No Image

Mitigating speculative execution side-channel attacks in Microsoft Edge and Internet Explorer

2018-01-04 KENNETH 0

Mitigating speculative execution side-channel attacks in Microsoft Edge and Internet Explorer Today, Google Project Zero published details of a class of vulnerabilities which can be exploited by speculative execution side-channel attacks. These techniques can be used via JavaScript code running in the browser, which may allow attackers to gain access to memory in the attacker’s process. Microsoft has issued security updates (KB4056890) with mitigations for this class of attacks. As part of these updates, we are making changes to the behavior of supported versions of Microsoft Edge and Internet Explorer 11 to mitigate the ability to successfully read memory through this new class of side-channel attacks. Initially, we are removing support for SharedArrayBuffer from Microsoft Edge (originally introduced in the Windows 10 Fall Creators Update), and reducing the resolution of performance.now() in Microsoft Edge and Internet Explorer from 5 microseconds [ more… ]

No Image

RHSA-2018:0015-1: Important: linux-firmware security update

2018-01-04 KENNETH 0

RHSA-2018:0015-1: Important: linux-firmware security update Red Hat Enterprise Linux: An update for linux-firmware is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Source: RHSA-2018:0015-1: Important: linux-firmware security update

No Image

RHSA-2018:0014-1: Important: linux-firmware security update

2018-01-04 KENNETH 0

RHSA-2018:0014-1: Important: linux-firmware security update Red Hat Enterprise Linux: An update for linux-firmware is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Source: RHSA-2018:0014-1: Important: linux-firmware security update

No Image

RHSA-2018:0013-1: Important: microcode_ctl security update

2018-01-04 KENNETH 0

RHSA-2018:0013-1: Important: microcode_ctl security update Red Hat Enterprise Linux: An update for microcode_ctl is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Source: RHSA-2018:0013-1: Important: microcode_ctl security update

No Image

RHSA-2018:0011-1: Important: kernel security update

2018-01-04 KENNETH 0

RHSA-2018:0011-1: Important: kernel security update Red Hat Enterprise Linux: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Source: RHSA-2018:0011-1: Important: kernel security update