IT Security
It Security need to be address by today organizations. This should start from the top down but in most cases IT Security start from the bottom and in most cases never reach the top. The blog on IT Security are to help everyone better...
It Security need to be address by today organizations. This should start from the top down but in most cases IT Security start from the bottom and in most cases never reach the top. The blog on IT Security are to help everyone better understand how knowledge of the subject. The bad guys are working hard to gain access to your network and/or computer, we need to work at keeping them out.
Symantec has released yet another security update for several of its Altiris resource management products to patch a critical vulnerability that could allow an attacker to execute arbitrary code
More perspectives...
From heise-security.co.uk
()
CentOS has updated kdelibs (C4:
arbitrary code execution).
Debian has updated libvorbis
(arbitrary code execution).
Fedora has updated php-pear-Net-Ping (F10, F11, F12: arbitrary code execution) and
php-pear-Net-Traceroute (F10, F11, F12:
arbitrary code execution).
Gentoo has updated uw-imap (multiple
vulnerabilities), dstat (arbitrary code
execution), and wireshark (multiple
vulnerabilities).
Red Hat has updated kdelibs (RHEL 4...
From lwn.net
()
- Monday's security advisories (lwn.net)
- Security advisories for Monday (lwn.net)
- Security advisories for Friday (lwn.net)
From the 'Mission Accomplished?' files:For more than a year now I've heard lots of people in the Internet industry proclaiming DNSSEC (DNS Security Extensions) as the long-term solution to DNS cache poisoning vulnerabilities.That may not necessarily be the case....
From blog.internetnews.com
()
- DNSSEC Implemetation Held Up By Tech Delays (rss.slashdot.org)
- DNSSEC Implementation Held Up By Tech Delays (rss.slashdot.org)
Phil Muncaster, V3.co.uk, Thursday 26 November 2009 at 12:27:00 New malware could spell trouble for users of IP telephony service Security experts have warned Skype users that new malware similar to the infamous Koobface worm that caused havoc on Facebook is now targeting the popular IP telephony service....
More perspectives...
From vnunet.com
()
LinuxSecurity.com:
Maksymilian Arciemowicz discovered that PHP did not properly validate
arguments to the dba_replace function. If a script passed untrusted input
to the dba_replace function, an attacker could truncate the database. This
issue only applied to Ubuntu 6.06 LTS, 8.04 LTS, and 8.10. (CVE-2008-7068)
It was discovered that PHP's php_openssl_apply_verification_policy
function did not correctly handle SSL certificates with zero bytes...
More perspectives...
From linuxsecurity.com
()
A hacker recently demonstrated how a SQL injection vulnerability in a Symantec Website could be exploited to reveal user data. Symantec says the vulnerability ony impacts customers in Japan and South Korea. - A Website operated by security firm Symantec was hacked giving an attacker a sneak peak at sensitive customer data.
The Romanian hacker known as Unu, who earlier this year uncovered a hole in a Website run by Kaspersky Lab, exploited...
From eweek.com
()
- Internet Explorer New Attack Codes Released By Hackers (trendsupdates.com)
LinuxSecurity.com:
It was discovered that libvorbis did not correctly handle ogg files with
underpopulated Huffman trees. If a user were tricked into opening a
specially crafted ogg file with an application that uses libvorbis, an
attacker could cause a denial of service. (CVE-2008-2009)
It was discovered that libvorbis did not correctly handle certain malformed
ogg files. If a user were tricked into opening a specially crafted ogg file
with...
From linuxsecurity.com
()
- Ubuntu: Qt vulnerabilities (linuxsecurity.com)


