| The 20 best iPhone/iPad games of 2012 so far | Cisco: Global 'Net traffic to surpass 1 zettabyte in 2016 | ||||||||||
| Network World Daily News AM | ||||||||||
The Flame Virus: Your FAQs Answered WHITE PAPER: Quest Software Effectively Manage IT Compliance IT compliance is mandatory for your business but it doesn't have to be difficult, and when properly controlled is a boon for your company. In this four-part eBook, see how the many parts of IT compliance can be effectively managed throughout the business. Read Now! In this Issue
WHITE PAPER: Silver Peak Systems, Inc. 2012 WAN Optimization Magic Quadrant Limited bandwidth, long distances and poor network quality prohibit cost reductions for today's critical IT initiatives. Your IT organization needs WAN optimization that can be deployed anywhere, on any platform, and for the lowest cost. See how the new Gartner Magic Quadrant for WAN Optimization Controllers can help. Read now. The 20 best iPhone/iPad games of 2012 so far Cisco: Global 'Net traffic to surpass 1 zettabyte in 2016 10 Mobile Device Management Apps to Take Charge of BYOD WHITE PAPER: Quest Software Want to Make Compliance Easy? Get Proactive! Is your business reactively implementing compliance? If so, you're wasting time and money and destroying productivity. Get proactive! Read now! DMARC helps protect reputation of American Greetings' e-cards Mobile payments still slow to catch on in U.S. NSA security expert worries about mobility, cloud WEBCAST: IBM Delivery Management -- Extending Lifecycle Management Date: Wednesday, June 20, 2012, 1:00 PM EDT Hear from application lifecycle management experts how to increase delivery efficiency and effectiveness with a new approach to Delivery Management. Register Now Chrome to take world's top browser spot for May 10 keys for building private clouds Consumer Reports: Free anti-malware software for Windows, Mac is effective | ||||||||||
| ||||||||||
SLIDESHOWS 10 terrific LTE smartphones for $150 or less JOIN THE NETWORK WORLD COMMUNITIES MOST-READ STORIES
| ||||||||||
| Do You Tweet? You are currently subscribed to networkworld_daily_news_alert as security.world@gmail.com. Unsubscribe from this newsletter | Manage your subscriptions | Subscribe | Privacy Policy To contact Network World, please send an e-mail to customer_service@nww.com. Copyright (C) 2011 Network World, 492 Old Connecticut Path, Framingham MA 01701 ** Please do not reply to this message. If you want to contact someone directly, send an e-mail to customer_service@nww.com. ** | ||||||||||
Everything related to Computer Security - Security Audits, Security Vulnerabilities, Intrusion Detection, Incident Handling, Forensics and Investigation, Information Security Policies, and a whole lot more.
Search This Blog
Sunday, June 03, 2012
Top 10 Network World items to catch up on this weekend
[SECURITY] [DSA 2485-1] imp4 security update
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2485-1 security@debian.org
http://www.debian.org/security/ Thijs Kinkhorst
June 3, 2012 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : imp4
Vulnerability : cross site scripting
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-0791
Debian Bug : 659392
Multiple cross-site scripting (XSS) vulnerabilities were discovered in
IMP, the webmail component in the Horde framework. The vulnerabilities
allow remote attackers to inject arbitrary web script or HTML via various
crafted parameters.
For the stable distribution (squeeze), this problem has been fixed in
version 4.3.7+debian0-2.2.
For the testing distribution (wheezy) and unstable distribution (sid),
this problem will be fixed soon.
