This is a Linux/portable port of OpenBSD’s excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen’s SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.
Monthly Archives: August 2016
TOR Virtual Network Tunneling Tool 0.2.8.6
Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with built-in privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers (ISPs).
Red Hat Security Advisory 2016-1538-01
Red Hat Security Advisory 2016-1538-01 – The golang packages provide the Go programming language compiler. The following packages have been upgraded to a newer upstream version: golang. Security Fix: An input-validation flaw was discovered in the Go programming language built in CGI implementation, which set the environment variable “HTTP_PROXY” using the incoming “Proxy” HTTP-request header. The environment variable “HTTP_PROXY” is used by numerous web clients, including Go’s net/http package, to specify a proxy server to use for HTTP and, in some cases, HTTPS requests. This meant that when a CGI-based web application ran, an attacker could specify a proxy server which the application then used for subsequent outgoing requests, allowing a man-in-the-middle attack.
Red Hat Security Advisory 2016-1539-01
Red Hat Security Advisory 2016-1539-01 – The kernel packages contain the Linux kernel, the core of any Linux operating system. These updated kernel packages include several security issues and numerous bug fixes, some of which you can see below. Space precludes documenting all of these bug fixes in this advisory.
WordPress WangGuard 1.7.1 Cross Site Scripting
WordPress WangGuard plugin version 1.7.1 suffers from a cross site scripting vulnerability.
WordPress Uji Countdown 2.0.6 Cross Site Scripting
WordPress Uji Countdown plugin version 2.0.6 suffers from a cross site scripting vulnerability.
Zoll ePCR 2.6.4 Script Insertion
Zoll ePCR version 2.6.4 suffers from a malicious script insertion vulnerability.
Docebo LMS 6.9 Remote Code Execution
Docebo LMS version 6.9 suffers from a remote code execution vulnerability.
FortiManager Script Insertion
Multiple versions of FortiManager allows for malicious script insertion attacks.
Red Hat Security Advisory 2016-1546-01
Red Hat Security Advisory 2016-1546-01 – The libtiff packages contain a library of functions for manipulating Tagged Image File Format files. Security Fix: Multiple flaws have been discovered in libtiff. A remote attacker could exploit these flaws to cause a crash or memory corruption and, possibly, execute arbitrary code by tricking an application linked against libtiff into processing specially crafted files.