Security
Don't Panic about "going dark"
The rising use of encrypted communication channels, coupled with more system-wide encryption on devices like phones, has been increasingly fingered by law enforcement and other government agencies as an impediment to doing their jobs. This is the so-called "going dark" problem that posits that the ability to thwart terrorism and other crimes is slowly being reduced because these organizations can't see inside the encrypted data—even if they have obtained the legal authority to do so. A recent report [PDF] from a panel of security experts frames the debate a bit differently, as its title ("Don't Panic") might indicate.
The report comes from a "a diverse group of security and policy
experts from
academia, civil society, and the U.S. intelligence community
" under
the auspices of the Berkman Center for Internet & Society at Harvard
University. The group was convened by Matt Olsen, Bruce Schneier, and
Jonathan
Zittrain. The latter two are reasonably well-known in our communities;
Olsen is former director of the US National Counterterrorism Center (NCTC) and
former general counsel to the US National Security Agency (NSA). The
report and its conclusions were endorsed by the private sector participants
(including Olsen),
but the government officials "are precluded from
signing on
because of their employment
"; they were simply thanked for
participating in the discussions over the last year.
The "going dark" argument has been used to bolster the idea of encryption backdoors that can "only" be used by properly authorized law enforcement or national security agencies. The idea is as appealing as it is impossible, but debunking it is not really the thrust of the report. Instead, it looks at the reality of the computing landscape and concludes, rather ironically, that various factors will increase, not decrease, the ability to do surveillance.
The "findings" section (pages five and six of the PDF) is kind of
eye-opening. For
one thing, end-to-end encryption is "unlikely to be adopted ubiquitously by companies, because the majority of businesses that
provide communications services
rely on access to user data for revenue streams and
product functionality
", it states. In addition, the "Internet of
Things" (IoT) will provide many more avenues for surveillance through
sensors, audio, video, and the like.
Beyond that, metadata (e.g. email headers, phone and SMS call records, or
location information) is typically not encrypted and is unlikely to be
encrypted anytime soon. "This information provides an enormous amount
of surveillance data that was
unavailable before these systems became widespread.
" The report
points to fragmentation in the software ecosystem as another reason not to
panic about going dark. In fact, the report questions the metaphor itself:
From a security and privacy standpoint, the findings are worrisome, as the report acknowledges. The hope that more and better-integrated encryption will lead to better privacy seems to be dashed by the realities of the market. Companies will still want to track users and their data so they can use (or abuse) that information—or sell it to others. New devices will roll out with insufficient security and privacy safeguards that will spill our secrets left and right. While the report may provide some solace for the agencies that are concerned about going dark, it can only be viewed with some sadness by privacy and security advocates.
The moderately lengthy report provides some background on the debate, including its roots in the "crypto wars" of the 1990s (and earlier). It also gives more detail on the bullet points in the findings section. It builds a fairly strong case that companies and fragmentation in the market will lead to less encryption or, at least, less encryption where the users hold the only keys.
The IoT will likely bring a whole new range of surveillance options. There are several examples given of existing devices (automobile assistance systems with in-car microphones, smart TVs, wireless cameras, even the "OK Google" feature in the Chrome browser) that have the potential to be used for surveillance. Court orders could be used to force those companies to arrange for law enforcement to use these products for surveillance. While the report doesn't directly address it, there is the risk that organizations or individuals could exploit security vulnerabilities in the devices to do the same—with no court order required.
There are also three "individual statements from signatories" attached as Appendix A (page 19), which offer some additional perspectives. Susan Landau focused on the "business case" for encryption:
Schneier pointed out that there are multiple uses for encryption, from protecting credit card numbers to helping dissidents avoid arrest to journalists communicating with sources, all of which are worth protecting—and protecting well.
[...] We’re not being asked to choose between security and privacy. We’re being asked to choose between less security and more security.
