1. Vulnerabilities in IBM Notes and Domino
(1963812)
[14/08/2015]
Vulnerabilities were identified in the IBM Notes
and Domino. An attacker could gain access to the system and obtain sensitive
information. These vulnerabilities affect multiple versions of the mentioned
products. Security patches are available to resolve these
vulnerabilities.
URL:www-01.ibm.com/support/docview.wss?uid=swg21963812
2. Vulnerabilities in Apple Products (HT205030, HT205031,
HT205032, HT205033)
[14/08/2015] Vulnerabilities were identified in the Apple iOS, OS X and
Safari. An attacker could bypass security restrictions, execute arbitrary code,
obtain sensitive information and cause a denial of service condition. These
vulnerabilities affect multiple versions of the mentioned products. Security
patches are available to resolve these
vulnerabilities.
URL:support.apple.com/en-hk/HT205030
URL:support.apple.com/en-hk/HT205031
URL:support.apple.com/en-hk/HT205032
URL:support.apple.com/en-hk/HT205033
3. Vulnerabilities in Rockwell Automation devices
(ICS-ALERT-15-225-01, ICS-ALERT-15-225-02)
[14/08/2015] Vulnerabilities were identified in the Rockwell Automation
devices web interface. An attacker could perform cross-site scripting attacks,
execute arbitrary code and cause a denial of service condition. These
vulnerabilities affect 1769-L18ER, A LOGIX5318ER, 1766-L32BWAA, 1766-L32BXBA
models of the mentioned
products.
URL:ics-cert.us-cert.gov/alerts/ICS-ALERT-15-225-01
URL:ics-cert.us-cert.gov/alerts/ICS-ALERT-15-225-02
4. Vulnerability in KAKO HMI Products
(ICS-ALERT-15-224-01)
[14/08/2015] Vulnerability was identified in the KAKO HMI products. An
attacker could execute arbitrary code and take control of the products. The
affected versions were not
specified.
URL:ics-cert.us-cert.gov/alerts/ICS-ALERT-15-224-01
5. Vulnerabilities in Schneider Electric Products
(ICS-ALERT-15-224-02)
[14/08/2015] Vulnerabilities were identified in several Schneider
Electric's Modicon M340 PLC Station P34 CPU modules. An attacker could execute
arbitrary code, perform directory traversal attacks and cause a denial of
service condition. The affected versions were not
specified.
URL:ics-cert.us-cert.gov/alerts/ICS-ALERT-15-224-02
6. Vulnerabilities in Prisma web products
(ICS-ALERT-15-224-03)
[14/08/2015] Vulnerabilities were identified in the Prisma web products.
An attacker could change configuration and execute arbitrary code. The affected
versions were not
specified.
URL:ics-cert.us-cert.gov/alerts/ICS-ALERT-15-224-03
7. Vulnerabilities in Moxa ioLogik E2210
(ICS-ALERT-15-224-04)
[14/08/2015] Vulnerabilities were identified in the Ethernet Micro RTU
controller of the Moxa ioLogik E2210. An attacker could obtain unauthorised
access. The affected versions were not
specified.
URL:ics-cert.us-cert.gov/alerts/ICS-ALERT-15-224-04
8. Vulnerabilities in Google
Andriod
[14/08/2015]
Vulnerabilities were identified in the messaging
app of the Google Andriod. An attacker could crash the application and
manipulate SMS/MMS data. These vulnerabilities affect multiple versions of the
mentioned
product.
URL:www.hkcert.org/my_url/en/alert/15081301
9. Security Updates in Debian
(DSA-3335-1)
[14/08/2015] Debian has
released security update packages for fixing the vulnerability identified in the
request-tracker4 package for multiple versions of Debian GNU/Linux. An attacker
could perform cross-site scripting
attacks.
URL:www.debian.org/security/2015/dsa-3335
10.
Security Updates in SUSE
(SUSE-SU-2015:1379-1, SUSE-SU-2015:1380-1)
[14/08/2015] SUSE has
released security update packages for fixing the vulnerabilities identified in
the MozillaFirefox package of SUSE Linux Enterprise 11 and 12. Due to multiple
errors, an attacker could bypass security restrictions and gain elevated
privileges.
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00009.html
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00010.html
11.
Vulnerability in Mozilla Firefox (MFSA
2015-93)
[13/08/2015]
Vulnerability was identified in the Mozilla
Firefox. An attacker could gain crash the system. This vulnerability affects
versions prior to 38 of the mentioned product. Security patches are available to
resolve this
vulnerability.
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-93/
12.
Vulnerability in Lenovo Service Engine
BIOS (LEN-2015-020, LEN-2015-077)
[13/08/2015] Vulnerability was identified in the Lenovo Service Engine
BIOS. An attacker could take control of an affected system. This vulnerability
affects multiple models of Lenovo notebooks and desktops. Security patches are
available to resolve this
vulnerability.
URL:support.lenovo.com/us/en/product_security/lse_bios_notebook
URL:support.lenovo.com/us/en/product_security/lse_bios_desktop
URL:www.us-cert.gov/ncas/current-activity/2015/08/12/Lenovo-Service-Engine-LSE-BIOS-Vulnerability
13.
Vulnerability in GnuTLS
(GNUTLS-SA-2015-3)
[13/08/2015] Vulnerability was identified in the GnuTLS. An attacker could
crash the application. This vulnerability affects versions prior to 3.3.17 and
3.4.4 of the mentioned product. Security patches are available to resolve this
vulnerability.
URL:www.gnutls.org/security.html#GNUTLS-SA-2015-3
URL:www.hkcert.org/my_url/en/alert/15081217
14.
Security Updates in Red Hat Enterprise
Linux (RHSA-2015:1603-1)
[13/08/2015] Red Hat
has released security update packages for fixing the vulnerabilities identified
in the Adobe Flash Player package for Red Hat Enterprise Linux 5 and 6. Due to
multiple errors, an attacker could crash the system and execute arbitrary
code.
URL:rhn.redhat.com/errata/RHSA-2015-1603.html
15.
Security Updates in SUSE
(SUSE-SU-2015:1373-1, SUSE-SU-2015:1374-1, SUSE-SU-2015:1375-1,
SUSE-SU-2015:1376-1)
[13/08/2015] SUSE has
released security update packages for fixing the vulnerabilities identified in
the flash-player, java-1_7_0-ibm and Real Time Linux Kernel packages of SUSE
Linux Enterprise 11 and 12. Due to multiple errors, an attacker could bypass
security restrictions, gain elevated privileges, cause a denial of service
condition, execute arbitrary code and obtain sensitive
information.
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00004.html
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00005.html
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00006.html
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00007.html
16.
Security Updates in Debian (DSA-3328-1,
DSA-3330-1, DSA-3331-1, DSA-3332-1, DSA-3333-1,
DSA-3334-1)
[13/08/2015] Debian has
released security update packages for fixing the vulnerability identified in the
wordpress, activemq, subversion, iceweasel and gnutls28 packages for multiple
versions of Debian GNU/Linux. Due to multiple errors, an attacker could perform
cross-site scripting attacks, gain elevated privileges, cause a denial of
service condition, perform code injection attacks, obtain sensitive information,
execute arbitrary code and crash the
application.
URL:www.debian.org/security/2015/dsa-3328
URL:www.debian.org/security/2015/dsa-3330
URL:www.debian.org/security/2015/dsa-3331
URL:www.debian.org/security/2015/dsa-3332
URL:www.debian.org/security/2015/dsa-3333
URL:www.debian.org/security/2015/dsa-3334
17.
Vulnerabilities in Microsoft Products
(MS15-079, MS15-080, MS15-081, MS15-082, MS15-083, MS15-084, MS15-085, MS15-086,
MS15-087, MS15-088, MS15-089, MS15-090, MS15-091,
MS15-092)
[12/08/2015]
Vulnerabilities were identified in the Microsoft
Windows, Microsoft Internet Explorer, Microsoft .NET Framework, Microsoft
Office, Microsoft Lync, Microsoft Silverlight, Microsoft Server Software and
Microsoft Edge. An attacker could perform remote code execution, gain elevated
privileges and obtain sensitive information. These vulnerabilities affect
multiple versions of the mentioned products. Security patches are available to
resolve these
vulnerabilities.
URL:technet.microsoft.com/en-us/library/security/ms15-aug.aspx
URL:technet.microsoft.com/library/security/MS15-079
URL:technet.microsoft.com/library/security/MS15-080
URL:technet.microsoft.com/library/security/MS15-081
URL:technet.microsoft.com/library/security/MS15-082
URL:technet.microsoft.com/library/security/MS15-083
URL:technet.microsoft.com/library/security/MS15-084
URL:technet.microsoft.com/library/security/MS15-085
URL:technet.microsoft.com/library/security/MS15-086
URL:technet.microsoft.com/library/security/MS15-087
URL:technet.microsoft.com/library/security/MS15-088
URL:technet.microsoft.com/library/security/MS15-089
URL:technet.microsoft.com/library/security/MS15-090
URL:technet.microsoft.com/library/security/MS15-091
URL:technet.microsoft.com/library/security/MS15-092
URL:www.hkcert.org/my_url/en/alert/15081201
URL:www.hkcert.org/my_url/en/alert/15081202
URL:www.hkcert.org/my_url/en/alert/15081203
URL:www.hkcert.org/my_url/en/alert/15081204
URL:www.hkcert.org/my_url/en/alert/15081205
URL:www.hkcert.org/my_url/en/alert/15081206
URL:www.hkcert.org/my_url/en/alert/15081207
URL:www.hkcert.org/my_url/en/alert/15081208
URL:www.hkcert.org/my_url/en/alert/15081209
URL:www.hkcert.org/my_url/en/alert/15081210
URL:www.hkcert.org/my_url/en/alert/15081211
URL:www.hkcert.org/my_url/en/alert/15081212
URL:www.hkcert.org/my_url/en/alert/15081213
URL:www.hkcert.org/my_url/en/alert/15081214
URL:www.us-cert.gov/ncas/current-activity/2015/08/11/Microsoft-Releases-August-2015-Security-Bulletin
18.
Vulnerabilities in Adobe Flash Player
(APSB15-19)
[12/08/2015] Vulnerabilities were identified in the Adobe Flash Player. An
attacker could gain execute arbitrary code, cause a buffer overflow and take
control of the affected system. These vulnerabilities affect multiple versions
of the mentioned product. Security patches are available to resolve these
vulnerabilities.
URL:helpx.adobe.com/security/products/flash-player/apsb15-19.html
URL:technet.microsoft.com/en-us/library/security/2755801
URL:www.hkcert.org/my_url/en/alert/15081215
URL:www.us-cert.gov/ncas/current-activity/2015/08/11/Adobe-Releases-Security-Updates-Flash-Player
19.
