OpenSSL Padding Oracle Incomplete Fix Information Disclosure Vulnerability
Monthly Archives: July 2016
Vuln: cURL/libcURL NTLM Connection CVE-2016-0755 Remote Security Bypass Vulnerability
cURL/libcURL NTLM Connection CVE-2016-0755 Remote Security Bypass Vulnerability
Vuln: OpenSSL CVE-2015-3195 Information Disclosure Vulnerability
OpenSSL CVE-2015-3195 Information Disclosure Vulnerability
WordPress All In One SEO Pack 2.3.6.1 Cross Site Scripting
WordPress All In One SEO Pack plugin version 2.3.6.1 suffers from a persistent cross site scripting vulnerability.
CESA-2016:1392 Important CentOS 5 thunderbirdSecurity Update
CentOS Errata and Security Advisory 2016:1392 Important Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-1392.html The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) i386: 3ba2329533bfe42576f424632f1db5cd816e3c768f895cd7ac1955944ef33f8d thunderbird-45.2-1.el5.centos.i386.rpm x86_64: 1f3ebde7fd1829758faed41e807423c3b926a87aceaab8060be8b59c90b8c2bb thunderbird-45.2-1.el5.centos.x86_64.rpm Source: 22f6e1b779c81c7a2e2670ef9b70b7df9ed25ed91bb4d23e7ee835c8b2f3cff5 thunderbird-45.2-1.el5.centos.src.rpm
Ubuntu Security Notice USN-3028-1
Ubuntu Security Notice 3028-1 – It was discovered that NSPR incorrectly handled memory allocation. A remote attacker could use this issue to cause NSPR to crash, resulting in a denial of service, or possibly execute arbitrary code.
Ubuntu Security Notice USN-3030-1
Ubuntu Security Notice 3030-1 – It was discovered that the GD library incorrectly handled memory when using gdImageScaleTwoPass(). A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS. It was discovered that the GD library incorrectly handled certain malformed XBM images. If a user or automated system were tricked into processing a specially crafted XBM image, an attacker could cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 15.10 and Ubuntu 16.04 LTS. Various other issues were also addressed.
Ubuntu Security Notice USN-3029-1
Ubuntu Security Notice 3029-1 – Tyson Smith and Jed Davis discovered that NSS incorrectly handled memory. A remote attacker could use this issue to cause NSS to crash, resulting in a denial of service, or possibly execute arbitrary code. This update refreshes the NSS package to version 3.23 which includes the latest CA certificate bundle. As a security improvement, this update also modifies NSS behaviour to reject DH key sizes below 1024 bits, preventing a possible downgrade attack. Various other issues were also addressed.
Red Hat Security Advisory 2016-1392-01
Red Hat Security Advisory 2016-1392-01 – Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 45.2.0. Security Fix: Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird.
CESA-2016:1392 Important CentOS 7 thunderbirdSecurity Update
CentOS Errata and Security Advisory 2016:1392 Important Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-1392.html The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: c86b3d368508a59cd16d64e04a1bc193d775c7fbd451fc13d7a7c2f7c1a23043 thunderbird-45.2-1.el7.centos.x86_64.rpm Source: 0afe6ca8e844277a55e85ad18c97c5bc1f3554c517181d4711904ac434947f08 thunderbird-45.2-1.el7.centos.src.rpm