cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system. cPanel has rated these updates as having security impact levels ranging from …
Posts Tagged security
Red Hat: 2013:1447-01: java-1.7.0-openjdk: Important Advisory
(Oct 21) Updated java-1.7.0-openjdk packages that fix various security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having [More…]
Debian: 2780-1: mysql-5.1: Multiple vulnerabilities
(Oct 18) This DSA updates the MySQL database to 5.1.72. This fixes multiple unspecified security problems in the Optimizer component: http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html [More…]
Red Hat: 2013:1440-01: java-1.7.0-oracle: Critical Advisory
(Oct 17) Updated java-1.7.0-oracle packages that fix several security issues are now available for Red Hat Enterprise Linux 5 and 6 Supplementary. The Red Hat Security Response Team has rated this update as having critical [More…]
Red Hat: 2013:1441-01: rubygems: Moderate Advisory
(Oct 17) An updated rubygems package that fixes three security issues is now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More…]
Red Hat: 2013:1436-01: kernel: Moderate Advisory
(Oct 16) Updated kernel packages that fix two security issues and several bugs are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More…]
Red Hat: 2013:1426-01: xorg-x11-server: Important Advisory
(Oct 15) Updated xorg-x11-server packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having [More…]
US Government aiding spying… against itself
Partly as a consequence of the US Government shutdown, there are presently more than two hundred .gov websites using expired SSL certificates. Although the shutdown is expected to be a short term measure, the widespread use of expired certificates on .gov sites may cause long term harm. The US Government is effectively training its citizens […]
Red Hat: 2013:1418-01: libtar: Moderate Advisory
(Oct 10) An updated libtar package that fixes one security issue is now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More…]
Debian: 2771-1: nas: Multiple vulnerabilities
(Oct 9) Hamid Zamani discovered multiple security problems (buffer overflows, format string vulnerabilities and missing input sanitising), which could lead to the execution of arbitrary code. [More…]
Red Hat: 2013:1411-01: glibc: Moderate Advisory
(Oct 8) Updated glibc packages that fix one security issue and one bug are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More…]
Red Hat: 2013:1409-01: xinetd: Moderate Advisory
(Oct 7) An updated xinetd package that fixes one security issue is now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate [More…]
Phishing sites hosted in the cloud are providing fraudsters with the benefits of high availability and good performance. Additionally, some cloud-hosted phishing sites are using “flexible” SSL to boost their credibility, even though the data submitted by the victim may not actually be encrypted for the whole length of its journey.
Red Hat: 2013:1310-01: samba3x: Moderate Advisory
(Sep 30) Updated samba3x packages that fix multiple security issues and several bugs are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More…]
Red Hat: 2013:1302-01: xinetd: Low Advisory
(Sep 30) An updated xinetd package that fixes one security issue and two bugs is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having low [More…]
Red Hat: 2013:1319-01: sssd: Low Advisory
(Sep 30) Updated sssd packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having low [More…]
Red Hat: 2013:1307-01: php53: Moderate Advisory
(Sep 30) Updated php53 packages that fix multiple security issues, several bugs, and add one enhancement are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More…]
Red Hat: 2013:1353-01: sudo: Low Advisory
(Sep 30) An updated sudo package that fixes multiple security issues and several bugs is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having low [More…]
Red Hat: 2013:1323-01: ccid: Low Advisory
(Sep 30) An updated ccid package that fixes one security issue and one bug is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having low [More…]
President Obama forgets to renew SSL certificate
At the start of the first US Government shutdown since 1996, an SSL certificate used on barackobama.com has expired. Issued by Go Daddy in September 2012, the SSL certificate for *.barackobama.com and barackobama.com was used by Organizing for Action, a non-profit grassroots organisation aligned with Obama’s political policies. Whilst not directly associated with the US […]
Red Hat: 2013:1292-01: kernel: Moderate Advisory
(Sep 26) Updated kernel packages that fix multiple security issues and several bugs are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More…]
Red Hat: 2013:1282-01: rtkit: Important Advisory
(Sep 24) An updated rtkit package that fixes one security issue is now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having [More…]
Red Hat: 2013:1283-01: puppet: Moderate Advisory
(Sep 24) Updated puppet packages that fix several security issues are now available for Red Hat OpenStack 3.0. The Red Hat Security Response Team has rated this update as having moderate [More…]
IMPORTANT: cPanel Security Notice 2013-09-25: WordPress 3.6.1
SUMMARY Three CVEs were reported for WordPress 3.6 and WordPress has released an upgraded version to address theses vulnerabilities. cPanel has updated the WordPress version delivered via the cPAddons functionality in WHM to the new version of 3.6.1. AFFECTED VERSIONS All versions of WordPress 3.6.0 and below. SECURITY RATING US-CERT/NIST …
Wildcard EV certificates supported by major browsers
Extended Validation, or EV, certificates are designed to provide evidence of a greater level of verification by the Certificate Authority of the legal identity of the company in control of the SSL certificate and domain name. By way of contrast, the most common type of certificate, domain-validated, only requires the CA to verify control of […]
Red Hat: 2013:1285-01: openstack-keystone: Moderate Advisory
(Sep 25) Updated openstack-keystone packages that fix one security issue are now available for Red Hat OpenStack 3.0. The Red Hat Security Response Team has rated this update as having moderate [More…]
Red Hat: 2013:1284-01: ruby193-puppet: Critical Advisory
(Sep 24) Updated ruby193-puppet packages that fix three security issues are now available for Red Hat OpenStack 3.0. The Red Hat Security Response Team has rated this update as having critical [More…]
Certificate Authorities struggle to comply with Baseline Requirements
SSL Certificate Authorities (CAs) are responsible for issuing the SSL certificates which are used to protect billions of secure transactions across the internet against eavesdroppers and impersonators. The CA/B forum — a group of CAs and browser vendors — drew up the Baseline Requirements in 2011 outlining a set of minimum standards to which all […]
Red Hat: 2013:1270-01: polkit: Important Advisory
(Sep 19) Updated polkit packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having [More…]
Red Hat: 2013:1272-01: libvirt: Important Advisory
(Sep 19) Updated libvirt packages that fix two security issues and several bugs are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having [More…]