He also reprises another common theme in his writing:
In his statement, Zittrain reiterates the avenues that are being opened up by new technology:
As can be seen, the report is a bit bleak, at least for privacy advocates, but it does paint a realistic picture of where we are today—and where we are likely to be in the near future. There are few, if any, who are arguing that there are no circumstances that should allow government access to private data. But there is a balance to be struck and, at least rhetorically, politicians generally seem to want to magically legislate around the realities of encryption, instead of recognizing the limits of their power. As this report shows, the sky is not falling: law enforcement can get most of what it needs without endangering the real, important uses of encryption. Hopefully the politicians are listening.
Brief items
Security quotes of the week
Congress will be forced to act. They might authorize more surveillance. They might authorize more government involvement in private-sector cybersecurity. They might try to ban certain technologies or certain uses. The results won't be well-thought-out, and they probably won't mitigate the actual risks. If we're lucky, they won't cause even more problems.
NSA Hacker Chief Explains How to Keep Him Out of Your System (Wired)
Wired reports on a talk at the USENIX Enigma conference by Rob Joyce of the US National Security Agency (NSA). Joyce is the head of the NSA's Tailored Access Operations, which is tasked with breaking into the systems of adversaries and sometimes allies. He spoke about ways to thwart the NSA and other nation-state-level attackers. "'We put the time in …to know [that network] better than the people who designed it and the people who are securing it,' he said. 'You know the technologies you intended to use in that network. We know the technologies that are actually in use in that network. Subtle difference. You'd be surprised about the things that are running on a network vs. the things that you think are supposed to be there.'"
Fifteen years of SELinux
This Red Hat blog post celebrates the fifteenth anniversary of the first SELinux release. "With the question of open source security long behind us, we are now focused on providing an even more flexible security model through SELinux. With the rise of composite, distributed applications that can span hundreds of physical and virtual machines as well as disparate cloud instances and Linux container deployments, one-off usage of SELinux is not enough. Instead, we are focused on providing “defense in depth” for modern computing scenarios, effectively building and deploying SELinux policies at each level of the datacenter."
New vulnerabilities
gosa: code injection
| Package(s): | gosa | CVE #(s): | CVE-2015-8771 | ||||||||
| Created: | February 1, 2016 | Updated: | July 26, 2016 | ||||||||
| Description: | From the Debian LTS advisory:
GOsa upstream reported a code injection vulnerability in the Samba plugin code of GOsa. During Samba password changes it has been possible to inject malicious Perl code. | ||||||||||
| Alerts: |
| ||||||||||
java: information leak
| Package(s): | java-1.6.0-ibm | CVE #(s): | CVE-2015-5041 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | February 2, 2016 | Updated: | February 3, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Red Hat bugzilla:
A flaw in the IBM J9 JVM allows code to invoke non-public interface methods under certain circumstances. Untrusted code could potentially exploit this. This could lead to sensitive data being exposed to an attacker, or the attacker being able to inject bad data. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||
kernel: information leak
| Package(s): | kernel | CVE #(s): | CVE-2015-4004 | ||||||||||||||||||||||||||||||||
| Created: | February 1, 2016 | Updated: | February 3, 2016 | ||||||||||||||||||||||||||||||||
| Description: | From the CVE entry:
The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via a crafted packet. | ||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||
kernel: NULL pointer dereference
| Package(s): | kernel | CVE #(s): | CVE-2015-8787 | ||||||||||||||||||||||||||||||||||||||||||||
| Created: | February 1, 2016 | Updated: | February 3, 2016 | ||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Red Hat bugzilla:
Kernel NULL pointer dereference vulnerability was found in netfilter/nf_nat_redirect.c in nf_nat_redirect_ipv4 function introduced by commit 8b13eddfdf04cbfa561725cfc42d6868fe896f56 ("netfilter: refactor NAT redirect IPv4 to use it from nf_tables"). | ||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||
kernel: denial of service
