Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -2 articles for you...
67

OpenSSH: 7.1 Released With Logic Error Fixes And Compatibility Improvements

OpenSSH 7.1 has just been released. It will be available from the mirrors listed at https://www.openssh.org/ shortly.. From: Damien Miller Date: Fri, 21 Aug 2015 00:11:02 -0600 (MDT) To: This email address is being protected from spambots. You need JavaScript enabled to view it. Subject: Announce: OpenSSH 7.1 released OpenSSH 7.1 has just been released. It will be available from the mirrors listed at https://www.openssh.org/ shortly. OpenSSH is a 100% complete SSH protocol 2.0 implementation and includes sftp client and server support. OpenSSH also includes transitional support for the legacy SSH 1.3 and 1.5 protocols that may be enabled at compile-time. Once again, we would like to thank the OpenSSH community for their continued support of the project, especially those who contributed code or patches, reported bugs, tested snapshots or donated to the project. More information on donations may be found at: https://www.openssh.org/donations.html Future deprecation notice ========================= We plan on retiring more legacy cryptography in the next release including: Refusing all RSA keys smaller than 1024 bits (the current minimum is 768 bits) Several ciphers will be disabled by default: blowfish-cbc, cast128-cbc, all arcfour variants and the rijndael-cbc aliases for AES. MD5-based HMAC algorithms will be disabled by default. This list reflects our current intentions, but please check the final release notes for OpenSSH 7.1 when it is released. Changes since OpenSSH 7.0 ========================= This is a bugfix release. Security -------- sshd(8): OpenSSH 7.0 contained a logic error in PermitRootLogin prohibit-password/without-password that could, depending on compile-time configuration, permit password authentication to root while preventing other forms of authentication. This problem was reported by Mantas Mikulenas. Bugfixes -------- ssh(1), sshd(8): add compatability workarounds for FuTTY ssh(1), sshd(8): refine compatability workarounds forWinSCP Fix a number of memory faults (double-free, free of uninitialised memory, etc) in ssh(1) and ssh-keygen(1). Reported by Mateusz Kocielski. Checksums: ========== - SHA1 (openssh-7.1.tar.gz) = 06c1db39f33831fe004726e013b2cf84f1889042 - SHA256 (openssh-7.1.tar.gz) = H7U1se9EoBmhkKi2i7lqpMX9QHdDTsgpu7kd5VZUGSY= - SHA1 (openssh-7.1p1.tar.gz) = ed22af19f962262c493fcc6ed8c8826b2761d9b6 - SHA256 (openssh-7.1p1.tar.gz) = /AptLR0GPVxm3/2VJJPQzaJWytIE9oHeD4TvhbKthCg= Please note that the SHA256 signatures are base64 encoded and not hexadecimal (which is the default for most checksum tools). The PGP key used to sign the releases is available as RELEASE_KEY.asc from the mirror sites. Reporting Bugs: =============== - Please read https://www.openssh.org/report.html Security bugs should be reported directly to This email address is being protected from spambots. You need JavaScript enabled to view it. OpenSSH is brought to you by Markus Friedl, Niels Provos, Theo de Raadt, Kevin Steves, Damien Miller, Darren Tucker, Jason McIntyre, Tim Rice and Ben Lindstrom. . OpenSSH 7.1 resolves logical discrepancies and enhances interoperability, concurrently retiring obsolete cryptographic techniques.. OpenSSH 7.1, Secured Connections, Bug Fixes. . LinuxSecurity.com Team

Calendar 2 Aug 21, 2015 User Avatar LinuxSecurity.com Team Cryptography
76

Web Services Interoperability Challenges: WS-I Addresses Security Issues

A group working to ensure the compatibility of Web services software is preparing to tackle its biggest challenge yet: Security. The Web Services Interoperability organization (WS-I) was formed last year at the behest of companies including IBM and Microsoft to see to it that Web services products from different companies work together.. . .. A group working to ensure the compatibility of Web services software is preparing to tackle its biggest challenge yet: Security. The Web Services Interoperability organization (WS-I) was formed last year at the behest of companies including IBM and Microsoft to see to it that Web services products from different companies work together. The group now has approximately 160 members, including about 20 companies that are not information technology suppliers. Although businesses are forging ahead with Web services applications as a way of bridging differences between disparate systems, minor incompatibilities are surfacing. The WS-I's stated goal is to make sure gear from various IT suppliers is compatible and to help customers iron out any Web services glitches. So far, the group has delivered a draft specification of basic Web services protocols, which is set to be finalized in the second quarter. The link for this article located at ZDNet is no longer available. . A group working to ensure the compatibility of Web services software is preparing to tackle its bigg. group, working, ensure, compatibility, services, software, preparing, tackle. . Anthony Pell

