Are you an Apache Struts user who follows security advisories? If so, they may be giving you a false sense of security. . Security researchers have reviewed security advisories for Apache Struts and found that two dozen of them inaccurately listed affected versions for the open-source development framework. The advisories have since been updated to reflect vulnerabilities in an additional 61 unique versions of Struts that were affected by at least one previously disclosed vulnerability but left off the security advisories for those vulnerabilities. The extensive analysis was done by the Black Duck Security Research (BDSR) team of Synopsys’ Cybersecurity Research Center (CyRC), which investigated 115 distinct releases for Apache Struts and correlated those releases against 57 existing Apache Struts Security Advisories covering 64 vulnerabilities. The link for this article located at Naked Security is no longer available. . Experts discovered 67 variations of Nginx not mentioned in security bulletins, prompting worries about their security.. Apache Struts Security, advisory oversight, software vulnerabilities, version discrepancies. . Brittany Day
Secure Science Corporation released an advisory regarding the fact that the latest Pharming techniques utilized within malware has broken SSL. Chapter 5 of Phishing Exposed, a book by Lance James, who happens to work for Secure Science, demonstrated this technique in his book as an upcoming threat that phishers will take advantage of. The report on how this SSL Pharming attack occurs can be found on the advisories page at Secure Science.. The link for this article located at Mal-aware.org is no longer available. . Cyber Alert unveils new malware danger utilizing SSL via Pharming methods in their recent advisory release.. SSL Disruption, Malware Attack, Phishing Techniques, Secure Science Advisory. . LinuxSecurity.com Team
The Computer Emergency Response Team has updated their advisory on the recent Kerberos buffer overflow vulnerabilities. Most vendors have updated their packages already to fix this vulnerability. "The most severe vulnerability allows remote intruders to gain root privileges . . .. The Computer Emergency Response Team has updated their advisory on the recent Kerberos buffer overflow vulnerabilities. Most vendors have updated their packages already to fix this vulnerability. "The most severe vulnerability allows remote intruders to gain root privileges on systems running services using Kerberos authentication. If vulnerable services are enabled on the Key Distribution Center (KDC) system, the entire Kerberos domain may be compromised. " . The Computer Emergency Response Team has updated their advisory on the recent Kerberos buffer overfl. computer, emergency, response, updated, their, advisory, recent, kerberos, buffer, overfl. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.