We recommend that you upgrade your imp4 packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQEcBAEBAgAGBQJPyy+/AAoJEOxfUAG2iX57r4EIALIxx6GJEVcSDlpsjIdiXXRD
f5Q5UInq8nnuhyhZxZIUjr9111zTemBbccRaWtdunXm5uPb6CT1j5wOScwVQiYdz
RAQFmEaoCL1jEay479gL51VIhtGvlCv0F5LLcQVfpVy5Vi7lTvT64dqz7MnNM2+o
UDgOXFTgECmbPLlZcST1XGtvrdXfZ3Y8Jo6W0y3kVwAQ4qQ/+hfeOstajsnk3Jyf
D4BCZxyfu+6Kv38NeTeRZu5d7f/ST8qoKb3kLdgPZifpvY1P7QugHqp/+frAppqb
N+WVj7zbNzdG6EV4zSGu5GSrp3mQMWmevAAQZERFhmzi5+iguLHNSBZk0PdwiAM=
=aV1g
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: http://lists.debian.org/20120603093546.03E1E59A13@kinkhorst.com
Saturday, June 02, 2012
[SECURITY] [DSA 2482-1] libgdata security update
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2482-1 security@debian.org
http://www.debian.org/security/ Yves-Alexis Perez
June 2, 2012 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : libgdata
Vulnerability : insufficient certificate validation
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-2653
Debian Bug : 664032
Vreixo Formoso discovered that libgdata, a library used to access various
Google services, wasn't validating certificates against trusted system
root CAs when using an https connection.
For the stable distribution (squeeze), this problem has been fixed in
version 0.6.4-2+squeeze1.
For the testing distribution (wheezy), this problem has been fixed in
version 0.10.2-1.
For the unstable distribution (sid), this problem has been fixed in
version 0.10.2-1.
We recommend that you upgrade your libgdata packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQEcBAEBAgAGBQJPyg+cAAoJEOxfUAG2iX570q8H/34iZgboRkiMBx82t6kaP5J+
xn0pP6ZfQqrGJUA9VeWegD3nFuNLG9LlxCmE5B+v743/+V891ctQ6UzCG2iL1xd4
z8eiij//E+2QhaZatrrd58HXBYQI+51/rPpJ3nE+5l3QxCNGwpE8P8D7dIae20SR
EFS5TJ4WzwYKt+cgEJVgPOH94l4KV69MJCDIwOYy79ZgYWT5lrfJ2pQ9Mw4mVtkg
Z8+pxZCeXhgEq7H5NrAZplfcjgxBb2ZiJG1naxmGhVNtuo2ybSuOHbGeTbOQ47q5
5ZSFKaafo+CzSOXXwWPzfPMbpRDBwPvdRZgpsKUaWbHLQwkDDNCi+xE5XRPB+Fo=
=WCiw
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: http://lists.debian.org/20120602130605.A35E459C8E@kinkhorst.com
[SECURITY] [DSA 2482-1] arpwatch security update
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2482-1 security@debian.org
http://www.debian.org/security/ Yves-Alexis Perez
June 2, 2012 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : libgdata
Vulnerability : insufficient certificate validation
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-2653
Debian Bug : 664032
Vreixo Formoso discovered that libgdata, a library used to access various
Google services, wasn't validating certificates against trusted system
root CAs when using an https connection.
For the stable distribution (squeeze), this problem has been fixed in
version 0.6.4-2+squeeze1.
For the testing distribution (wheezy), this problem has been fixed in
version 0.10.2-1.
For the unstable distribution (sid), this problem has been fixed in
version 0.10.2-1.
We recommend that you upgrade your libgdata packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQEcBAEBAgAGBQJPygyBAAoJEOxfUAG2iX57khMIAMxbExHsAKz+hHW+0OkfbfKN
IZ9JChzsA+I56DIqpUXGGw2cTFvxEjHjpDaH3JDX+zj0r7fpIhe3JvproQc6nkF0
5GVCxMglKAnL3vxLeJpLm13BdHG32W/Sa2bElZCl+Ar0s6WAFYcpjaX9VRBw3Jb+
cQ2zRQxg6UketX5w+shJkvyoqfbdo+648/qpMPiK6F+PL6j6ag/wL9pKwx8Hzy9o
PvMCdeKGslHHBHkc4cgoxDXOLV+UF8eo4pWkEj+GbGTJfs8T3DwkwDkG9bhm91mA
Fs0BUHuuvKk+bj78dz8R4KS1AElxpp4ssHmF1atbHqGfRfL4LBM0bWaf2bKpVJg=
=yPHj
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: http://lists.debian.org/20120602125249.1374E59C8C@kinkhorst.com
[SECURITY] [DSA 2481-1] arpwatch security update
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2481-1 security@debian.org
http://www.debian.org/security/ Yves-Alexis Perez
June 2, 2012 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : arpwatch
Vulnerability : fails to drop supplementary groups
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-2653
Debian Bug : 674715
Steve Grubb from Red Hat discovered that a patch for arpwatch (as shipped at
least in Red Hat and Debian distributions) in order to make it drop root
privileges would fail to do so and instead add the root group to the list of
the daemon uses.