Vulnerabilities in Mozilla Firefox (MFSA
2015-79, MFSA 2015-80, MFSA 2015-81, MFSA 2015-82, MFSA 2015-83, MFSA 2015-84,
MFSA 2015-85, MFSA 2015-86, MFSA 2015-87, MFSA 2015-88, MFSA 2015-89, MFSA
2015-90, MFSA 2015-91, MFSA 2015-92)
[12/08/2015] Vulnerabilities were identified in the Mozilla Firefox. An
attacker could gain execute arbitrary code, crash the application, bypass
security restrictions and perform cross-site scripting attacks. These
vulnerabilities affect multiple versions of the mentioned product. Security
patches are available to resolve these
vulnerabilities.
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-79/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-80/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-81/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-82/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-83/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-84/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-85/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-86/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-87/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-88/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-89/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-90/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-91/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-92/
URL:www.hkcert.org/my_url/en/alert/15081216
URL:www.us-cert.gov/ncas/current-activity/2015/08/11/Mozilla-Releases-Security-Updates-Firefox-Firefox-ESR-and-Firefox
20. Vulnerability in Schneider Electric IMT25 DTM
component (ICSA-15-223-01)
[12/08/2015] Vulnerability was identified in the Schneider Electric IMT25
DTM component. An attacker could cause a denial of service condition and execute
arbitrary code. This vulnerability affects versions 1.500.000 and prior of the
mentioned product. Security patches are available to resolve this
vulnerability.
URL:ics-cert.us-cert.gov/advisories/ICSA-15-223-01
21.
Vulnerabilities in Actiontec GT784WN
Wireless N DSL Modem (VU#335192)
[12/08/2015] Vulnerabilities were identified in the Actiontec GT784WN
Wireless N DSL Modem. An attacker could gain escalated privileges, perform
cross-site request forgery attacks and execute arbitrary code. These
vulnerabilities affect versions NCS01-1.0.12 and prior of the mentioned product.
Security patches are available to resolve these
vulnerabilities.
URL:www.kb.cert.org/vuls/id/335192
22.
Vulnerabilities in Mobile Devices C4 ODB2
dongle (VU#209512)
[12/08/2015] Vulnerabilities were identified in the Mobile Devices C4 ODB2
dongle. An attacker could execute arbitrary code and take complete control of
the devices. The affected version was not specified. Security patches are
available to resolve these
vulnerabilities.
URL:www.kb.cert.org/vuls/id/209512
23.
Security Updates in Red Hat Enterprise
Linux (RHSA-2015:1583-1, RHSA-2015:1586-1)
[12/08/2015] Red Hat
has released security update packages for fixing the vulnerabilities identified
in the kernel and firefox packages for Red Hat Enterprise Linux 5, 6, and 7. Due
to multiple errors, an attacker could gain escalated privileges, crash the
system and execute arbitrary
code.
URL:rhn.redhat.com/errata/RHSA-2015-1583.html
URL:rhn.redhat.com/errata/RHSA-2015-1586.html
24.
Security Updates in Ubuntu GNU/Linux
(USN-2702-1, USN-2702-2)
[12/08/2015] Ubuntu has
released security update packages for fixing the vulnerabilities identified in
the firefox and ubufox packages for versions 12.04 LTS, 14.04 LTS and 15.04 of
Ubuntu GNU/Linux. Due to multiple errors, an attacker could cause a denial of
service condition, crash the system, execute arbitrary code and obtain sensitive
information.
URL:www.ubuntu.com/usn/usn-2702-1/
URL:www.ubuntu.com/usn/usn-2702-2/
25.
Security Updates in Oracle Linux
(ELSA-2015-1586)
[12/08/2015] Oracle has
released security update packages for fixing the vulnerabilities identified in
the firefox package for Oracle Linux 5, 6 and 7. Due to multiple errors, an
attacker could cause a denial of service condition, crash the system and execute
arbitrary
code.
URL:linux.oracle.com/errata/ELSA-2015-1586.html
26.
Vulnerabilities in Xen (105253,
105254)
[11/08/2015]
Vulnerabilities were identified in the Xen. An
attacker could gain elevated privileges and obtain sensitive information. These
vulnerabilities affect multiple versions of the mentioned product. Security
patches are available to resolve these
vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105253
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105254
27.
Vulnerability in devscripts
(105242)
[11/08/2015]
Vulnerability was identified in the devscripts.
An attacker could execute arbitrary code. This vulnerability affects multiple
versions of the mentioned product. Security patches are available to resolve
this
vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105242
28.
Vulnerabilities in Linux Kernel (105236,
105237)
[11/08/2015]
Vulnerabilities were identified in the Linux
Kernel. An attacker could execute arbitrary code. These vulnerabilities affect
multiple versions of the mentioned product. Security patches are available to
resolve these
vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105236
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105237
29.
Vulnerabilities in IBM Domino Web Server
(1963016)
[10/08/2015]
Vulnerabilities were identified in the IBM
Domino Web Server. An attacker could perform cross-site scripting attacks. These
vulnerabilities affect versions prior to 8.5.3 Fix Pack 6 and 9.0.1 Fix Pack 3
of the mentioned product. Security patches are available to resolve these
vulnerabilities.
URL:www-01.ibm.com/support/docview.wss?uid=swg21963016
30.
Vulnerabilities in Huawei Android
Products (Huawei-SA-20150809-01-Android)
[10/08/2015] Vulnerabilities were identified in the Huawei Honor 7 and P8.
A remote attacker could execute arbitrary code. These vulnerabilities affect
multiple versions of the mentioned
products.
URL:www.huawei.com/en/security/psirt/security-bulletins/security-advisories/archive/hw-448928.htm
31.
Vulnerability in Sierra Wireless GX, ES,
and LS gateway devices (VU#628568)
[10/08/2015] Vulnerability was identified in the Sierra Wireless GX, ES,
and LS gateway devices running ALEOS. An attacker could gain full control of an
affected device. This vulnerability affects mentioned devices running ALEOS
versions 4.4.1 and earlier. Security patches are available to resolve this
vulnerability.
URL:www.kb.cert.org/vuls/id/628568
32.
Security Updates in Red Hat Enterprise
Linux (RHSA-2015:1581-1)
[10/08/2015] Red Hat
has released security update packages for fixing the vulnerabilities identified
in the firefox package for Red Hat Enterprise Linux 5, 6, and 7. An attacker
could obtain sensitive
information.
URL:rhn.redhat.com/errata/RHSA-2015-1581.html
33.
Security Updates in Ubuntu GNU/Linux
(USN-2707-1)
[10/08/2015] Ubuntu has
released security update packages for fixing the vulnerabilities identified in
the firefox package for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu
GNU/Linux. An attacker could obtain sensitive
information.
URL:www.ubuntu.com/usn/usn-2707-1/
34.
Security Updates in Debian
(DSA-3329-1)
[10/08/2015] Debian has
released security update packages for fixing the vulnerability identified in the
linux package for multiple versions of Debian GNU/Linux. Due to multiple errors,
an attacker could gain escalated privileges, cause a denial of service condition
and obtain sensitive
information.
URL:www.debian.org/security/2015/dsa-3329
35.
Security Updates in Oracle Linux
(ELSA-2015-1581)
[10/08/2015] Oracle has
released security update packages for fixing the vulnerabilities identified in
the firefox package for Oracle Linux 5, 6 and 7. Due to multiple errors, an
attacker could obtain sensitive
information.
URL:linux.oracle.com/errata/ELSA-2015-1581.html
36.
Security Updates in Slackware
(SSA:2015-219-02)
[10/08/2015] Slackware
has released security update packages for fixing the vulnerability identified in
the mozilla-nss package for multiple versions of Slackware Linux. An attacker
could obtain sensitive
information.
URL:www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.387488
Source(s)
of above information:
Sunday, August 16, 2015
Sunday, August 9, 2015
IT Security Alerts Weekly Digest (2 Aug ~ 8 Aug 2015)
1. Vulnerabilities in Mozilla Products (MFSA 2015-72, MFSA
2015-73, MFSA 2015-74, MFSA 2015-75, MFSA 2015-76, MFSA 2015-77, MFSA
2015-78)
[07/08/2015] Vulnerabilities were identified in Mozilla Firefox OS, Mozilla Firefox and Mozilla Firefox ESR. An attacker could bypass security restriction, obtain sensitive information, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect multiple versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:www.mozilla.org/en-US/security/known-vulnerabilities/firefox/
URL:www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-72/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-73/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-74/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-75/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-76/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-77/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-78/
2. Vulnerabilities in F5 Products (SOL17079)
[07/08/2015] Vulnerabilities were identified in the F5 BIG-IP LTM, BIG-IP AAM, BIG-IP AFM, BIG-IP Analytics, BIG-IP APM, BIG-IP ASM, BIG-IP Edge Gateway, BIG-IP GTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP PSM, BIG-IP WebAccelerator, BIG-IP WOM, Enterprise Manager, BIG-IQ Cloud, BIG-IQ Device, BIG-IQ Security and BIG-IQ ADC. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect multiple versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:support.f5.com/kb/en-us/solutions/public/17000/000/sol17079.html
3. Vulnerability in Websense Triton Content Manager (105344)
[07/08/2015] Vulnerability was identified in the Websense Triton Content Manager. An attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system. This vulnerability affects versions prior to 8.0.0 HF02 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105344
4. Vulnerabilities in Linux Kernel (105346, 105348)
[07/08/2015] Vulnerabilities were identified in the Linux Kernel. An attacker could bypass security restrictions, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system. These vulnerabilities affect multiple versions of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105346
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105348
5. Vulnerability in WordPress (105343)
[07/08/2015] Vulnerability was identified in the WordPress. An attacker could bypass security restrictions, execute arbitrary code and perform cross-site scripting attacks. This vulnerability affects version 4.2.2 of the mentioned product.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105343
6. Security Updates in Oracle Linux (ELSA-2015-3066, ELSA-2015-3067, ELSA-2015-3068)
[07/08/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the kernel package for Oracle Linux 5, 6 and 7. Due to multiple errors, an attacker could bypass security restriction, execute arbitrary code, cause a denial of service condition and crash the system.
