The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.
Monthly Archives: December 2016
Gentoo Linux Security Advisory 201612-37
Gentoo Linux Security Advisory 201612-37 – A buffer overflow in Pixman might allow remote attackers to execute arbitrary code. Versions less than 0.32.8 are affected.
Gentoo Linux Security Advisory 201612-39
Gentoo Linux Security Advisory 201612-39 – A vulnerability in Bash could potentially lead to arbitrary code execution. Versions less than 4.3_p46-r1 are affected.
Gentoo Linux Security Advisory 201612-40
Gentoo Linux Security Advisory 201612-40 – Multiple vulnerabilities have been found in SQUASHFS, the worst of which may allow execution of arbitrary code. Versions less than 4.3 are affected.
Gentoo Linux Security Advisory 201612-38
Gentoo Linux Security Advisory 201612-38 – Multiple vulnerabilities have been found in Botan, the worst of which allows remote attackers to execute arbitrary code. Versions less than 1.10.12 are affected.
Gentoo Linux Security Advisory 201612-34
Gentoo Linux Security Advisory 201612-34 – Multiple vulnerabilities have been found in systemd, the worst of which may allow execution of arbitrary code. Versions less than 208 are affected.
Gentoo Linux Security Advisory 201612-35
Gentoo Linux Security Advisory 201612-35 – A vulnerability in XStream may allow remote attackers to execute arbitrary code. Versions less than 1.4.8-r1 are affected.
Gentoo Linux Security Advisory 201612-36
Gentoo Linux Security Advisory 201612-36 – An integer overflow in TigerVNC might allow remote attackers to execute arbitrary code. Versions less than 1.4.2 are affected.
Gentoo Linux Security Advisory 201612-43
Gentoo Linux Security Advisory 201612-43 – Multiple vulnerabilities have been found in Node.js, the worst of which can allow remote attackers to cause Denial of Service conditions. Versions less than 4.6.1 are affected.
Gentoo Linux Security Advisory 201612-33
Gentoo Linux Security Advisory 201612-33 – An integer overflow in GPL Ghostscript may allow remote attackers to execute arbitrary code. Versions prior to 9.09 are affected.