Debian Linux Security Advisory 3709-1 – Nick Wellnhofer discovered that the xsltFormatNumberConversion function in libxslt, an XSLT processing runtime library, does not properly check for a zero byte terminating the pattern string. This flaw can be exploited to leak a couple of bytes after the buffer that holds the pattern string.
Monthly Archives: November 2016
Ubuntu Security Notice USN-3125-1
Ubuntu Security Notice 3125-1 – Zhenhao Hong discovered that QEMU incorrectly handled the Virtio module. A privileged attacker inside the guest could use this issue to cause QEMU to consume resources, resulting in a denial of service. Li Qiang discovered that QEMU incorrectly handled VMWARE VMXNET3 network card emulation support. A privileged attacker inside the guest could use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. Various other issues were also addressed.
Red Hat Security Advisory 2016-2694-01
Red Hat Security Advisory 2016-2694-01 – The systemd packages contain systemd, a system and service manager for Linux, compatible with the SysV and LSB init scripts. It provides aggressive parallelism capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, and keeps track of processes using Linux cgroups.
Red Hat Security Advisory 2016-2695-01
Red Hat Security Advisory 2016-2695-01 – The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix: It was found that the Linux kernel’s IPv6 implementation mishandled socket options. A local attacker could abuse concurrent access to the socket options to escalate their privileges, or cause a denial of service via a crafted sendmsg system call.
HP Security Bulletin HPSBGN03670 1
HP Security Bulletin HPSBGN03670 1 – A vulnerability in the Apache Commons Collections library for handling Java object deserialization was addressed by HPE Business Service Management (BSM). The vulnerability could be exploited remotely to allow remote code execution. Revision 1 of this advisory.
Here's How President Trump Could Destroy Net Neutrality
Yahoo Admits Some Employees Knew Of Hack In 2014
Russian Banks Hit By Cyber Attack
What Went Wrong At Tesco Bank?
Facebook Buys Leaked Passwords From Black Market, But Do You Know Why?
Facebook is reportedly buying stolen passwords that hackers are selling on the underground black market in an effort to keep its users’ accounts safe.
On the one hand, we just came know that Yahoo did not inform its users of the recently disclosed major 2014 hacking incident that exposed half a billion user accounts even after being aware of the hack in 2014.
On the other hand, Facebook
![]()