URL:linux.oracle.com/errata/ELSA-2015-3066.html
URL:linux.oracle.com/errata/ELSA-2015-3067.html
URL:linux.oracle.com/errata/ELSA-2015-3068.html
7. Security Updates in SUSE (SUSE-SU-2015:1353-1)
[07/08/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the oracle-update package of SUSE Manager 2.1. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00003.html
8. Security Updates in Ubuntu GNU/Linux (USN-2703-1, USN-2704-1, USN-2705-1, USN-2706-1)
[07/08/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the cinder, swift, python-keystoneclient, python-keystonemiddleware and openjdk-6 packages for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.ubuntu.com/usn/usn-2703-1/
URL:www.ubuntu.com/usn/usn-2704-1/
URL:www.ubuntu.com/usn/usn-2705-1/
URL:www.ubuntu.com/usn/usn-2706-1/
9. Vulnerability in Juniper Pulse Secure (105288)
[06/08/2015] Vulnerability was identified in the Juniper Pulse Secure. An attacker could bypass security restrictions and obtain sensitive information. This vulnerability affects versions 7.1 and 8.0 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105288
10. Vulnerability in FortiNet FortiSandbox WebUI (105316)
[06/08/2015] Vulnerability was identified in the FortiNet FortiSandbox WebUI. An attacker could bypass security restrictions, execute arbitrary code and perform cross-site scripting attacks. This vulnerability affects versions prior to 2.1 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105316
11. Vulnerabilities in Huawei Products (Huawei-SA-20150805-01-ME906, Huawei-SA-20150805-01-VRP)
[06/08/2015] Vulnerabilities were identified in the Huawei mobile Internet access module and Huawei switches. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system. These vulnerabilities affect multiple firmware versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:www.huawei.com/en/security/psirt/security-bulletins/security-advisories/archive/hw-446601.htm
URL:www.huawei.com/en/security/psirt/security-bulletins/security-advisories/archive/hw-446634.htm
12. Vulnerability in VirtueMart extension for Joomla (105318)
[06/08/2015] Vulnerability was identified in the VirtueMart extension for Joomla. An attacker could bypass security restrictions. This vulnerability affects version 3.0.9 of the mentioned product.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105318
13. Security Updates in Oracle Linux (ELSA-2015-1534)
[06/08/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the kernel package for Oracle Linux 7. Due to multiple errors, an attacker could bypass security restriction, execute arbitrary code, cause a denial of service condition and crash the system.
URL:linux.oracle.com/errata/ELSA-2015-1534.html
14. Security Updates in FreeBSD (FreeBSD-SA-15:18.bsdpatch, FreeBSD-SA-15:19.routed)
[06/08/2015] FreeBSD has released security update packages for fixing the vulnerability identified in the patch and routed packages for multiple versions of FreeBSD Linux. Due to multiple errors, an attacker could bypass security restriction, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:18.bsdpatch.asc
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:19.routed.asc
15. Security Updates in SUSE (SUSE-SU-2015:1345-1)
[06/08/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the java-1_6_0-ibm packages of SUSE Linux Enterprise 12. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00002.html
16. Vulnerability in Android devices
[05/08/2015] Vulnerability was identified in the mediaserver service of Android devices. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. This vulnerability affects multiple versions of the mentioned products.
URL:www.hkcert.org/my_url/en/alert/15080501
17. Vulnerabilities in WordPress
[05/08/2015] Vulnerabilities were identified in the WordPress. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system. These vulnerabilities affect versions prior to 4.2.4 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:wordpress.org/news/2015/08/wordpress-4-2-4-security-and-maintenance-release/
URL:www.us-cert.gov/ncas/current-activity/2015/08/04/WordPress-Releases-Security-Update
18. Security Updates in Red Hat Enterprise Linux (RHSA-2015:1544-1, RHSA-2015:1545-1, RHSA-2015:1546-1)
[05/08/2015] Red Hat has released security update packages for fixing the vulnerabilities identified in the java-1.5.0-ibm and node.js packages for Red Hat OpenShift Enterprise 2.0 and 2.1, and Red Hat Enterprise Linux 5 and 6. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:rhn.redhat.com/errata/RHSA-2015-1544.html
URL:rhn.redhat.com/errata/RHSA-2015-1545.html
URL:rhn.redhat.com/errata/RHSA-2015-1546.html
19. Security Updates in Ubuntu GNU/Linux (USN-2677-1)
[05/08/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the oxide-qt package for versions 14.04 LTS and 15.04 of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.ubuntu.com/usn/usn-2677-1/
20. Vulnerabilities in F5 Products (SOL15273, SOL15532, SOL15889, SOL17028)
[04/08/2015] Vulnerabilities were identified in the F5 BIG-IP LTM, BIG-IP AAM, BIG-IP AFM, BIG-IP Analytics, BIG-IP APM, BIG-IP ASM, BIG-IP Edge Gateway, BIG-IP GTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP PSM, BIG-IP WebAccelerator, BIG-IP WOM, ARX, Enterprise Manager, FirePass, BIG-IQ Cloud, BIG-IQ Device, BIG-IQ Security and BIG-IQ ADC. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system. These vulnerabilities affect multiple versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:support.f5.com/kb/en-us/solutions/public/15000/200/sol15273.html
URL:support.f5.com/kb/en-us/solutions/public/15000/500/sol15532.html
URL:support.f5.com/kb/en-us/solutions/public/15000/800/sol15889.html
URL:support.f5.com/kb/en-us/solutions/public/17000/000/sol17028.html
21. Vulnerabilities in Xen (XSA-139, XSA-140)
[04/08/2015] Vulnerabilities were identified in the Xen. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges and execute arbitrary code. These vulnerabilities affect multiple versions of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:xenbits.xen.org/xsa/advisory-139.html
URL:xenbits.xen.org/xsa/advisory-140.html
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105253
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105254
22. Vulnerability in devscripts (105242)
[04/08/2015] Vulnerability was identified in the devscripts. An attacker could bypass security restrictions and execute arbitrary code. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105242
23. Vulnerabilities in Linux Kernel (105236, 105237)
[04/08/2015] Vulnerabilities were identified in the Linux Kernel. An attacker could bypass security restrictions and execute arbitrary code. These vulnerabilities affect multiple versions of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105236
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105237
24. Security Updates in Debian (DSA-3327-1)
[04/08/2015] Debian has released security update packages for fixing the vulnerability identified in the squid3 package for multiple versions of Debian GNU/Linux. An attacker could bypass security restrictions.
URL:www.debian.org/security/2015/dsa-3327
25. Security Updates in Mageia (MGASA-2015-0300, MGASA-2015-0301, MGASA-2015-0302, MGASA-2015-0303)
[04/08/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the ipython, pdns, pdns-recursor, moodle and php packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0300.html
URL:advisories.mageia.org/MGASA-2015-0301.html
URL:advisories.mageia.org/MGASA-2015-0302.html
URL:advisories.mageia.org/MGASA-2015-0303.html
26. Security Updates in SUSE (openSUSE-SU-2015:1332-1, openSUSE-SU-2015:1335-1)
[04/08/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the libuser and bind packages of openSUSE 13.1 and 13.2. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.html
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00001.html
27. Vulnerabilities in Trend Micro OfficeScan
[03/08/2015] Vulnerabilities were identified in the Trend Micro OfficeScan 11. An attacker could bypass security restrictions, obtain sensitive information, cause a denial of service condition and crash the system. These vulnerabilities affect versions prior to 11.0 Service Pack 1 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:docs.trendmicro.com/all/ent/officescan/v11.0/en-us/osce_11.0_sp1_cp_server_readme.htm
URL:downloadcenter.trendmicro.com/index.php?regs=NABU&clk=tbl&clkval=4569&cm_mmc=RSS-_-Download%20Center-_-product-_-5
28. Vulnerabilities in Chiyu Technology fingerprint access control devices (VU#360431)
[03/08/2015] Vulnerabilities were identified in the Chiyu Technology fingerprint access control devices. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code and perform cross-site scripting attacks. These vulnerabilities affect multiple firmware versions of the mentioned products.
URL:www.kb.cert.org/vuls/id/360431
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105233
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105234
29. Vulnerability in Net-SNMP (105232)
[03/08/2015] Vulnerability was identified in the Net-SNMP. An attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105232
30. Security Updates in Oracle Linux (ELSA-2015-3054, ELSA-2015-3055, ELSA-2015-3065)
[03/08/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the kernel and lxc packages for Oracle Linux 5, 6 and 7. Due to multiple errors, an attacker could bypass security restriction, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:linux.oracle.com/errata/ELSA-2015-3054.html
URL:linux.oracle.com/errata/ELSA-2015-3055.html
URL:linux.oracle.com/errata/ELSA-2015-3065.html
31. Security Updates in Debian (DSA-3322-1, DSA-3323-1, DSA-3324-1, DSA-3325-1, DSA-3326-1)
[03/08/2015] Debian has released security update packages for fixing the vulnerabilities identified in the ruby-rack, icu, icedove, apache2 and ghostscript packages for multiple versions of Debian GNU/Linux. Due to multiple errors, an attacker could bypass security restriction, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.debian.org/security/2015/dsa-3322
URL:www.debian.org/security/2015/dsa-3323
URL:www.debian.org/security/2015/dsa-3324
URL:www.debian.org/security/2015/dsa-3325
URL:www.debian.org/security/2015/dsa-3326
32. Security Updates in Mageia (MGASA-2015-0297, MGASA-2015-0298, MGASA-2015-0299)
[03/08/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the icu, bind and remind packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system.
URL:advisories.mageia.org/MGASA-2015-0297.html
URL:advisories.mageia.org/MGASA-2015-0298.html
URL:advisories.mageia.org/MGASA-2015-0299.html
33. Security Updates in SUSE (SUSE-SU-2015:1324-1, openSUSE-SU-2015:1326-1, SUSE-SU-2015:1329-1, SUSE-SU-2015:1331-1)
[03/08/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the kernel, bind and java-1_7_1-ibm packages of SUSE Linux Enterprise 11 and 12, and openSUSE Evergreen 11.4. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00050.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00051.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00052.html
34. Security Updates in Ubuntu GNU/Linux (USN-2700-1, USN-2701-1)
[03/08/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the linux and linux-lts-trusty packages for versions 12.04 LTS and 14.04 LTS of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.ubuntu.com/usn/usn-2700-1/
URL:www.ubuntu.com/usn/usn-2701-1/
[07/08/2015] Vulnerabilities were identified in Mozilla Firefox OS, Mozilla Firefox and Mozilla Firefox ESR. An attacker could bypass security restriction, obtain sensitive information, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect multiple versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:www.mozilla.org/en-US/security/known-vulnerabilities/firefox/
URL:www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-72/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-73/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-74/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-75/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-76/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-77/
URL:www.mozilla.org/en-US/security/advisories/mfsa2015-78/
2. Vulnerabilities in F5 Products (SOL17079)
[07/08/2015] Vulnerabilities were identified in the F5 BIG-IP LTM, BIG-IP AAM, BIG-IP AFM, BIG-IP Analytics, BIG-IP APM, BIG-IP ASM, BIG-IP Edge Gateway, BIG-IP GTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP PSM, BIG-IP WebAccelerator, BIG-IP WOM, Enterprise Manager, BIG-IQ Cloud, BIG-IQ Device, BIG-IQ Security and BIG-IQ ADC. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect multiple versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:support.f5.com/kb/en-us/solutions/public/17000/000/sol17079.html
3. Vulnerability in Websense Triton Content Manager (105344)
[07/08/2015] Vulnerability was identified in the Websense Triton Content Manager. An attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system. This vulnerability affects versions prior to 8.0.0 HF02 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105344
4. Vulnerabilities in Linux Kernel (105346, 105348)
[07/08/2015] Vulnerabilities were identified in the Linux Kernel. An attacker could bypass security restrictions, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system. These vulnerabilities affect multiple versions of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105346
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105348
5. Vulnerability in WordPress (105343)
[07/08/2015] Vulnerability was identified in the WordPress. An attacker could bypass security restrictions, execute arbitrary code and perform cross-site scripting attacks. This vulnerability affects version 4.2.2 of the mentioned product.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105343
6. Security Updates in Oracle Linux (ELSA-2015-3066, ELSA-2015-3067, ELSA-2015-3068)
[07/08/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the kernel package for Oracle Linux 5, 6 and 7. Due to multiple errors, an attacker could bypass security restriction, execute arbitrary code, cause a denial of service condition and crash the system.
