Monthly Archives: January 2017
Trump's Cyber-Guru Giuliani Runs Pathetically Insecure Website
Guccifer 2.0 Persona Resurfaces After Months Of Silence
Bug Exposes WhatsApp Message Secrets
fedmsg-0.18.2-1.el7
Fix validation logic in the base consumer
The base consumer is intended to only derive its validation switch from the
on-disk configuration if the child class doesn’t override the
validate_signatures switch.
There was a bug here where the default value provided in the base class made it
appear as if *all* child consumers had turned *off* validation, which is
incorrect.
This fix turns on signature validation by default while preserving the ability
of child consumers to override the on-disk configuration in special cases.
– Fixes: CVE-2017-1000001
– Reviewed-by: Patrick Uiterwijk
fedmsg-0.18.2-1.fc25
Fix validation logic in the base consumer
The base consumer is intended to only derive its validation switch from the
on-disk configuration if the child class doesn’t override the
validate_signatures switch.
There was a bug here where the default value provided in the base class made it
appear as if *all* child consumers had turned *off* validation, which is
incorrect.
This fix turns on signature validation by default while preserving the ability
of child consumers to override the on-disk configuration in special cases.
– Fixes: CVE-2017-1000001
– Reviewed-by: Patrick Uiterwijk
fedmsg-0.18.2-1.fc24
Fix validation logic in the base consumer
The base consumer is intended to only derive its validation switch from the
on-disk configuration if the child class doesn’t override the
validate_signatures switch.
There was a bug here where the default value provided in the base class made it
appear as if *all* child consumers had turned *off* validation, which is
incorrect.
This fix turns on signature validation by default while preserving the ability
of child consumers to override the on-disk configuration in special cases.
– Fixes: CVE-2017-1000001
– Reviewed-by: Patrick Uiterwijk
WhatsApp bug: Messages ‘can be intercepted and read’
A WhatsApp ‘security issue’ has been identified, meaning third parties may be able to both intercept and read encrypted messages, according to new research.
The post WhatsApp bug: Messages ‘can be intercepted and read’ appeared first on WeLiveSecurity
![]()
Threatpost News Wrap, January 13, 2017
The news of the week is discussed, including the ShadowBrokers’ farewell, GoDaddy’s buggy domain validation issue, MongoDB ransoms, and the latest with St. Jude Medical.
Forensic analysis techniques for digital imaging
ESET’s Miguel Ángel Mendoza looks at a range of forensic analysis techniques that are used to examine digital images.
The post Forensic analysis techniques for digital imaging appeared first on WeLiveSecurity
![]()