For the stable distribution (squeeze), this problem has been fixed in
version 2.1a15-1.1+squeeze1.
For the testing distribution (wheezy), this problem has been fixed in
version 2.1a15-1.2.
For the unstable distribution (sid), this problem has been fixed in
version 2.1a15-1.2.
We recommend that you upgrade your arpwatch packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQEcBAEBAgAGBQJPygvjAAoJEOxfUAG2iX57kQMH/3fZNWPAbXpbn2EYmZsZZBqc
LVBPBL+qp++Ym/dNqm/TKop0+FSVeF3rGpTq1l9HOk6BNMm2jNZvVJ9/OF6vvIZD
zTKEDtqYNbHPMapr/zU7py5Qb/XL2prFlFjfd3A5HXCeLc1dptuhlbyUVkJYjsga
P9QJMphQ5U4CiL9EYV5xM5Co6WAlR13SFrX1cBV7il+OxpGK+lUV4NckocoQk4mG
Su3ImPyCpTbxprZH5BuPjSsGqKB6M6EKIiAA7KvTPfbNyWro53WTg7fChhEJbGzO
X4nZI1eQXJLOCDyYWZekdUFGKb4OsxQPAqRmZJnrURpxB66YWIAzyipE5UfeELI=
=nMw+
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: http://lists.debian.org/20120602125029.F10AC59C8C@kinkhorst.com
[SECURITY] [DSA 2484-1] nut security update
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2484-1 security@debian.org
http://www.debian.org/security/ Thijs Kinkhorst
June 02, 2012 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : nut
Vulnerability : denial of service
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-2944
Debian Bug : 675203
Sebastian Pohle discovered that upsd, the server of Network UPS Tools
(NUT) is vulnerable to a remote denial of service attack.
For the stable distribution (squeeze), this problem has been fixed in
version 2.4.3-1.1squeeze2.
For the testing distribution (wheezy) and unstable distribution (sid),
this problem will be fixed soon.
We recommend that you upgrade your nut packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQEcBAEBAgAGBQJPyghRAAoJEOxfUAG2iX57gCAH/A+MWuGLqqC2JkvcQxVvLFH0
rZiN5OyfvoL9Y416hYOJHuobowC39ubzkb8Uq5fhrF3RUrzgtfvO5u+3V9gpqkn3
xPYAw4BWrRB5JINZcLXyIZmkf0vEEyB43i0R8pKNjo/eS/CC0KFgH15nN/DakcwJ
UwX1MfeH2/Uerf30LaUCq41pvJnI+ABI365YhNQblnkPZBE7gEH4PVDYhpgBhcBg
vaP+PQT+P96M7GOhnBQqVWgZCQvTEuK2M+96m1neQz2UK/QRLOKcZwCSJpCG/jXS
6T8T2ZbbvoP+HwX8KYVyyJJHVbTUsbeKCz9Uuq2qtB0aay5NMSTioVGhMG30g58=
=2W9p
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: http://lists.debian.org/20120602123511.81F1359C8C@kinkhorst.com
Friday, June 01, 2012
iPhone 5 rumor rollup for the week ending June 1
| Is RIM ruined? | HP looking to close ranks at Discover 2012 event | ||||||||||
| Network World Daily News PM | ||||||||||
iPhone 5 rumor rollup for the week ending June 1 WHITE PAPER: Quest Software Effectively Manage IT Compliance IT compliance is mandatory for your business but it doesn't have to be difficult, and when properly controlled is a boon for your company. In this four-part eBook, see how the many parts of IT compliance can be effectively managed throughout the business. Read Now! In this Issue
RESOURCE COMPLIMENTS OF: IT Roadmap Denver Your IT Career Roadmap This unique session is designed with you, the IT professional in mind. How can you build your personal brand, and properly design a career plan? How do you work with your staff to create a plan that retains your best talent? Come to IT Roadmap Denver for valuable information on how today's IT leaders build successful careers. Click to continue Is RIM ruined? HP looking to close ranks at Discover 2012 event Windows 8 Release Preview Impressions WHITE PAPER: Silver Peak Systems, Inc. 5 Ways to Optimize Offsite Storage Storage people are from Mars. Network people are from Venus. Despite interdependencies, each group has its own acronyms, vendors, and metrics making it difficult to communicate between these two "silos". Read now. Anonymous Claims Attack on Facebook Jailbreaking: Don't blame the player, blame the game Flame's Bluetooth functionality could help spies extract data