URL:linux.oracle.com/errata/ELSA-2015-3066.html
URL:linux.oracle.com/errata/ELSA-2015-3067.html
URL:linux.oracle.com/errata/ELSA-2015-3068.html
7. Security Updates in SUSE (SUSE-SU-2015:1353-1)
[07/08/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the oracle-update package of SUSE Manager 2.1. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00003.html
8. Security Updates in Ubuntu GNU/Linux (USN-2703-1, USN-2704-1, USN-2705-1, USN-2706-1)
[07/08/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the cinder, swift, python-keystoneclient, python-keystonemiddleware and openjdk-6 packages for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.ubuntu.com/usn/usn-2703-1/
URL:www.ubuntu.com/usn/usn-2704-1/
URL:www.ubuntu.com/usn/usn-2705-1/
URL:www.ubuntu.com/usn/usn-2706-1/
9. Vulnerability in Juniper Pulse Secure (105288)
[06/08/2015] Vulnerability was identified in the Juniper Pulse Secure. An attacker could bypass security restrictions and obtain sensitive information. This vulnerability affects versions 7.1 and 8.0 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105288
10. Vulnerability in FortiNet FortiSandbox WebUI (105316)
[06/08/2015] Vulnerability was identified in the FortiNet FortiSandbox WebUI. An attacker could bypass security restrictions, execute arbitrary code and perform cross-site scripting attacks. This vulnerability affects versions prior to 2.1 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105316
11. Vulnerabilities in Huawei Products (Huawei-SA-20150805-01-ME906, Huawei-SA-20150805-01-VRP)
[06/08/2015] Vulnerabilities were identified in the Huawei mobile Internet access module and Huawei switches. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system. These vulnerabilities affect multiple firmware versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:www.huawei.com/en/security/psirt/security-bulletins/security-advisories/archive/hw-446601.htm
URL:www.huawei.com/en/security/psirt/security-bulletins/security-advisories/archive/hw-446634.htm
12. Vulnerability in VirtueMart extension for Joomla (105318)
[06/08/2015] Vulnerability was identified in the VirtueMart extension for Joomla. An attacker could bypass security restrictions. This vulnerability affects version 3.0.9 of the mentioned product.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105318
13. Security Updates in Oracle Linux (ELSA-2015-1534)
[06/08/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the kernel package for Oracle Linux 7. Due to multiple errors, an attacker could bypass security restriction, execute arbitrary code, cause a denial of service condition and crash the system.
URL:linux.oracle.com/errata/ELSA-2015-1534.html
14. Security Updates in FreeBSD (FreeBSD-SA-15:18.bsdpatch, FreeBSD-SA-15:19.routed)
[06/08/2015] FreeBSD has released security update packages for fixing the vulnerability identified in the patch and routed packages for multiple versions of FreeBSD Linux. Due to multiple errors, an attacker could bypass security restriction, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:18.bsdpatch.asc
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:19.routed.asc
15. Security Updates in SUSE (SUSE-SU-2015:1345-1)
[06/08/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the java-1_6_0-ibm packages of SUSE Linux Enterprise 12. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00002.html
16. Vulnerability in Android devices
[05/08/2015] Vulnerability was identified in the mediaserver service of Android devices. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. This vulnerability affects multiple versions of the mentioned products.
URL:www.hkcert.org/my_url/en/alert/15080501
17. Vulnerabilities in WordPress
[05/08/2015] Vulnerabilities were identified in the WordPress. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system. These vulnerabilities affect versions prior to 4.2.4 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:wordpress.org/news/2015/08/wordpress-4-2-4-security-and-maintenance-release/
URL:www.us-cert.gov/ncas/current-activity/2015/08/04/WordPress-Releases-Security-Update
18. Security Updates in Red Hat Enterprise Linux (RHSA-2015:1544-1, RHSA-2015:1545-1, RHSA-2015:1546-1)
[05/08/2015] Red Hat has released security update packages for fixing the vulnerabilities identified in the java-1.5.0-ibm and node.js packages for Red Hat OpenShift Enterprise 2.0 and 2.1, and Red Hat Enterprise Linux 5 and 6. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:rhn.redhat.com/errata/RHSA-2015-1544.html
URL:rhn.redhat.com/errata/RHSA-2015-1545.html
URL:rhn.redhat.com/errata/RHSA-2015-1546.html
19. Security Updates in Ubuntu GNU/Linux (USN-2677-1)
[05/08/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the oxide-qt package for versions 14.04 LTS and 15.04 of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.ubuntu.com/usn/usn-2677-1/
20. Vulnerabilities in F5 Products (SOL15273, SOL15532, SOL15889, SOL17028)
[04/08/2015] Vulnerabilities were identified in the F5 BIG-IP LTM, BIG-IP AAM, BIG-IP AFM, BIG-IP Analytics, BIG-IP APM, BIG-IP ASM, BIG-IP Edge Gateway, BIG-IP GTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP PSM, BIG-IP WebAccelerator, BIG-IP WOM, ARX, Enterprise Manager, FirePass, BIG-IQ Cloud, BIG-IQ Device, BIG-IQ Security and BIG-IQ ADC. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system. These vulnerabilities affect multiple versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:support.f5.com/kb/en-us/solutions/public/15000/200/sol15273.html
URL:support.f5.com/kb/en-us/solutions/public/15000/500/sol15532.html
URL:support.f5.com/kb/en-us/solutions/public/15000/800/sol15889.html
URL:support.f5.com/kb/en-us/solutions/public/17000/000/sol17028.html
21. Vulnerabilities in Xen (XSA-139, XSA-140)
[04/08/2015] Vulnerabilities were identified in the Xen. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges and execute arbitrary code. These vulnerabilities affect multiple versions of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:xenbits.xen.org/xsa/advisory-139.html
URL:xenbits.xen.org/xsa/advisory-140.html
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105253
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105254
22. Vulnerability in devscripts (105242)
[04/08/2015] Vulnerability was identified in the devscripts. An attacker could bypass security restrictions and execute arbitrary code. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105242
23. Vulnerabilities in Linux Kernel (105236, 105237)
[04/08/2015] Vulnerabilities were identified in the Linux Kernel. An attacker could bypass security restrictions and execute arbitrary code. These vulnerabilities affect multiple versions of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105236
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105237
24. Security Updates in Debian (DSA-3327-1)
[04/08/2015] Debian has released security update packages for fixing the vulnerability identified in the squid3 package for multiple versions of Debian GNU/Linux. An attacker could bypass security restrictions.
URL:www.debian.org/security/2015/dsa-3327
25. Security Updates in Mageia (MGASA-2015-0300, MGASA-2015-0301, MGASA-2015-0302, MGASA-2015-0303)
[04/08/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the ipython, pdns, pdns-recursor, moodle and php packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0300.html
URL:advisories.mageia.org/MGASA-2015-0301.html
URL:advisories.mageia.org/MGASA-2015-0302.html
URL:advisories.mageia.org/MGASA-2015-0303.html
26. Security Updates in SUSE (openSUSE-SU-2015:1332-1, openSUSE-SU-2015:1335-1)
[04/08/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the libuser and bind packages of openSUSE 13.1 and 13.2. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.html
URL:lists.opensuse.org/opensuse-security-announce/2015-08/msg00001.html
27. Vulnerabilities in Trend Micro OfficeScan
[03/08/2015] Vulnerabilities were identified in the Trend Micro OfficeScan 11. An attacker could bypass security restrictions, obtain sensitive information, cause a denial of service condition and crash the system. These vulnerabilities affect versions prior to 11.0 Service Pack 1 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:docs.trendmicro.com/all/ent/officescan/v11.0/en-us/osce_11.0_sp1_cp_server_readme.htm
URL:downloadcenter.trendmicro.com/index.php?regs=NABU&clk=tbl&clkval=4569&cm_mmc=RSS-_-Download%20Center-_-product-_-5
28. Vulnerabilities in Chiyu Technology fingerprint access control devices (VU#360431)
[03/08/2015] Vulnerabilities were identified in the Chiyu Technology fingerprint access control devices. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code and perform cross-site scripting attacks. These vulnerabilities affect multiple firmware versions of the mentioned products.
URL:www.kb.cert.org/vuls/id/360431
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105233
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105234
29. Vulnerability in Net-SNMP (105232)
[03/08/2015] Vulnerability was identified in the Net-SNMP. An attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105232
30. Security Updates in Oracle Linux (ELSA-2015-3054, ELSA-2015-3055, ELSA-2015-3065)
[03/08/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the kernel and lxc packages for Oracle Linux 5, 6 and 7. Due to multiple errors, an attacker could bypass security restriction, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:linux.oracle.com/errata/ELSA-2015-3054.html
URL:linux.oracle.com/errata/ELSA-2015-3055.html
URL:linux.oracle.com/errata/ELSA-2015-3065.html
31. Security Updates in Debian (DSA-3322-1, DSA-3323-1, DSA-3324-1, DSA-3325-1, DSA-3326-1)
[03/08/2015] Debian has released security update packages for fixing the vulnerabilities identified in the ruby-rack, icu, icedove, apache2 and ghostscript packages for multiple versions of Debian GNU/Linux. Due to multiple errors, an attacker could bypass security restriction, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.debian.org/security/2015/dsa-3322
URL:www.debian.org/security/2015/dsa-3323
URL:www.debian.org/security/2015/dsa-3324
URL:www.debian.org/security/2015/dsa-3325
URL:www.debian.org/security/2015/dsa-3326
32. Security Updates in Mageia (MGASA-2015-0297, MGASA-2015-0298, MGASA-2015-0299)
[03/08/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the icu, bind and remind packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system.
URL:advisories.mageia.org/MGASA-2015-0297.html
URL:advisories.mageia.org/MGASA-2015-0298.html
URL:advisories.mageia.org/MGASA-2015-0299.html
33. Security Updates in SUSE (SUSE-SU-2015:1324-1, openSUSE-SU-2015:1326-1, SUSE-SU-2015:1329-1, SUSE-SU-2015:1331-1)
[03/08/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the kernel, bind and java-1_7_1-ibm packages of SUSE Linux Enterprise 11 and 12, and openSUSE Evergreen 11.4. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00050.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00051.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00052.html
34. Security Updates in Ubuntu GNU/Linux (USN-2700-1, USN-2701-1)
[03/08/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the linux and linux-lts-trusty packages for versions 12.04 LTS and 14.04 LTS of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.ubuntu.com/usn/usn-2700-1/
URL:www.ubuntu.com/usn/usn-2701-1/
Monday, August 3, 2015
IT Security Alerts Weekly Digest (26 Jul ~ 1 Aug 2015)
1. Vulnerabilities in Cisco Products
(cisco-sa-20150730-asr1k)
[31/07/2015] Vulnerabilities were identified in the Cisco ASR 1000 Series Aggregation Services Routers, Cisco AnyConnect Secure Mobilty Client, Cisco Prime Central Hosted Collaboration Solution, Cisco IM and Presence Service, Cisco IOS-XE Software and Cisco Unified Communications Manager. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code, perform cross-site scripting attacks, cause a denial of service condition and crash the system. These vulnerabilities affect multiple firmware versions of the mentioned products. Security patches are available to resolve these vulnerabilities except the Cisco Prime Central Hosted Collaboration Solution and Cisco Unified Communications Manager.
