Red Hat Enterprise Linux: Updated nss, nss-util, and nspr packages that fix three security issues are
now available for Red Hat Enterprise Linux 6.2 and 6.4 Advanced Update
Support, and Red Hat Enterprise Linux 6.5 and 6.6 Extended Update Support.
Red Hat Product Security has rated this update as having Critical security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2015-7181, CVE-2015-7182, CVE-2015-7183
A security issue affects these releases of Ubuntu and its
derivatives:
Ubuntu 15.10
Ubuntu 15.04
Summary
Several security issues were fixed in LXCFS.
Software description
lxcfs
– FUSE based filesystem for LXC
Details
It was discovered that LXCFS incorrectly enforced directory escapes. A local attacker could use this issue to possibly escalate privileges. (CVE-2015-1342)
It was discovered that LXCFS incorrectly checked certain permissions. A local attacker could use this issue t possibly escalate privileges. (CVE-2015-1344)
Update instructions
The problem can be corrected by updating your system to the following
package version:
Cross-site request forgery (CSRF) vulnerability in Cisco Prime Collaboration Assurance 10.5(1) and 10.6 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus62712.
The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide an invalid package, and consequently execute arbitrary code, via a crafted certificate, aka Bug ID CSCuw06444.
The default configuration of EMC VPLEX GeoSynchrony 5.4 SP1 before P3 stores cleartext NAVISPHERE GUI passwords in a log file, which allows local users to obtain sensitive information by reading this file.
Instagram’s new API policy makes it a lot harder for third party apps to gain access to its feed. News of this comes on the back of a malicious app harvesting its user’s details.
British chancellor George Osborne has warned about the spectre of online terrorists attacking national infrastructure, and made some rather bold pronouncements about the UK’s willingness to engage in cyberwarfare to defend itself.
Ubuntu Security Notice 2813-1 – It was discovered that LXCFS incorrectly enforced directory escapes. A local attacker could use this issue to possibly escalate privileges. It was discovered that LXCFS incorrectly checked certain permissions. A local attacker could use this issue t possibly escalate privileges.