locally, researchers say WHITE PAPER: Radware 2011 State of Cyber Security Your organization's business continuity depends on understanding intricacies of the current attack landscape. The 2011 Radware Global Application & Network Security Report gives essential guidance and findings on the state of global cyber security and how you can better prepare for what comes next. Learn More Opinion split on authority to shut down wireless in emergency Ellison: Next version of Oracle database set for December or January release An assessment of how the US government is trying to improve security Kyocera's speakerless phone hums sounds straight to the ear | ||||||||||
| ||||||||||
SLIDESHOWS 10 terrific LTE smartphones for $150 or less JOIN THE NETWORK WORLD COMMUNITIES MOST-READ STORIES
| ||||||||||
| Do You Tweet? You are currently subscribed to networkworld_daily_news_alert as security.world@gmail.com. Unsubscribe from this newsletter | Manage your subscriptions | Subscribe | Privacy Policy To contact Network World, please send an e-mail to customer_service@nww.com. Copyright (C) 2011 Network World, 492 Old Connecticut Path, Framingham MA 01701 ** Please do not reply to this message. If you want to contact someone directly, send an e-mail to customer_service@nww.com. ** | ||||||||||
US warns users of new Citadel ransomware hit
| DMARC helps protect reputation of American Greetings' e-cards | Is RIM ruined? | ||||||||||
| Network World Security | ||||||||||
| US warns users of new Citadel ransomware hit WEBCAST: IBM Delivery Management -- Extending Lifecycle Management Date: Wednesday, June 20, 2012, 1:00 PM EDT Hear from application lifecycle management experts how to increase delivery efficiency and effectiveness with a new approach to Delivery Management. Register Now In this Issue
WHITE PAPER: Fluke Networks How to Choose a Datacenter OTDR This white paper helps fiber installers and network technicians understand the key parameters for selecting an OTDR. Choosing the right device not only solves this new generation of datacenter testing requirements, but also helps professionals work efficiently, and increase the reliability and value of the enterprise fiber network. Learn More! DMARC helps protect reputation of American Greetings' e-cards Is RIM ruined? WHITE PAPER: Fortinet Next-Generation Security for Enterprise Networks Since the concept of a 'next-generation firewall' was introduced several years ago by Gartner, many network security vendors have introduced their own next-generation firewalls to address this product category - but with varying results. View Now 'Security Jam' online event highlights need for international cybersecurity Is the cloud really ready for prime time? WHITE PAPER: IBM Is Your Database Ready For Your Company's Future? This brochure is targeted to executives and will cover all the business benefits of DB2. Learn More Flame Malware: All You Need to Know U.S. companies, government not likely burned by Flame 1 in 5 U.S. Windows PCs lack antivirus defenses Virgin Galactic's suborbital spacecraft gets FAA blessing | ||||||||||
| ||||||||||
SLIDESHOWS 10 terrific LTE smartphones for $150 or less JOIN THE NETWORK WORLD COMMUNITIES MOST-READ STORIES
| ||||||||||
| Do You Tweet? You are currently subscribed to networkworld_security_alert as security.world@gmail.com. Unsubscribe from this newsletter | Manage your subscriptions | Subscribe | Privacy Policy To contact Network World, please send an e-mail to customer_service@nww.com. Copyright (C) 2011 Network World, 492 Old Connecticut Path, Framingham MA 01701 ** Please do not reply to this message. If you want to contact someone directly, send an e-mail to customer_service@nww.com. ** | ||||||||||