URL:tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150730-asr1k
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40175
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40214
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40215
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40217
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40223
URL:www.us-cert.gov/ncas/current-activity/2015/07/30/Cisco-Releases-Security-Updates
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105203
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105222
2. Vulnerabilities in Symantec Endpoint Protection (SYM15-007)
[31/07/2015] Vulnerabilities were identified in the Symantec Endpoint Protection Manager and Clients. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code and perform code injection attacks. These vulnerabilities affect versions prior to 12.1-RU6-MP1 of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2015&suid=20150730_00
3. Vulnerability in Multiple BIOS implementations (VU#577140)
[31/07/2015] Vulnerability was identified in multiple BIOS implementations. An attacker could bypass security restrictions, cause a denial of service condition and execute arbitrary code. This vulnerability affects multiple Vendor BIOS implementations. Security patches are available to resolve this vulnerability.
URL:www.kb.cert.org/vuls/id/577140
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105219
4. Vulnerability in Dell NetVault Backup (105220)
[31/07/2015] Vulnerability was identified in the Dell NetVault Backup. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. This vulnerability affects versions prior to 10.0.5 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105220
5. Vulnerability in F5 Products (SOL17025)
[31/07/2015] Vulnerability was identified in the F5 BIG-IP GTM. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. This vulnerability affects versions 10.0.0 - 10.1.0 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:support.f5.com/kb/en-us/solutions/public/17000/000/sol17025.html
6. Vulnerability in Huawei eCloud CC solution (HW-445981)
[31/07/2015] Vulnerability was identified in the Huawei eCloud CC solution. An attacker could bypass security restrictions and execute arbitrary code. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:www.huawei.com/en/security/psirt/security-bulletins/security-notices/archive/hw-445981.htm
7. Security Updates in Oracle Linux (ELSA-2015-1526, ELSA-2015-3064)
[31/07/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the java-1.6.0-openjdk and kernel-uek packages for Oracle Linux 6 and 7. Due to multiple errors, an attacker could bypass security restriction, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:linux.oracle.com/errata/ELSA-2015-1526.html
URL:linux.oracle.com/errata/ELSA-2015-3064.html
8. Security Updates in Debian (DSA-3320-1, DSA-3321-1)
[31/07/2015] Debian has released security update packages for fixing the vulnerabilities identified in the openafs and xmltooling package for multiple versions of Debian GNU/Linux. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code, cause a denial of service condition and crash the system.
URL:www.debian.org/security/2015/dsa-3320
URL:www.debian.org/security/2015/dsa-3321
9. Security Updates in Mageia (MGASA-2015-0296)
[31/07/2015] Mageia has released security update packages for fixing the vulnerability identified in the groovy package for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions and execute arbitrary code.
URL:advisories.mageia.org/MGASA-2015-0296.html
10. Security Updates in Red Hat Enterprise Linux (RHSA-2015:1526-1)
[31/07/2015] Red Hat has released security update packages for fixing the vulnerabilities identified in the java-1.6.0-openjdk packages for Red Hat Enterprise Linux 5, 6 and 7. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:rhn.redhat.com/errata/RHSA-2015-1526.html
11. Security Updates in SUSE (SUSE-SU-2015:1316-1, SUSE-SU-2015:1319-1, SUSE-SU-2015:1320-1, SUSE-SU-2015:1322-1)
[31/07/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the bind and java-1_7_0-openjdk packages of SUSE Linux Enterprise 10, 11 and 12. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00045.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00048.html
12. Security Updates in Ubuntu GNU/Linux (USN-2696-1, USN-2697-1, USN-2698-1, USN-2699-1)
[31/07/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the openjdk-7, ghostscript, sqlite3 and hplip package for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.ubuntu.com/usn/usn-2696-1/
URL:www.ubuntu.com/usn/usn-2697-1/
URL:www.ubuntu.com/usn/usn-2698-1/
URL:www.ubuntu.com/usn/usn-2699-1/
13. Information Updates on Microsoft Security Advisory and Bulletins (2755801, 3072630, 3072631, 3079904)
[30/07/2015] Microsoft has updated information on the Security Advisory and Security Bulletins for Microsoft Internet Explorer and Microsoft Windows. (a) KB2755801 added the 3074683 update for Windows 10 systems to the Current Update section. (b) MS15-069 was revised to correct the Desktop Experience footnote in the Affected Software section. (c) MS15-074 was rereleased to announce the availability of an update package for Windows 10 systems. (d) MS15-078 was rereleased to announce the availability of an update package for Windows 10 systems.
URL:technet.microsoft.com/en-us/library/security/2755801
URL:technet.microsoft.com/en-us/library/security/MS15-069
URL:technet.microsoft.com/en-us/library/security/MS15-074
URL:technet.microsoft.com/en-us/library/security/MS15-078
14. Vulnerabilities in IBM WebSphere Application Server
[30/07/2015] Vulnerabilities were identified in the IBM WebSphere Application Server. An attacker could obtain sensitive information and cause a denial of service condition. These vulnerabilities affect multiple versions of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:www-01.ibm.com/support/docview.wss?uid=swg21962931
15. Vulnerabilities in OpenStack Products (105132, 105198, 105199)
[30/07/2015] Vulnerabilities were identified in the OpenStack Glance and OpenStack Designate. An attacker could bypass security restrictions and cause a denial of service condition. These vulnerabilities affect multiple versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105132
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105198
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105199
16. Security Updates in Oracle Linux (ELSA-2015-1419, ELSA-2015-1471, ELSA-2015-1482, ELSA-2015-1513, ELSA-2015-1514, ELSA-2015-1515, ELSA-2015-3053)
[30/07/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the libxml2, bind, libuser, bind97 and kernel packages for Oracle Linux 5, 6 and 7. Due to multiple errors, an attacker could cause a denial of service condition, gain elevated privileges and crash the system.
URL:linux.oracle.com/errata/ELSA-2015-1419.html
URL:linux.oracle.com/errata/ELSA-2015-1471.html
URL:linux.oracle.com/errata/ELSA-2015-1482.html
URL:linux.oracle.com/errata/ELSA-2015-1513.html
URL:linux.oracle.com/errata/ELSA-2015-1514.html
URL:linux.oracle.com/errata/ELSA-2015-1515.html
URL:linux.oracle.com/errata/ELSA-2015-3053.html
17. Security Updates in Red Hat Gluster Storage (RHSA-2015:1495-1)
[30/07/2015] Red Hat has released security update packages for fixing the vulnerabilities identified in version 3.0 of Red Hat Gluster Storage. Due to multiple errors, an attacker could bypass security restrictions and execute arbitrary code.
URL:rhn.redhat.com/errata/RHSA-2015-1495.html
18. Security Updates in Ubuntu GNU/Linux (USN-2694-1, USN-2695-1)
[30/07/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the PCRE and HTML Tidy packages for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu GNU/Linux. Due to multiple errors, an attacker could crash the system, cause a denial of service condition and execute arbitrary code.
URL:www.ubuntu.com/usn/usn-2694-1/
URL:www.ubuntu.com/usn/usn-2695-1/
19. Vulnerability in BIND (AA-01272)
[29/07/2015] Vulnerability was identified in the BIND. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. This vulnerability affects versions prior to 9.9.7-P2 or 9.10.2-P3 of the mentioned products. Security patches are available to resolve this vulnerability.
URL:kb.isc.org/article/AA-01272
URL:www.us-cert.gov/ncas/current-activity/2015/07/28/Internet-Systems-Consortium-ISC-Releases-Security-Updates-BIND
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105120
20. Vulnerabilities in Cisco Products
[29/07/2015] Vulnerabilities were identified in the Cisco UCS Central Software and Cisco AnyConnect Secure Mobility Client. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect multiple firmware versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40151
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40176
21. Vulnerabilities in F5 Products (SOL16909, SOL16912)
[29/07/2015] Vulnerabilities were identified in the F5 BIG-IP LTM, BIG-IP AAM, BIG-IP AFM, BIG-IP Analytics, BIG-IP APM, BIG-IP ASM, BIG-IP Edge Gateway, BIG-IP GTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP PSM, BIG-IP WebAccelerator, BIG-IP WOM, Enterprise Manager, BIG-IQ Cloud, BIG-IQ Device, BIG-IQ Security and BIG-IQ ADC. An attacker could bypass security restrictions, obtain sensitive information, cause a denial of service condition and crash the system. These vulnerabilities affect multiple versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:support.f5.com/kb/en-us/solutions/public/16000/900/sol16909.html
URL:support.f5.com/kb/en-us/solutions/public/16000/900/sol16912.html
22. Vulnerability in Foxit Reader (105109)
[29/07/2015] Vulnerability was identified in the Foxit Reader. An attacker could bypass security restrictions and execute arbitrary code. This vulnerability affects versions 7.0.8, 7.0.9 and 7.1.5 of the mentioned product.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105109
23. Vulnerabilities in Android Stagefright
[29/07/2015] Vulnerabilities were identified in the Android Stagefright media playback service. An attacker could bypass security restrictions, execute arbitrary code and compromise the system. These vulnerabilities affect firmware versions prior to 5.1.1_r5 of the mentioned products.
