New file-sharing protocols and interfaces called Upspin have been released to open source. Built by Google, Upspin returns access control and data security to the user.
Tag Archives: Open Source Security
Critical Vulnerability Patched in Roundcube Webmail
Open source webmail provider Roundcube was patched against a vulnerability that could be trivially exploited to run code on servers or access email accounts.
Critical glibc Vulnerability Puts All Linux Machines at Risk
A critical vulnerability in glibc, the GNU C library, affects all Linux machines and many web frameworks, opening the door to remote code execution.
Socat Warns Weak Prime Number Could Mean It’s Backdoored
Socat published a security advisory warning users that a hard-coded 1024 Diffie-Hellman prime number was not prime, and that an attacker could listen and recover secrets from a key exchange.
FreeBSD Patches Kernel Panic Vulnerability
FreeBSD has patched a kernel panic vulnerability is versions compiled to support IPv6 and SCTP.
Serious Linux Kernel Vulnerability Patched
The Linux security team today patched a critical privilege escalation vulnerability in the Linux kernel discovered by startup Perception Point.
Patched Libpng Vulnerabilities Have Limited Scope
Most applications, including Firefox, are not vulnerable to a pair of memory corruption vulnerabilities patched in the libpng PNG reference library.
Details Surface on Patched Bugzilla Privilege Escalation Flaw
Bugzilla users should upgrade to current versions after a privilege escalation vulnerability was reported and patched.
Netflix Sleepy Puppy Awakens XSS Vulnerabilities in Secondary Applications
Netflix released Sleepy Puppy, a cross-site scripting payload management framework, to open source. The tool finds XSS vulnerabilities in secondary applications.
Core Infrastructure Initiative Launches Open Source Security Badge Program
The Core Infrastructure Initiative, which has funded OpenSSL among other open source security projects, announced a badge program that evaluates secure development best practices.