| Package(s): | kernel | CVE #(s): | CVE-2015-8785 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | February 2, 2016 | Updated: | February 3, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Ubuntu advisory:
It was discovered that the Linux kernel's Filesystem in Userspace (FUSE) implementation did not handle initial zero length segments properly. A local attacker could use this to cause a denial of service (unkillable task). | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
kernel: memory leak
| Package(s): | kernel | CVE #(s): | CVE-2016-0774 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | February 3, 2016 | Updated: | April 12, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Red Hat advisory:
It was found that the fix for CVE-2015-1805 incorrectly kept buffer offset and buffer length in sync on a failed atomic read, potentially resulting in a pipe buffer state corruption. A local, unprivileged user could use this flaw to crash the system or leak kernel memory to user space. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
krb5: information leak
| Package(s): | krb5 | CVE #(s): | |||||
| Created: | January 29, 2016 | Updated: | February 3, 2016 | ||||
| Description: | From the Fedora advisory: krb5kdc.log file is world-readable by default. | ||||||
| Alerts: |
| ||||||
krb5: three vulnerabilities
| Package(s): | krb5 | CVE #(s): | CVE-2015-8629 CVE-2015-8630 CVE-2015-8631 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | February 1, 2016 | Updated: | April 4, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Mageia advisory:
In all versions of MIT krb5, an authenticated attacker can cause kadmind to read beyond the end of allocated memory by sending a string without a terminating zero byte. Information leakage may be possible for an attacker with permission to modify the database (CVE-2015-8629). In MIT krb5 1.12 and later, an authenticated attacker with permission to modify a principal entry can cause kadmind to dereference a null pointer by supplying a null policy value but including KADM5_POLICY in the mask (CVE-2015-8630). In all versions of MIT krb5, an authenticated attacker can cause kadmind to leak memory by supplying a null principal name in a request which uses one. Repeating these requests will eventually cause kadmind to exhaust all available memory (CVE-2015-8631). | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
nettle: improper cryptographic calculations
| Package(s): | nettle lib32-nettle | CVE #(s): | CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | February 3, 2016 | Updated: | June 2, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Arch Linux advisory:
It has been discovered that multiple carry propagation bugs are producing wrong results in calculations. They affect the NIST P-256 and P-384 curves. The P-256 bug is in the C code and affects multiple architectures. The P-384 bug is in the assembly code and only affects 64 bit x86. The computation compiles a certain curve point with 1, which should not change the coordinates, however it does. The impact is currently unclear, but miscalculations in cryptographic functions are classified as security issues. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
nginx: two denial of service flaws
| Package(s): | nginx | CVE #(s): | CVE-2016-0746 CVE-2016-0747 | ||||||||||||||||||||||||||||||||||||
| Created: | January 28, 2016 | Updated: | February 3, 2016 | ||||||||||||||||||||||||||||||||||||
| Description: | From the Arch Linux advisory:
CVE-2016-0746 (denial of service): Use-after-free condition might occur during CNAME response processing if the "resolver" directive was used, allowing an attacker who is able to trigger name resolution to cause segmentation fault in a worker process, or might have potential other impact. CVE-2016-0747 (denial of service): CNAME resolution was insufficiently limited if the "resolver" directive was used, allowing an attacker who is able to trigger arbitrary name resolution to cause excessive resource consumption in worker processes. | ||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||
ntp: multiple vulnerabilities