URL:www.hkcert.org/my_url/en/alert/15072901
URL:www.kb.cert.org/vuls/id/924951
URL:www.us-cert.gov/ncas/current-activity/2015/07/28/%E2%80%9CStagefright%E2%80%9D-Android-Vulnerability
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105118
24. Security Updates in Oracle Linux (ELSA-2015-1249, ELSA-2015-1254, ELSA-2015-1272, ELSA-2015-1287, ELSA-2015-1330, ELSA-2015-1344, ELSA-2015-1347, ELSA-2015-1378, ELSA-2015-1385, ELSA-2015-1409, ELSA-2015-1417, ELSA-2015-1419, ELSA-2015-1439, ELSA-2015-1447, ELSA-2015-1457, ELSA-2015-1458, ELSA-2015-1459, ELSA-2015-1460, ELSA-2015-1462)
[29/07/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the httpd, curl, kernel, freeradius, python, autofs, pki-core, hivex, net-snmp, sudo, mailman, libxml2, wpa_supplicant, grep, gnutls, libreoffice, ntp, wireshark and ipa packages for Oracle Linux 6. Due to multiple errors, an attacker could bypass security restriction, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:linux.oracle.com/errata/ELSA-2015-1249.html
URL:linux.oracle.com/errata/ELSA-2015-1254.html
URL:linux.oracle.com/errata/ELSA-2015-1272.html
URL:linux.oracle.com/errata/ELSA-2015-1287.html
URL:linux.oracle.com/errata/ELSA-2015-1330.html
URL:linux.oracle.com/errata/ELSA-2015-1344.html
URL:linux.oracle.com/errata/ELSA-2015-1347.html
URL:linux.oracle.com/errata/ELSA-2015-1378.html
URL:linux.oracle.com/errata/ELSA-2015-1385.html
URL:linux.oracle.com/errata/ELSA-2015-1409.html
URL:linux.oracle.com/errata/ELSA-2015-1417.html
URL:linux.oracle.com/errata/ELSA-2015-1419.html
URL:linux.oracle.com/errata/ELSA-2015-1439.html
URL:linux.oracle.com/errata/ELSA-2015-1447.html
URL:linux.oracle.com/errata/ELSA-2015-1457.html
URL:linux.oracle.com/errata/ELSA-2015-1458.html
URL:linux.oracle.com/errata/ELSA-2015-1459.html
URL:linux.oracle.com/errata/ELSA-2015-1460.html
URL:linux.oracle.com/errata/ELSA-2015-1462.html
25. Security Updates in Debian (DSA-3319-1)
[29/07/2015] Debian has released security update packages for fixing the vulnerability identified in the bind9 package for multiple versions of Debian GNU/Linux. An attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system.
URL:www.debian.org/security/2015/dsa-3319
26. Security Updates in FreeBSD (FreeBSD-SA-15:14.bsdpatch, FreeBSD-SA-15:15.tcp, FreeBSD-SA-15:16.openssh, FreeBSD-SA-15:17.bind)
[29/07/2015] FreeBSD has released security update packages for fixing the vulnerability identified in the patch, inet, openssh and bind packages for multiple versions of FreeBSD Linux. Due to multiple errors, an attacker could bypass security restriction, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:14.bsdpatch.asc
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:15.tcp.asc
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:16.openssh.asc
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:17.bind.asc
27. Security Updates in Mageia (MGASA-2015-0291, MGASA-2015-0292, MGASA-2015-0293, MGASA-2015-0294, MGASA-2015-0295)
[29/07/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the freeradius, ansible, python-django14, python-django, springframework and openssh packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0291.html
URL:advisories.mageia.org/MGASA-2015-0292.html
URL:advisories.mageia.org/MGASA-2015-0293.html
URL:advisories.mageia.org/MGASA-2015-0294.html
URL:advisories.mageia.org/MGASA-2015-0295.html
28. Security Updates in Red Hat Enterprise Linux (RHSA-2015:1512-1, RHSA-2015:1513-1, RHSA-2015:1514-1, RHSA-2015:1515-1)
[29/07/2015] Red Hat has released security update packages for fixing the vulnerabilities identified in the qemu-kvm-rhev, bind and bind97 packages for Red Hat Enterprise Linux OpenStack Platform 5 and 6, Red Hat Enterprise Linux 5, 6 and 7. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:rhn.redhat.com/errata/RHSA-2015-1512.html
URL:rhn.redhat.com/errata/RHSA-2015-1513.html
URL:rhn.redhat.com/errata/RHSA-2015-1514.html
URL:rhn.redhat.com/errata/RHSA-2015-1515.html
29. Security Updates in Slackware (SSA:2015-209-01)
[29/07/2015] Slackware has released security update packages for fixing the vulnerability identified in the bind package for multiple versions of Slackware Linux. An attacker could bypass security restriction, cause a denial of service condition and crash the system.
URL:www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.554472
30. Security Updates in SUSE (SUSE-SU-2015:1302-1, SUSE-SU-2015:1304-1, SUSE-SU-2015:1305-1)
[29/07/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the xen and bind packages of SUSE Linux Enterprise 11 and 12. Due to multiple errors, an attacker could bypass security restrictions, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00042.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00043.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00044.html
31. Security Updates in Ubuntu GNU/Linux (USN-2686-1)
[29/07/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the apache2 package for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, execute arbitrary code and perform HTTP request smuggling attacks.
URL:www.ubuntu.com/usn/usn-2687-1/
URL:www.ubuntu.com/usn/usn-2688-1/
URL:www.ubuntu.com/usn/usn-2689-1/
URL:www.ubuntu.com/usn/usn-2690-1/
URL:www.ubuntu.com/usn/usn-2691-1/
URL:www.ubuntu.com/usn/usn-2692-1/
URL:www.ubuntu.com/usn/usn-2693-1/
32. Vulnerabilities in Microsoft Internet Explorer Mobile
[28/07/2015] Vulnerabilities were identified in the Microsoft Internet Explorer Mobile. An attacker could bypass security restrictions and execute arbitrary code. The affected version was not specified.
URL:www.hkcert.org/my_url/en/alert/15072701
33. Vulnerabilities in Cisco Products
[28/07/2015] Vulnerabilities were identified in the Cisco Firepower 9000 Series devices, Cisco Web Security Appliance (WSA), Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA). An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code and perform cross-site scripting attacks. These vulnerabilities affect multiple firmware versions of the mentioned products.
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40136
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40172
34. Security Updates in Oracle Linux (ELSA-2015-1507, ELSA-2015-1510)
[28/07/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the qemu-kvm and clutter packages for Oracle Linux 7. Due to multiple errors, an attacker could bypass security restriction, gain elevated privileges and execute arbitrary code.
URL:linux.oracle.com/errata/ELSA-2015-1507.html
URL:linux.oracle.com/errata/ELSA-2015-1510.html
35. Security Updates in Debian (DSA-3316-1, DSA-3318-1)
[28/07/2015] Debian has released security update packages for fixing the vulnerabilities identified in the openjdk-7 and expat package for multiple versions of Debian GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.debian.org/security/2015/dsa-3316
URL:www.debian.org/security/2015/dsa-3318
36. Security Updates in Mageia (MGASA-2015-0279, MGASA-2015-0280, MGASA-2015-0281, MGASA-2015-0282, MGASA-2015-0283, MGASA-2015-0284, MGASA-2015-0285, MGASA-2015-0286, MGASA-2015-0287, MGASA-2015-0288, MGASA-2015-0289, MGASA-2015-0290)
[28/07/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the mariadb, java-1.8.0-openjdk, apache, evolution, wesnoth, thunderbird, thunderbird-l10n, expat, icu, chromium-browser-stable, stunnel and wordpress packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0279.html
URL:advisories.mageia.org/MGASA-2015-0280.html
URL:advisories.mageia.org/MGASA-2015-0281.html
URL:advisories.mageia.org/MGASA-2015-0282.html
URL:advisories.mageia.org/MGASA-2015-0283.html
URL:advisories.mageia.org/MGASA-2015-0284.html
URL:advisories.mageia.org/MGASA-2015-0285.html
URL:advisories.mageia.org/MGASA-2015-0286.html
URL:advisories.mageia.org/MGASA-2015-0287.html
URL:advisories.mageia.org/MGASA-2015-0288.html
URL:advisories.mageia.org/MGASA-2015-0289.html
URL:advisories.mageia.org/MGASA-2015-0290.html
37. Security Updates in Red Hat Enterprise Linux (RHSA-2015:1499-1, RHSA-2015:1507-1, RHSA-2015:1510-1)
[28/07/2015] Red Hat has released security update packages for fixing the vulnerabilities identified in the chromium-browser, qemu-kvm and clutter packages for Red Hat Enterprise Linux 6 and 7. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:rhn.redhat.com/errata/RHSA-2015-1499.html
URL:rhn.redhat.com/errata/RHSA-2015-1507.html
URL:rhn.redhat.com/errata/RHSA-2015-1510.html
38. Security Updates in SUSE (SUSE-SU-2015:1299-1)
[28/07/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the xen package of SUSE Linux Enterprise 11. Due to multiple errors, an attacker could bypass security restrictions, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00041.html
39. Security Updates in Ubuntu GNU/Linux (USN-2686-1)
[28/07/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the apache2 package for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, execute arbitrary code and perform HTTP request smuggling attacks.
URL:www.ubuntu.com/usn/usn-2686-1/
40. Vulnerability in Cisco Products
[27/07/2015] Vulnerability was identified in the Cisco Web Security Appliance (WSA), Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA). An attacker could bypass security restrictions and obtain sensitive information. This vulnerability affects multiple firmware versions of the mentioned products.
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40137
41. Vulnerabilities in Honeywell Tuxedo Touch Controller (VU#857948)
[27/07/2015] Vulnerabilities were identified in the Honeywell Tuxedo Touch Controller. An attacker could bypass security restrictions, execute arbitrary code, perform cross-site request forgery attacks. These vulnerabilities affect firmware versions prior to TUXW_V5.2.19.0_VA of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:www.kb.cert.org/vuls/id/857948
42. Vulnerability in Fiat-Chrysler Automative UConnect (VU#819439)
[27/07/2015] Vulnerability was identified in the Fiat-Chrysler Automative UConnect. An attacker could bypass security restrictions, execute arbitrary code and compromise the system. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:www.kb.cert.org/vuls/id/819439
43. Vulnerability in Ghostscript (105033)
[27/07/2015] Vulnerability was identified in the Ghostscript. An attacker could bypass security restrictions and execute arbitrary code. This vulnerability affects version 9.16 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105033
44. Vulnerabilities in libuser (105022, 105023)
[27/07/2015] Vulnerabilities were identified in the libuser. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system. These vulnerabilities affect versions prior to 0.62 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105022
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105023
45. Security Updates in Debian (DSA-3315-1, DSA-3317-1)
[27/07/2015] Debian has released security update packages for fixing the vulnerabilities identified in the chromium-browser and lxc package for multiple versions of Debian GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.debian.org/security/2015/dsa-3315
URL:www.debian.org/security/2015/dsa-3317
46. Security Updates in Mageia (MGASA-2015-0278)
[27/07/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the libuser packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0278.html
47. Security Updates in SUSE (openSUSE-SU-2015:1287-1, openSUSE-SU-2015:1288-1, openSUSE-SU-2015:1289-1)
[27/07/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the Chromium, java-1_7_0-openjdk and java-1_8_0-openjdk package of openSUSE 13.1 and 13.2. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00038.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.html
[31/07/2015] Vulnerabilities were identified in the Cisco ASR 1000 Series Aggregation Services Routers, Cisco AnyConnect Secure Mobilty Client, Cisco Prime Central Hosted Collaboration Solution, Cisco IM and Presence Service, Cisco IOS-XE Software and Cisco Unified Communications Manager. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code, perform cross-site scripting attacks, cause a denial of service condition and crash the system. These vulnerabilities affect multiple firmware versions of the mentioned products. Security patches are available to resolve these vulnerabilities except the Cisco Prime Central Hosted Collaboration Solution and Cisco Unified Communications Manager.
