Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Vendors/Products - Page 40

We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.

Discover Vendors/Products News

WordPress 2.8.5 Advisory: Essential DoS Safeguards and PHP Execution Limits

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

WordPress version 2.8.5 promises better security. Described by the development team as a 'hardening release', it contains a number of functions back ported from the version 2.9 beta which should make the blogging system more resistant to attack. According to developer Peter Westwood, these include a fix for Trackback related denial-of-service (DoS) attacks and the deletion of areas of code which allowed PHP code in variables to be executed via the eval() function.

Introducing Private Cloud Features in Ubuntu 9.10 Server Edition

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Canonical is touting private cloud capabilities in an upgrade to its Ubuntu Linux OS being announced on Tuesday. Available for free download on October 29, Ubuntu 9.10 Server Edition introduces UEC (Ubuntu Enterprise Cloud), an open source cloud computing environment based on the same APIs as Amazon EC2 (Elastic Compute Cloud). Businesses can take advantage of private clouds, Canonical said.

ClamAV: 0.94.x End-Of-Life, Security Flaw in Freshclam Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The ClamAV developers have announced that the 15th of April 2010 will be the end-of-life (EOL) date for all versions up to 0.94.x of their free open source anti-virus program. The reason for the change is that releases older than 0.95 are affected by a bug in freshclam, the ClamAV utility used to download new virus definitions. The bug prevents incremental updates from working with signatures that are longer than 980 bytes. The developers note that they haven't yet released any signatures that exceed the limit.

Apple iPhone Security Issues With Exchange And VPN Compliance

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It turns out that Apple's iPhone 3.1 OS fix of a serious security issue, falsely reporting to Exchange servers that pre-3G S iPhones and iPod Touches had on-device encryption, wasn't the first such policy falsehood that Apple has quietly fixed in an OS upgrade. It fixed a similar lie in its June iPhone OS 3.0 update. Before that update, the iPhone falsely reported its adherence to VPN policies, specifically those that confirm the device is not saving the VPN password (so users are forced to enter it manually). Until the iPhone 3.0 OS update, users could save VPN passwords on their Apple devices, yet the iPhone OS would report to the VPN server that the passwords were not being saved.

Your message here