RHSA-2016:0502-1: Moderate: python-django security update

Red Hat Enterprise Linux: An update for python-django is now available for Red Hat Enterprise Linux
OpenStack Platform 5.0 (Icehouse) for RHEL 6.

Red Hat Product Security has rated this update as having a security impact of
Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a
detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.
CVE-2016-2512, CVE-2016-2513

USN-2939-1: LibTIFF vulnerabilities

Ubuntu Security Notice USN-2939-1

23rd March, 2016

tiff vulnerabilities

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 15.10
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

LibTIFF could be made to crash or run programs as your login if it opened a
specially crafted file.

Software description

  • tiff
    – Tag Image File Format (TIFF) library

Details

It was discovered that LibTIFF incorrectly handled certain malformed
images. If a user or automated system were tricked into opening a specially
crafted image, a remote attacker could crash the application, leading to a
denial of service, or possibly execute arbitrary code with user privileges.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 15.10:
libtiff5

4.0.3-12.3ubuntu2.1
Ubuntu 14.04 LTS:
libtiff5

4.0.3-7ubuntu0.4
Ubuntu 12.04 LTS:
libtiff4

3.9.5-2ubuntu1.9

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

CVE-2015-8665,

CVE-2015-8683,

CVE-2015-8781,

CVE-2015-8782,

CVE-2015-8783,

CVE-2015-8784

USN-2941-1: Quagga vulnerabilities

Ubuntu Security Notice USN-2941-1

24th March, 2016

quagga vulnerabilities

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 15.10
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

Quagga could be made to crash or run programs if it received specially
crafted network traffic.

Software description

  • quagga
    – BGP/OSPF/RIP routing daemon

Details

Kostya Kortchinsky discovered that Quagga incorrectly handled certain route
data when configured with BGP peers enabled for VPNv4. A remote attacker
could use this issue to cause Quagga to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2016-2342)

It was discovered that Quagga incorrectly handled messages with a large
LSA when used in certain configurations. A remote attacker could use this
issue to cause Quagga to crash, resulting in a denial of service. This
issue only affected Ubuntu 12.04 LTS. (CVE-2013-2236)

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 15.10:
quagga

0.99.24.1-2ubuntu0.1
Ubuntu 14.04 LTS:
quagga

0.99.22.4-3ubuntu1.1
Ubuntu 12.04 LTS:
quagga

0.99.20.1-0ubuntu0.12.04.4

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart Quagga to make all the
necessary changes.

References

CVE-2013-2236,

CVE-2016-2342

What is SMTP STS? How It improves Email Security for StartTLS?

Despite so many messaging apps, Email is still one of the widely used and popular ways to communicate in this digital age.

But are your Emails secure?

We are using email services for decades, but the underlying 1980s transport protocol used to send emails, Simple Mail Transfer Protocol (SMTP), is ancient and lacks the ability to secure your email communication entirely.

However, to

Fake mobile antivirus apps promise rainbows and safety forever

fakeAVads4.pngAnnoying popups advertising fake antivirus apps appear in mobile browsers.

Those evil popups. We all know them, we all see them every day on our PCs while we are reading news, watching videos, or just generally – clicking. As tempting as they might sound, let me assure you that you’re not a 1000000th visitor and you certainly just didn’t win a lottery. Also no magic diet pills for you. Popups are not your friend. Close them, block them, and never trust them.

Ubuntu Security Notice USN-2941-1

Ubuntu Security Notice 2941-1 – Kostya Kortchinsky discovered that Quagga incorrectly handled certain route data when configured with BGP peers enabled for VPNv4. A remote attacker could use this issue to cause Quagga to crash, resulting in a denial of service, or possibly execute arbitrary code. It was discovered that Quagga incorrectly handled messages with a large LSA when used in certain configurations. A remote attacker could use this issue to cause Quagga to crash, resulting in a denial of service. This issue only affected Ubuntu 12.04 LTS. Various other issues were also addressed.

Red Hat Security Advisory 2016-0506-01

Red Hat Security Advisory 2016-0506-01 – Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY principle. Security Fix: An open-redirect flaw was found in the way Django’s django.utils.http.is_safe_url() function filtered authentication URLs. An attacker able to trick a victim into visiting a crafted URL could use this flaw to redirect that victim to a malicious site.

Red Hat Security Advisory 2016-0503-01

Red Hat Security Advisory 2016-0503-01 – Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY principle. Security Fix: An open-redirect flaw was found in the way Django’s django.utils.http.is_safe_url() function filtered authentication URLs. An attacker able to trick a victim into visiting a crafted URL could use this flaw to redirect that victim to a malicious site.