URL:tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150730-asr1k
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40175
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40214
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40215
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40217
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40223
URL:www.us-cert.gov/ncas/current-activity/2015/07/30/Cisco-Releases-Security-Updates
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105203
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105222
2. Vulnerabilities in Symantec Endpoint Protection (SYM15-007)
[31/07/2015] Vulnerabilities were identified in the Symantec Endpoint Protection Manager and Clients. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code and perform code injection attacks. These vulnerabilities affect versions prior to 12.1-RU6-MP1 of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2015&suid=20150730_00
3. Vulnerability in Multiple BIOS implementations (VU#577140)
[31/07/2015] Vulnerability was identified in multiple BIOS implementations. An attacker could bypass security restrictions, cause a denial of service condition and execute arbitrary code. This vulnerability affects multiple Vendor BIOS implementations. Security patches are available to resolve this vulnerability.
URL:www.kb.cert.org/vuls/id/577140
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105219
4. Vulnerability in Dell NetVault Backup (105220)
[31/07/2015] Vulnerability was identified in the Dell NetVault Backup. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. This vulnerability affects versions prior to 10.0.5 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105220
5. Vulnerability in F5 Products (SOL17025)
[31/07/2015] Vulnerability was identified in the F5 BIG-IP GTM. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. This vulnerability affects versions 10.0.0 - 10.1.0 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:support.f5.com/kb/en-us/solutions/public/17000/000/sol17025.html
6. Vulnerability in Huawei eCloud CC solution (HW-445981)
[31/07/2015] Vulnerability was identified in the Huawei eCloud CC solution. An attacker could bypass security restrictions and execute arbitrary code. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:www.huawei.com/en/security/psirt/security-bulletins/security-notices/archive/hw-445981.htm
7. Security Updates in Oracle Linux (ELSA-2015-1526, ELSA-2015-3064)
[31/07/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the java-1.6.0-openjdk and kernel-uek packages for Oracle Linux 6 and 7. Due to multiple errors, an attacker could bypass security restriction, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:linux.oracle.com/errata/ELSA-2015-1526.html
URL:linux.oracle.com/errata/ELSA-2015-3064.html
8. Security Updates in Debian (DSA-3320-1, DSA-3321-1)
[31/07/2015] Debian has released security update packages for fixing the vulnerabilities identified in the openafs and xmltooling package for multiple versions of Debian GNU/Linux. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code, cause a denial of service condition and crash the system.
URL:www.debian.org/security/2015/dsa-3320
URL:www.debian.org/security/2015/dsa-3321
9. Security Updates in Mageia (MGASA-2015-0296)
[31/07/2015] Mageia has released security update packages for fixing the vulnerability identified in the groovy package for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions and execute arbitrary code.
URL:advisories.mageia.org/MGASA-2015-0296.html
10. Security Updates in Red Hat Enterprise Linux (RHSA-2015:1526-1)
[31/07/2015] Red Hat has released security update packages for fixing the vulnerabilities identified in the java-1.6.0-openjdk packages for Red Hat Enterprise Linux 5, 6 and 7. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:rhn.redhat.com/errata/RHSA-2015-1526.html
11. Security Updates in SUSE (SUSE-SU-2015:1316-1, SUSE-SU-2015:1319-1, SUSE-SU-2015:1320-1, SUSE-SU-2015:1322-1)
[31/07/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the bind and java-1_7_0-openjdk packages of SUSE Linux Enterprise 10, 11 and 12. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00045.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00048.html
12. Security Updates in Ubuntu GNU/Linux (USN-2696-1, USN-2697-1, USN-2698-1, USN-2699-1)
[31/07/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the openjdk-7, ghostscript, sqlite3 and hplip package for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.ubuntu.com/usn/usn-2696-1/
URL:www.ubuntu.com/usn/usn-2697-1/
URL:www.ubuntu.com/usn/usn-2698-1/
URL:www.ubuntu.com/usn/usn-2699-1/
13. Information Updates on Microsoft Security Advisory and Bulletins (2755801, 3072630, 3072631, 3079904)
[30/07/2015] Microsoft has updated information on the Security Advisory and Security Bulletins for Microsoft Internet Explorer and Microsoft Windows. (a) KB2755801 added the 3074683 update for Windows 10 systems to the Current Update section. (b) MS15-069 was revised to correct the Desktop Experience footnote in the Affected Software section. (c) MS15-074 was rereleased to announce the availability of an update package for Windows 10 systems. (d) MS15-078 was rereleased to announce the availability of an update package for Windows 10 systems.
URL:technet.microsoft.com/en-us/library/security/2755801
URL:technet.microsoft.com/en-us/library/security/MS15-069
URL:technet.microsoft.com/en-us/library/security/MS15-074
URL:technet.microsoft.com/en-us/library/security/MS15-078
14. Vulnerabilities in IBM WebSphere Application Server
[30/07/2015] Vulnerabilities were identified in the IBM WebSphere Application Server. An attacker could obtain sensitive information and cause a denial of service condition. These vulnerabilities affect multiple versions of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:www-01.ibm.com/support/docview.wss?uid=swg21962931
15. Vulnerabilities in OpenStack Products (105132, 105198, 105199)
[30/07/2015] Vulnerabilities were identified in the OpenStack Glance and OpenStack Designate. An attacker could bypass security restrictions and cause a denial of service condition. These vulnerabilities affect multiple versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105132
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105198
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105199
16. Security Updates in Oracle Linux (ELSA-2015-1419, ELSA-2015-1471, ELSA-2015-1482, ELSA-2015-1513, ELSA-2015-1514, ELSA-2015-1515, ELSA-2015-3053)
[30/07/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the libxml2, bind, libuser, bind97 and kernel packages for Oracle Linux 5, 6 and 7. Due to multiple errors, an attacker could cause a denial of service condition, gain elevated privileges and crash the system.
URL:linux.oracle.com/errata/ELSA-2015-1419.html
URL:linux.oracle.com/errata/ELSA-2015-1471.html
URL:linux.oracle.com/errata/ELSA-2015-1482.html
URL:linux.oracle.com/errata/ELSA-2015-1513.html
URL:linux.oracle.com/errata/ELSA-2015-1514.html
URL:linux.oracle.com/errata/ELSA-2015-1515.html
URL:linux.oracle.com/errata/ELSA-2015-3053.html
17. Security Updates in Red Hat Gluster Storage (RHSA-2015:1495-1)
[30/07/2015] Red Hat has released security update packages for fixing the vulnerabilities identified in version 3.0 of Red Hat Gluster Storage. Due to multiple errors, an attacker could bypass security restrictions and execute arbitrary code.
URL:rhn.redhat.com/errata/RHSA-2015-1495.html
18. Security Updates in Ubuntu GNU/Linux (USN-2694-1, USN-2695-1)
[30/07/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the PCRE and HTML Tidy packages for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu GNU/Linux. Due to multiple errors, an attacker could crash the system, cause a denial of service condition and execute arbitrary code.
URL:www.ubuntu.com/usn/usn-2694-1/
URL:www.ubuntu.com/usn/usn-2695-1/
19. Vulnerability in BIND (AA-01272)
[29/07/2015] Vulnerability was identified in the BIND. An attacker could bypass security restrictions, cause a denial of service condition and crash the system. This vulnerability affects versions prior to 9.9.7-P2 or 9.10.2-P3 of the mentioned products. Security patches are available to resolve this vulnerability.
URL:kb.isc.org/article/AA-01272
URL:www.us-cert.gov/ncas/current-activity/2015/07/28/Internet-Systems-Consortium-ISC-Releases-Security-Updates-BIND
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105120
20. Vulnerabilities in Cisco Products
[29/07/2015] Vulnerabilities were identified in the Cisco UCS Central Software and Cisco AnyConnect Secure Mobility Client. An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code, cause a denial of service condition and crash the system. These vulnerabilities affect multiple firmware versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40151
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40176
21. Vulnerabilities in F5 Products (SOL16909, SOL16912)
[29/07/2015] Vulnerabilities were identified in the F5 BIG-IP LTM, BIG-IP AAM, BIG-IP AFM, BIG-IP Analytics, BIG-IP APM, BIG-IP ASM, BIG-IP Edge Gateway, BIG-IP GTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP PSM, BIG-IP WebAccelerator, BIG-IP WOM, Enterprise Manager, BIG-IQ Cloud, BIG-IQ Device, BIG-IQ Security and BIG-IQ ADC. An attacker could bypass security restrictions, obtain sensitive information, cause a denial of service condition and crash the system. These vulnerabilities affect multiple versions of the mentioned products. Security patches are available to resolve these vulnerabilities.
URL:support.f5.com/kb/en-us/solutions/public/16000/900/sol16909.html
URL:support.f5.com/kb/en-us/solutions/public/16000/900/sol16912.html
22. Vulnerability in Foxit Reader (105109)
[29/07/2015] Vulnerability was identified in the Foxit Reader. An attacker could bypass security restrictions and execute arbitrary code. This vulnerability affects versions 7.0.8, 7.0.9 and 7.1.5 of the mentioned product.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105109
23. Vulnerabilities in Android Stagefright
[29/07/2015] Vulnerabilities were identified in the Android Stagefright media playback service. An attacker could bypass security restrictions, execute arbitrary code and compromise the system. These vulnerabilities affect firmware versions prior to 5.1.1_r5 of the mentioned products.
URL:www.hkcert.org/my_url/en/alert/15072901
URL:www.kb.cert.org/vuls/id/924951
URL:www.us-cert.gov/ncas/current-activity/2015/07/28/%E2%80%9CStagefright%E2%80%9D-Android-Vulnerability
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105118
24. Security Updates in Oracle Linux (ELSA-2015-1249, ELSA-2015-1254, ELSA-2015-1272, ELSA-2015-1287, ELSA-2015-1330, ELSA-2015-1344, ELSA-2015-1347, ELSA-2015-1378, ELSA-2015-1385, ELSA-2015-1409, ELSA-2015-1417, ELSA-2015-1419, ELSA-2015-1439, ELSA-2015-1447, ELSA-2015-1457, ELSA-2015-1458, ELSA-2015-1459, ELSA-2015-1460, ELSA-2015-1462)
[29/07/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the httpd, curl, kernel, freeradius, python, autofs, pki-core, hivex, net-snmp, sudo, mailman, libxml2, wpa_supplicant, grep, gnutls, libreoffice, ntp, wireshark and ipa packages for Oracle Linux 6. Due to multiple errors, an attacker could bypass security restriction, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:linux.oracle.com/errata/ELSA-2015-1249.html
URL:linux.oracle.com/errata/ELSA-2015-1254.html
URL:linux.oracle.com/errata/ELSA-2015-1272.html
URL:linux.oracle.com/errata/ELSA-2015-1287.html
URL:linux.oracle.com/errata/ELSA-2015-1330.html
URL:linux.oracle.com/errata/ELSA-2015-1344.html
URL:linux.oracle.com/errata/ELSA-2015-1347.html
URL:linux.oracle.com/errata/ELSA-2015-1378.html
URL:linux.oracle.com/errata/ELSA-2015-1385.html
URL:linux.oracle.com/errata/ELSA-2015-1409.html
URL:linux.oracle.com/errata/ELSA-2015-1417.html
URL:linux.oracle.com/errata/ELSA-2015-1419.html
URL:linux.oracle.com/errata/ELSA-2015-1439.html
URL:linux.oracle.com/errata/ELSA-2015-1447.html
URL:linux.oracle.com/errata/ELSA-2015-1457.html
URL:linux.oracle.com/errata/ELSA-2015-1458.html
URL:linux.oracle.com/errata/ELSA-2015-1459.html
URL:linux.oracle.com/errata/ELSA-2015-1460.html
URL:linux.oracle.com/errata/ELSA-2015-1462.html
25. Security Updates in Debian (DSA-3319-1)
[29/07/2015] Debian has released security update packages for fixing the vulnerability identified in the bind9 package for multiple versions of Debian GNU/Linux. An attacker could bypass security restrictions, execute arbitrary code, cause a denial of service condition and crash the system.
