Tuesday's

CentOS has updated C5: kernel(two privilege escalation vulnerabilities).

Debian has updated kernel (multiplevulnerabilities).

Fedora has updated xerces-c27 (F10,F11: stack consumption vulnerability),xerces-c (F10, F11: stack consumption vulnerability),ctorrent (F10, F11: buffer overflow).

Mandriva has updated davfs (denialof service), libneon (man in the middleattack).

rPath has updated python (arbitrarycode execution), apr-util (memoryconsumption), curl (null prefixvulnerability).

Ubuntu has updated kdelibs (multiplevulnerabilities), kdegraphics (multiplevulnerabilities), php5 (remote denial ofservice), libvorbis (denial of service).

More: continued here

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Netvouz
  • DZone
  • ThisNext
  • MisterWong
  • Wists
  • Technorati

Related News


  • An IT Admin’s Dream Come True: The Promise of Desktop Virtualization


  • Join MokaFive co-founder and CTO, John Whaley, as he discusses desktop virtualization as a potential dream-come-true for IT administrators faced with demanding users and impending disasters. Whaley will cover how desktop virtualization provides solutions to accommodate a mobile workforce including secure remote access, ability to work online or offline, running complete operating systems and applications off a USB flash drive or iPod, and centrally-managed updates delivered simultaneously. Whaley will also talk about key security benefits to building and deploying virtual desktops including malware immunity, backing up to the cloud and automatic rejuvenation.read more


  • News to know: iPhone OS 3.0; Text messaging; Social search; Morro; Palm


  • Here are today s notable headlines. You can get News To Know via email alert and RSS daily. For continuous updates see BNET s around-the-Web tech coverage. Mary Jo Foley: Former Softie to take real-time social-search startup public Matthew Miller: iPhone OS 3.0 update fails connecting to cellular data network What can you expect with the iPhone OS 3.0 update? Ryan Naraine: Apple iPhone OS 3.0 update plugs 46 security holes New iPhone 3.0 OS available Sam Diaz: Can MLB.com hit an iPhone homerun with AT&T powering the network? Jason O'Grady: Some pre-ordered iPhone 3GS' delayed Walt Mossberg: New iPhone Is Better Model Or Just Get OS 3.0 Microsoft to scale back Soapbox video service Washington digs in on text message pricing; asks about carrier exclusivity Richard Koman: Genachowski sails through FCC confirmation hearings Tom Steinert-Threlkeld: ...


  • SMS


  • By Michael SantoEditor-in-Chief, RealTechNewsThe Black Hat conference is an annual security get-together that frequently demos newly exposed security holes. And boy, this iPhone SMS hack is a doozy.Cybersecurity researcher Charlie Miller and his fellow researcher Collin Mulliner plan to present research on a huge iPhone security hole. Thursday at the Black Hat cybersecurity conference [...]


  • Social


  • The results of Bringing Social Security to the Online Community poll were released today, highlighting the vulnerabilities and concerns of social community members around cyber security and the precautions that they are taking or need to take to protect themselves. The online survey conducted by AVG and the CMO Council reveals that while the social networking community has serious concerns about the overall security of public spaces, few are taking the most basic of steps to protect themselves against online crimes. read more


  • Third Party Integrations Should Be An Integral Part of Product Plans


  • Security requirements of enterprises are varied, and contrary to the one-stop-shop movement, enterprises still buy security products from multiple vendors. While some enterprises do it as a part of an IT plan, most companies end-up with disparate products due to niche needs, acquisitions, etc. In this environment of multiple security products, the customer is typically left holding the ‘integrator bag’. Most security products do not interoperate or integrate with others in the infrastructure, leading to operational nightmares, and may undermine the very problem they are trying to solve by creating security gaps.All security companies, big and small, need to realize that they are neither the first, nor will they be the last security product in the customer environment, and make an earnest effort to use standards-based or published APIs to integrate and interoperate with other security and infrastructure solutions. (Also read recent blog “Security Teams Must Take Control of Virtual Networks.”)Initially at Altor Networks our own product features dominated the product plan. As we spoke with customers, we realized that the integrations they requested to address current pain would add tremendous value to both our own and our partners’ products. The first integration we brought to market was the ability to extend the hardware IDP solution into the virtualized server environment. This benefited the customer in many ways – a) leverage customers’ current investment in IDS systems, b) avoid bogging-down the virtual server with a resource-intensive IDS operation that slows down virtualized applications, c) re-gain visibility into the virtual switching layer that they lost with virtualization, d) ensure there are no security gaps since all intrusion detection and subsequent action work-flow operated seamlessly, e) bring virtualized applications back into compliance.Building upon the success of the IDS integration, we added further integration points such as Netflow (Juniper (NASDAQ: JNPR), Riverbed (NASDAQ: RVBD) , NetQoS, and Q1 Labs) and Syslog export to deliver a comprehensive, centralized, view of the data center (Juniper, ArcSight (NASDAQ: ARST), and Q1 Labs).In today’s climate of aggressive product schedules and diminishing resources, companies that include 3rd Party Integrations as part of their product plan ensure long-term value for their customers' success by supporting a vision for cohesive security solutions.read more


    Leave a Reply

    You must be logged in to post a comment.