| Package(s): | ntp | CVE #(s): | CVE-2015-7974 CVE-2015-7977 CVE-2015-7978 CVE-2015-7979 CVE-2015-8158 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | January 29, 2016 | Updated: | November 11, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Mageia advisory: CVE-2015-7974: In ntpd before 4.2.8p6, when used with symmetric key encryption, the client would accept packets encrypted with keys for any configured server, allowing a server to impersonate other servers to clients, thus performing a man-in-the-middle attack. A server can be attacked by a client in a similar manner. CVE-2015-7977: A NULL pointer dereference flaw was found in the way ntpd processed 'ntpdc reslist' commands that queried restriction lists with a large amount of entries. A remote attacker could use this flaw to crash the ntpd process. CVE-2015-7978: A stack-based buffer overflow was found in the way ntpd processed 'ntpdc reslist' commands that queried restriction lists with a large amount of entries. A remote attacker could use this flaw to crash the ntpd process. CVE-2015-7979: It was found that when NTP is configured in broadcast mode, an off-path attacker could broadcast packets with bad authentication (wrong key, mismatched key, incorrect MAC, etc) to all clients. The clients, upon receiving the malformed packets, would break the association with the broadcast server. This could cause the time on affected clients to become out of sync over a longer period of time. CVE-2015-8158: A flaw was found in the way the ntpq client certain processed incoming packets in a loop in the getresponse() function. A remote attacker could potentially use this flaw to crash an ntpq client instance. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
openssl: multiple vulnerabilities
| Package(s): | openssl | CVE #(s): | CVE-2015-3197 CVE-2016-0701 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | January 29, 2016 | Updated: | March 1, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Arch Linux advisory: CVE-2015-3197: A flaw was found in the way malicious SSL/TLS clients could negotiate SSLv2 ciphers that have been disabled on the server. This could result in weak SSLv2 ciphers being used for SSL/TLS connections, making them vulnerable to man-in-the-middle attacks. CVE-2016-0701: It was found that OpenSSL used weak Diffie-Hellman parameters based on unsafe primes, which were generated and stored in X9.42-style parameter files. An attacker who could force the peer to perform multiple handshakes using the same private DH component could use this flaw to conduct man-in-the-middle attacks on the SSL/TLS connection. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
openstack-heat: denial of service
| Package(s): | openstack-heat | CVE #(s): | CVE-2015-5295 | ||||||||||||||||||||
| Created: | February 3, 2016 | Updated: | March 14, 2016 | ||||||||||||||||||||
| Description: | From the CVE entry:
The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero. | ||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||
openstack-swift: denial of service
| Package(s): | openstack-swift | CVE #(s): | CVE-2016-0738 | ||||||||||||||||||||
| Created: | February 3, 2016 | Updated: | February 8, 2016 | ||||||||||||||||||||
| Description: | From the CVE entry:
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL. | ||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||
owncloud: multiple vulnerabilities
| Package(s): | owncloud | CVE #(s): | CVE-2016-1498 CVE-2016-1499 CVE-2016-1500 CVE-2015-1499 | ||||
| Created: | January 29, 2016 | Updated: | February 3, 2016 | ||||
| Description: | From the Mageia advisory: A Cross-site scripting (XSS) vulnerability in the OCS discovery provider in ownCloud Server before 8.0.10 allows remote attackers to inject arbitrary web script or HTML via the URL resulting in a reflected Cross-Site-Scripting (CVE-2016-1498). ownCloud Server before 8.0.10 allows remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption) via the force parameter to index.php/apps/files/ajax/scan.php (CVE-2015-1499). ownCloud Server before 8.0.10, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share (CVE-2016-1500). | ||||||
| Alerts: |
| ||||||
phpmyadmin: two vulnerabilities
| Package(s): | phpmyadmin | CVE #(s): | CVE-2016-2039 CVE-2016-2041 | ||||||||||||||||||||||||||||||||||||
| Created: | February 1, 2016 | Updated: | February 3, 2016 | ||||||||||||||||||||||||||||||||||||
| Description: | From the
Several flaws were discovered in the CSRF authentication code of phpMyAdmin. CVE-2016-2039: The XSRF/CSRF token is generated with a weak algorithm using functions that do not return cryptographically secure values. CVE-2016-2041: The comparison of the XSRF/CSRF token parameter with the value saved in the session is vulnerable to timing attacks. Moreover, the comparison could be bypassed if the XSRF/CSRF token matches a particular pattern. | ||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||
phpmyadmin: multiple vulnerabilities
| Package(s): | phpmyadmin | CVE #(s): | CVE-2016-2038 CVE-2016-2040 CVE-2016-1927 CVE-2016-2042 CVE-2016-2043 CVE-2016-2044 CVE-2016-2045 | ||||||||||||||||||||||||||||||||
| Created: | February 1, 2016 | Updated: | February 3, 2016 | ||||||||||||||||||||||||||||||||
| Description: | From the Red Hat bugzilla:
CVE-2016-2038: By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed.