URL:www.debian.org/security/2015/dsa-3319
26. Security Updates in FreeBSD (FreeBSD-SA-15:14.bsdpatch, FreeBSD-SA-15:15.tcp, FreeBSD-SA-15:16.openssh, FreeBSD-SA-15:17.bind)
[29/07/2015] FreeBSD has released security update packages for fixing the vulnerability identified in the patch, inet, openssh and bind packages for multiple versions of FreeBSD Linux. Due to multiple errors, an attacker could bypass security restriction, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:14.bsdpatch.asc
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:15.tcp.asc
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:16.openssh.asc
URL:www.freebsd.org/security/advisories/FreeBSD-SA-15:17.bind.asc
27. Security Updates in Mageia (MGASA-2015-0291, MGASA-2015-0292, MGASA-2015-0293, MGASA-2015-0294, MGASA-2015-0295)
[29/07/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the freeradius, ansible, python-django14, python-django, springframework and openssh packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0291.html
URL:advisories.mageia.org/MGASA-2015-0292.html
URL:advisories.mageia.org/MGASA-2015-0293.html
URL:advisories.mageia.org/MGASA-2015-0294.html
URL:advisories.mageia.org/MGASA-2015-0295.html
28. Security Updates in Red Hat Enterprise Linux (RHSA-2015:1512-1, RHSA-2015:1513-1, RHSA-2015:1514-1, RHSA-2015:1515-1)
[29/07/2015] Red Hat has released security update packages for fixing the vulnerabilities identified in the qemu-kvm-rhev, bind and bind97 packages for Red Hat Enterprise Linux OpenStack Platform 5 and 6, Red Hat Enterprise Linux 5, 6 and 7. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:rhn.redhat.com/errata/RHSA-2015-1512.html
URL:rhn.redhat.com/errata/RHSA-2015-1513.html
URL:rhn.redhat.com/errata/RHSA-2015-1514.html
URL:rhn.redhat.com/errata/RHSA-2015-1515.html
29. Security Updates in Slackware (SSA:2015-209-01)
[29/07/2015] Slackware has released security update packages for fixing the vulnerability identified in the bind package for multiple versions of Slackware Linux. An attacker could bypass security restriction, cause a denial of service condition and crash the system.
URL:www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.554472
30. Security Updates in SUSE (SUSE-SU-2015:1302-1, SUSE-SU-2015:1304-1, SUSE-SU-2015:1305-1)
[29/07/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the xen and bind packages of SUSE Linux Enterprise 11 and 12. Due to multiple errors, an attacker could bypass security restrictions, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00042.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00043.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00044.html
31. Security Updates in Ubuntu GNU/Linux (USN-2686-1)
[29/07/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the apache2 package for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, execute arbitrary code and perform HTTP request smuggling attacks.
URL:www.ubuntu.com/usn/usn-2687-1/
URL:www.ubuntu.com/usn/usn-2688-1/
URL:www.ubuntu.com/usn/usn-2689-1/
URL:www.ubuntu.com/usn/usn-2690-1/
URL:www.ubuntu.com/usn/usn-2691-1/
URL:www.ubuntu.com/usn/usn-2692-1/
URL:www.ubuntu.com/usn/usn-2693-1/
32. Vulnerabilities in Microsoft Internet Explorer Mobile
[28/07/2015] Vulnerabilities were identified in the Microsoft Internet Explorer Mobile. An attacker could bypass security restrictions and execute arbitrary code. The affected version was not specified.
URL:www.hkcert.org/my_url/en/alert/15072701
33. Vulnerabilities in Cisco Products
[28/07/2015] Vulnerabilities were identified in the Cisco Firepower 9000 Series devices, Cisco Web Security Appliance (WSA), Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA). An attacker could bypass security restrictions, obtain sensitive information, execute arbitrary code and perform cross-site scripting attacks. These vulnerabilities affect multiple firmware versions of the mentioned products.
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40136
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40172
34. Security Updates in Oracle Linux (ELSA-2015-1507, ELSA-2015-1510)
[28/07/2015] Oracle has released security update packages for fixing the vulnerabilities identified in the qemu-kvm and clutter packages for Oracle Linux 7. Due to multiple errors, an attacker could bypass security restriction, gain elevated privileges and execute arbitrary code.
URL:linux.oracle.com/errata/ELSA-2015-1507.html
URL:linux.oracle.com/errata/ELSA-2015-1510.html
35. Security Updates in Debian (DSA-3316-1, DSA-3318-1)
[28/07/2015] Debian has released security update packages for fixing the vulnerabilities identified in the openjdk-7 and expat package for multiple versions of Debian GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.debian.org/security/2015/dsa-3316
URL:www.debian.org/security/2015/dsa-3318
36. Security Updates in Mageia (MGASA-2015-0279, MGASA-2015-0280, MGASA-2015-0281, MGASA-2015-0282, MGASA-2015-0283, MGASA-2015-0284, MGASA-2015-0285, MGASA-2015-0286, MGASA-2015-0287, MGASA-2015-0288, MGASA-2015-0289, MGASA-2015-0290)
[28/07/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the mariadb, java-1.8.0-openjdk, apache, evolution, wesnoth, thunderbird, thunderbird-l10n, expat, icu, chromium-browser-stable, stunnel and wordpress packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0279.html
URL:advisories.mageia.org/MGASA-2015-0280.html
URL:advisories.mageia.org/MGASA-2015-0281.html
URL:advisories.mageia.org/MGASA-2015-0282.html
URL:advisories.mageia.org/MGASA-2015-0283.html
URL:advisories.mageia.org/MGASA-2015-0284.html
URL:advisories.mageia.org/MGASA-2015-0285.html
URL:advisories.mageia.org/MGASA-2015-0286.html
URL:advisories.mageia.org/MGASA-2015-0287.html
URL:advisories.mageia.org/MGASA-2015-0288.html
URL:advisories.mageia.org/MGASA-2015-0289.html
URL:advisories.mageia.org/MGASA-2015-0290.html
37. Security Updates in Red Hat Enterprise Linux (RHSA-2015:1499-1, RHSA-2015:1507-1, RHSA-2015:1510-1)
[28/07/2015] Red Hat has released security update packages for fixing the vulnerabilities identified in the chromium-browser, qemu-kvm and clutter packages for Red Hat Enterprise Linux 6 and 7. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:rhn.redhat.com/errata/RHSA-2015-1499.html
URL:rhn.redhat.com/errata/RHSA-2015-1507.html
URL:rhn.redhat.com/errata/RHSA-2015-1510.html
38. Security Updates in SUSE (SUSE-SU-2015:1299-1)
[28/07/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the xen package of SUSE Linux Enterprise 11. Due to multiple errors, an attacker could bypass security restrictions, gain elevated privileges, execute arbitrary code, cause a denial of service condition and crash the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00041.html
39. Security Updates in Ubuntu GNU/Linux (USN-2686-1)
[28/07/2015] Ubuntu has released security update packages for fixing the vulnerabilities identified in the apache2 package for versions 12.04 LTS, 14.04 LTS and 15.04 of Ubuntu GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, execute arbitrary code and perform HTTP request smuggling attacks.
URL:www.ubuntu.com/usn/usn-2686-1/
40. Vulnerability in Cisco Products
[27/07/2015] Vulnerability was identified in the Cisco Web Security Appliance (WSA), Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA). An attacker could bypass security restrictions and obtain sensitive information. This vulnerability affects multiple firmware versions of the mentioned products.
URL:tools.cisco.com/security/center/viewAlert.x?alertId=40137
41. Vulnerabilities in Honeywell Tuxedo Touch Controller (VU#857948)
[27/07/2015] Vulnerabilities were identified in the Honeywell Tuxedo Touch Controller. An attacker could bypass security restrictions, execute arbitrary code, perform cross-site request forgery attacks. These vulnerabilities affect firmware versions prior to TUXW_V5.2.19.0_VA of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:www.kb.cert.org/vuls/id/857948
42. Vulnerability in Fiat-Chrysler Automative UConnect (VU#819439)
[27/07/2015] Vulnerability was identified in the Fiat-Chrysler Automative UConnect. An attacker could bypass security restrictions, execute arbitrary code and compromise the system. This vulnerability affects multiple versions of the mentioned product. Security patches are available to resolve this vulnerability.
URL:www.kb.cert.org/vuls/id/819439
43. Vulnerability in Ghostscript (105033)
[27/07/2015] Vulnerability was identified in the Ghostscript. An attacker could bypass security restrictions and execute arbitrary code. This vulnerability affects version 9.16 of the mentioned product. Security patches are available to resolve this vulnerability.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105033
44. Vulnerabilities in libuser (105022, 105023)
[27/07/2015] Vulnerabilities were identified in the libuser. An attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system. These vulnerabilities affect versions prior to 0.62 of the mentioned product. Security patches are available to resolve these vulnerabilities.
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105022
URL:exchange.xforce.ibmcloud.com/vulnerabilities/105023
45. Security Updates in Debian (DSA-3315-1, DSA-3317-1)
[27/07/2015] Debian has released security update packages for fixing the vulnerabilities identified in the chromium-browser and lxc package for multiple versions of Debian GNU/Linux. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:www.debian.org/security/2015/dsa-3315
URL:www.debian.org/security/2015/dsa-3317
46. Security Updates in Mageia (MGASA-2015-0278)
[27/07/2015] Mageia has released security update packages for fixing the vulnerabilities identified in the libuser packages for multiple versions of Mageia. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:advisories.mageia.org/MGASA-2015-0278.html
47. Security Updates in SUSE (openSUSE-SU-2015:1287-1, openSUSE-SU-2015:1288-1, openSUSE-SU-2015:1289-1)
[27/07/2015] SUSE has released security update packages for fixing the vulnerabilities identified in the Chromium, java-1_7_0-openjdk and java-1_8_0-openjdk package of openSUSE 13.1 and 13.2. Due to multiple errors, an attacker could bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, cause a denial of service condition and compromise the system.
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00038.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.html
URL:lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.html
Subscribe to:
Posts (Atom)