RHSA-2015:0695-1: Important: kernel security and bug fix update

Red Hat Enterprise Linux: Updated kernel packages that fix multiple security issues and two bugs are
now available for Red Hat Enterprise Linux 6.2 Advanced Update Support.

Red Hat Product Security has rated this update as having Important security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2013-2596, CVE-2014-5471, CVE-2014-5472, CVE-2014-7841, CVE-2014-8159

RHSA-2015:0694-1: Important: kernel-rt security, bug fix, and enhancement update

Red Hat Enterprise Linux: Updated kernel-rt packages that fix multiple security issues, several bugs,
and add various enhancements are now available for Red Hat Enterprise MRG
2.5.

Red Hat Product Security has rated this update as having Important security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2014-7822, CVE-2014-8086, CVE-2014-8172, CVE-2014-8173, CVE-2015-0274

USB Killer reminds us what untrusted really means

If this “USB Killer” invention is real, then plugging in one of these unknown devices could electrocute your defenseless PC or Mac, and damage it beyond repair.

It’s a far cry from today’s worst-case-scenario of getting infected by malware and it’s a timely reminder to anybody who stumbles across a USB device by chance – you’ll want to think twice before plugging it in.

Indeed the natural curiosity of what happens when someone finds a USB stick in a public place is well documented, and as far back as 2010 it even spawned the concept of the USB dead drop.

This latest news adds to a growing concern around the security of all USB devices.  Last year researchers Karsten Nohl and Jacob Lell revealed a number of attacks known as BadUSB that has since uncovered a swathe of problems where malware could be transferred at a hardware layer with very little ability to protect against this type of threat.

But we have previously warned about the dangers of anything ‘untrusted’ – be it software, apps and hardware devices.  Your security these days relies more on trust than ever before, as outlined recently by our CEO Gary Kovacs in his keynote speech at Mobile World Congress.

 

What to do if you find an unknown USB device?

NEVER connect it to your PC or Mac. At best it will contain Malware, or at worst it may be a USB Killer (although unlikely).

Try to return it to its owner. Ask around or check if it has a label on it; or leave it where you found it, in case the owner returns to find it.

Consider destroying the USB device. Remember, if the device isn’t yours – neither is the data that it might contain.

Until next time, stay safe out there.

USN-2534-1: Libav vulnerabilities

Ubuntu Security Notice USN-2534-1

17th March, 2015

libav vulnerabilities

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 12.04 LTS

Summary

Libav could be made to crash or run programs as your login if it opened a
specially crafted file.

Software description

  • libav
    – Multimedia player, server, encoder and transcoder

Details

It was discovered that Libav incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 12.04 LTS:
libavformat53

4:0.8.17-0ubuntu0.12.04.1
libavcodec53

4:0.8.17-0ubuntu0.12.04.1

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References

CVE-2014-8542,

CVE-2014-8543,

CVE-2014-8544,

CVE-2014-8547,

CVE-2014-8548,

CVE-2014-9604

CEBA-2015:0693 CentOS 6 nss-pam-ldapd BugFixUpdate

CentOS Errata and Bugfix Advisory 2015:0693 

Upstream details at : https://rhn.redhat.com/errata/RHBA-2015-0693.html

The following updated files have been uploaded and are currently 
syncing to the mirrors: ( sha256sum Filename ) 

i386:
b99fc32c9b3a57f6a69619106d9a370c3d6daf513486cd54c18c3f08a694bf9d  nss-pam-ldapd-0.7.5-20.el6_6.3.i686.rpm

x86_64:
b99fc32c9b3a57f6a69619106d9a370c3d6daf513486cd54c18c3f08a694bf9d  nss-pam-ldapd-0.7.5-20.el6_6.3.i686.rpm
a3daa6a5ead529f1a7d16587221c867744ab4aa98af4c3a8481e2c84ceb40e0b  nss-pam-ldapd-0.7.5-20.el6_6.3.x86_64.rpm

Source:
5c9df72e2e04576e524af77814e8d51c6d19048a180928af65989280192fc02b  nss-pam-ldapd-0.7.5-20.el6_6.3.src.rpm



CEBA-2015:0692 CentOS 6 polkit FASTTRACK BugFixUpdate

CentOS Errata and Bugfix Advisory 2015:0692 

Upstream details at : https://rhn.redhat.com/errata/RHBA-2015-0692.html

The following updated files have been uploaded and are currently 
syncing to the mirrors: ( sha256sum Filename ) 

i386:
336eac9304d6754d3eab23c0c45796b89f4faa9dd69a15a83af130f15774af03  polkit-0.96-11.el6.i686.rpm
9e8a75d35acdb9b094ece75726a80d5b2a229d8641e5e1cdbf2ebba2aec9b512  polkit-desktop-policy-0.96-11.el6.noarch.rpm
fc4a101e5bc3ec1abf48632056e174700edf2a414f211a1b004f6205402275ca  polkit-devel-0.96-11.el6.i686.rpm
bade5d0398bb811d72083675327cabe93bbbc6e7f129c5b19d1758fc490ccf3d  polkit-docs-0.96-11.el6.i686.rpm

x86_64:
336eac9304d6754d3eab23c0c45796b89f4faa9dd69a15a83af130f15774af03  polkit-0.96-11.el6.i686.rpm
7fb2dc10f3ef3c15475def54c23c02c00d66acd39a89e860b1778512dc9bbd5c  polkit-0.96-11.el6.x86_64.rpm
9e8a75d35acdb9b094ece75726a80d5b2a229d8641e5e1cdbf2ebba2aec9b512  polkit-desktop-policy-0.96-11.el6.noarch.rpm
fc4a101e5bc3ec1abf48632056e174700edf2a414f211a1b004f6205402275ca  polkit-devel-0.96-11.el6.i686.rpm
75fe736d353c8919ea1b2666b6af57be4c0be6451daf003d7c379bdb9ee626fe  polkit-devel-0.96-11.el6.x86_64.rpm
04399b48f60eeecebf7b76a41b050bce52b9b41cd9bfd7cfd525ec358280c35a  polkit-docs-0.96-11.el6.x86_64.rpm

Source:
bca9435e496073ac382fa9f745d750dd23fc88c52852c50f487fb1b8d95f60f3  polkit-0.96-11.el6.src.rpm