Calendar 2 Feb 05, 2003 User Avatar Anthony Pell Organizations/Events
67

OpenSSL 0.9.7 Release Announcement: Enhancements And Transition Steps

The OpenSSL developers team is pleased to announce the upcoming release of OpenSSL 0.9.7. OpenSSL 0.9.7 contains several changes and enhancements in many fields; please check out the NEWS and CHANGES files for details. Some of the changes made break compatibility, so that application developers and distribution providers may need a transition period.. . .. The OpenSSL developers team is pleased to announce the upcoming release of OpenSSL 0.9.7. OpenSSL 0.9.7 contains several changes and enhancements in many fields; please check out the NEWS and CHANGES files for details. Some of the changes made break compatibility, so that application developers and distribution providers may need a transition period. Date: Tue, 16 Apr 2002 16:56:50 +0200 From: Lutz Jaenicke Reply-To: openssl-users@openssl.org To: openssl-announce@openssl.org, openssl-dev@openssl.org, openssl-users@openssl.org Subject: Announcement of OpenSSL 0.9.6d and 0.9.7 Release Plan and Schedule Announcement of OpenSSL 0.9.6d and 0.9.7 Release Plan and Schedule ================================================================== The OpenSSL developers team is pleased to announce the upcoming release of OpenSSL 0.9.7. OpenSSL 0.9.7 contains several changes and enhancements in many fields; please check out the NEWS and CHANGES files for details. Some of the changes made break compatibility, so that application developers and distribution providers may need a transition period. We have therefore decided for a 2-step strategy: * Release 0.9.6d: OpenSSL 0.9.6d will be the last release of the 0.9.6 series, containing all of the latest bugfixes while maintaining compatibility. * Release 0.9.7: OpenSSL 0.9.7 contains many enhancements and some incompatible changes. It also includes the bugfixes found in 0.9.6d (except for those obsoleted by other changes). We intend to provide releases according to the following schedule: 16 Apr 2002: 0.9.6d-beta1 30 Apr 2002: 0.9.6d The changes between 0.9.6c and 0.9.6d are quite small so that we donot expect too many problems. Therefore only one beta release is planned. 30 Apr 2002: 0.9.7-beta1 13 May 2002: 0.9.7-beta2 ... As the changes between 0.9.6x and 0.9.7 are numerous, we are prepared to handle more beta releases. The number of beta releases may change with error reports coming in. If no more errors are found after beta2, the final release will be made. If more errors are found in beta2, beta3 will be introduced and so on. Testing 0.9.7-beta... does not only mean to download and call "make install" and/or "make test" on different platforms. We explicitely ask application developers and users to test out the functionality of applications and/or integrate new functionality or adjust to the API changes. If these checks are not done in the beta phase and applications are only tested once 0.9.7 is released, bug fixes may be delayed until the release of 0.9.7a, if required. Be reminded that changes are also available via the daily snapshots. Incompatible Changes with 0.9.7: ================================ - List will be provided with the 0.9.7-beta releases. Known Problems with 0.9.7: ========================== > From the OpenSSL STATUS file: o BIGNUM library failures on 64-bit platforms (0.9.7-dev): - BN_mod_mul verificiation (bc) fails for solaris64-sparcv9-cc and other 64-bit platforms Checked on Result alpha-cc (Tru64 version 4.0) works linux-alpha+bwx-gcc doesn't work. Reported by Sean O'Riordain OpenBSD-sparc64 doesn't work. BN_mod_mul breaks. Needs checked on [add platforms here] - BN_mod_mul verification fails for mips3-sgi-irix unless configured with no-asm Bug reports: ============ - Bug reports should be sent to This email address is being protected from spambots. You need JavaScript enabled to view it., reports are copied to openssl-dev. - Success reports may be sent to openssl-bugs too, to indicate successfull operation and help other people to narrow their problems down. Downloads: ========== - Files will be made available at the usual locations at OpenSSL.org. -Seperate announcements will be made for each beta and release. Yours, The OpenSSL Project Team... Mark J. Cox Richard Levitte Andy Polyakov Ralf S. Engelschall Bodo M�ller Holger Reif Dr. Stephen Henson Ulf M�ller Geoff Thorpe Ben Laurie Lutz J�nicke ______________________________________________________________________ OpenSSL Project https://www.openssl.org:443/ Announcement Mailing List This email address is being protected from spambots. You need JavaScript enabled to view it. Automated List Manager This email address is being protected from spambots. You need JavaScript enabled to view it. . The OpenSSL developers team is pleased to announce the upcoming release of OpenSSL 0.9.7. OpenSSL 0.. openssl, developers, pleased, announce, upcoming, release. . LinuxSecurity.com Team

Calendar 2 Apr 17, 2002 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here