CVE-2016-2040:
* With a crafted table name it is possible to trigger an XSS attack in
the database search page. CVE-2016-1927: Password suggestion functionality uses Math.random() which does not provide cryptographically secure random numbers. CVE-2016-2042: By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. CVE-2016-2043: With a crafted table name it is possible to trigger an XSS attack in the database normalization page. CVE-2016-2044: By calling a particular script that is part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. CVE-2016-2045: With a crafted SQL query, it is possible to trigger an XSS attack in the SQL editor. | ||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||
prosody: insecure handling of dialback keys
| Package(s): | prosody | CVE #(s): | CVE-2016-0756 | ||||||||||||||||
| Created: | February 1, 2016 | Updated: | February 8, 2016 | ||||||||||||||||
| Description: | From the Debian advisory:
It was discovered that insecure handling of dialback keys may allow a malicious XMPP server to impersonate another server. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
python-django: permission bypass
| Package(s): | python-django | CVE #(s): | CVE-2016-2048 | ||||||||
| Created: | February 2, 2016 | Updated: | February 3, 2016 | ||||||||
| Description: | From the Arch Linux advisory:
If a ModelAdmin uses save_as=True (not the default), the admin provides an option when editing objects to "Save as new". A regression in Django 1.9 prevented that form submission from raising a "Permission Denied" error for users without the "add" permission. A remote attacker with django User account and change permissions but not "add" might be able to create objects for ModelAdmin with save=True. | ||||||||||
| Alerts: |
| ||||||||||
qemu: multiple vulnerabilities
| Package(s): | qemu, qemu-kvm | CVE #(s): | CVE-2016-1981 CVE-2016-2197 CVE-2016-2198 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | February 3, 2016 | Updated: | November 11, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Ubuntu advisory:
It was discovered that QEMU incorrectly handled the e1000 device. An attacker inside the guest could use this issue to cause QEMU to crash, resulting in a denial of service. (CVE-2016-1981) Zuozhi Fzz discovered that QEMU incorrectly handled IDE AHCI emulation. An attacker inside the guest could use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 15.10. (CVE-2016-2197) Zuozhi Fzz discovered that QEMU incorrectly handled USB EHCI emulation. An attacker inside the guest could use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2016-2198) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
rails: multiple vulnerabilities
| Package(s): | rails | CVE #(s): | CVE-2015-7576 CVE-2015-7577 CVE-2015-7581 CVE-2016-0751 CVE-2016-0752 CVE-2016-0753 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | February 1, 2016 | Updated: | October 3, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Debian advisory:
Multiple security issues have been discovered in the Rails on Rails web application development framework, which may result in denial of service, cross-site scripting, information disclosure or bypass of input validation. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
tiff: multiple vulnerabilities
| Package(s): | tiff | CVE #(s): | CVE-2015-8781 CVE-2015-8782 CVE-2015-8783 CVE-2015-8784 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | February 1, 2016 | Updated: | February 11, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Debian LTS advisory:
Several security flaws have been found and solved in libtiff, a library that provides support for handling Tag Image File Format (TIFF). These flaws concern out of bounds reads and writes in the LogL16Decode, LogLuvDecode24, LogLuvDecode32, LogLuvDecodeTile, LogL16Encode, LogLuvEncode24, LogLuvEncode32 and NeXTDecode functions. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
webkitgtk4: multiple vulnerabilities
xen: multiple vulnerabilities
| Package(s): | xen | CVE #(s): | CVE-2016-1570 CVE-2016-1571 | ||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | January 29, 2016 | Updated: | February 3, 2016 | ||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the CVE entries: CVE-2016-1570: The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or have unspecified other impact via a crafted page identifier (MFN) to the (1) MMUEXT_MARK_SUPER or (2) MMUEXT_UNMARK_SUPER sub-op in the HYPERVISOR_mmuext_op hypercall or (3) unknown vectors related to page table updates.. CVE-2016-1571: The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check. | ||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||
Page editor: Jake Edge
Next page:
Kernel development>>
