
Agafi-ROP x86 ROP-Chainer Tool
Agafi-ROP is a x86 ROP-Chainer tool oriented to build ROP chains for win32 programs, modules, and running processes.
Microsoft IIS 7.5 Cross Site Scripting
Microsoft IIS version 7.5 suffers from an error message cross site scripting vulnerability.
D-Link DAP-1360 Cross Site Scripting / Cross Site Request Forgery
The D-Link DAP-1360 suffers from cross site request forgery and cross site scripting vulnerabilities.
Get your small business noticed this Saturday
Black Friday and Cyber Monday still get the bulk of holiday shopping attention, but letâs not forget Small Business Saturday â which celebrates and encourages shopping at small businesses that are so vital to our economy.
Since Small Business Saturdayâs founding by American Express in 2010, the event to promote small businesses has spread globally and has seen its awareness grow. According to a joint Amex and National Federation of Independent Business (NFIB) survey conducted in December, 2013, awareness by U.S. consumers of the Small Business Saturday jumped to 71%. The survey also found 46% of consumers planned to shop Small Business Saturday and reported spending $5.7 billion with Indy merchants, up from $5.5 billion the previous year.
Itâs delightful to go the AMEX site and see the literally thousands of participating small businesses. Businesses can participate in this event by becoming a part of the American Express Shop Small movement.
For their part, customers can register to get up to $30 back when they Shop Small by spending $10 or more at participating businesses.
One of the main ways a small business owners can enhance their business prospects is to invite customers to participate and shop at their business. We all know promotion can be a daunting task for owners who donât know where to start. Small Business Saturday provides a great, easy entrée â creating free marketing materials, including digital banners, signage, events and more, making them available. More than 346,000 free online tools and materials were accessed by small business owners last year according to the NFIB/Amex survey.
Amex also has lined up major partners like Facebook, Verizon and AARP to help promote awareness, participation and shopping.
Here are few social/tech tips for small businesses for Small Business Saturday this holiday season and beyond:
- Use and look for the hashtags! Last year organizers reported more than 300,000 Tweets went out in support of #SmallBizSat , #ShopSmall, #DineSmall. Thatâs a lot of opportunity for you to be seen.
- Leverage the official social sites like the Facebook Small Business Saturday But also take advantage of the trend and ask your best customers to add a Facebook page for your business or to Yelp you.
- Be visual. Beautifully displayed merchandise, features of satisfied real customers modeling your wares (with the ownerâs permission, of course!) posted on Instagram and Pinterest can be great for enticing new customers. As they say, a photo is worth, what, a billion words now?
- Embrace the power of video. Share your businessâ unique story and why your products and specials are special this holidayâ¦
- Finally, with all the worrisome security breaches in the news, give yourself a gift as a small business owner, and do an IT Security Health Check to make sure you are prepared for the holidays â and everyday â to keep your business information and your customers safe.
I know I will #ShopSmall local businesses this Saturday and throughout the holiday â and be looking on #DiningSmall. Itâs so great to see a friendly face that knows exactly what you want!
Bugtraq: [ MDVSA-2014:232 ] glibc
[ MDVSA-2014:232 ] glibc