No Image

WordPress 4.5.2 Security Release

2016-05-07 KENNETH 0

WordPress 4.5.2 Security Release WordPress 4.5.2 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately. WordPress versions 4.5.1 and earlier are affected by a SOME vulnerability through Plupload, the third-party library WordPress uses for uploading files. WordPress versions 4.2 through 4.5.1 are vulnerable to reflected XSS using specially crafted URIs through MediaElement.js, the third-party library used for media players. MediaElement.js and Plupload have also released updates fixing these issues. Both issues were analyzed and reported by Mario Heiderich, Masato Kinugawa, and Filedescriptor from Cure53. Thanks to the team for practicing responsible disclosure, and to the Plupload and MediaElement.js teams for working closely with us to coördinate and fix these issues. Download WordPress 4.5.2 or venture over to Dashboard → Updates and simply click “Update Now.” Sites that [ more… ]

3BetGaming Serves More Customers and Saves 75% Bandwidth with NGINX Plus

2016-05-06 KENNETH 0

3BetGaming Serves More Customers and Saves 75% Bandwidth with NGINX Plus   Situation 3BetGaming is a software provider for online sports betting companies. Whether before a match or in the middle of the game, 3BetGaming’s backend infrastructure powers the bidding behind thousands of games every day. The company offers the most extensive sports book application on the market, and supports nearly 12,000 active players, 14,000 live monthly events, and 100 million bets so far. 3BetGaming is based in Malta and has clients around the world – from growing startups to massive corporations. 3BetGaming consistently provides flexible and powerful software for its diverse range of clients. As its customer base grew, 3BetGaming faced a problem with its existing virtual load balancing appliances. The growth in traffic was bringing 3BetGaming close to exceeding the bandwidth limit imposed by its existing license. In [ more… ]

No Image

USN-2964-1: OpenJDK 7 vulnerabilities

2016-05-05 KENNETH 0

USN-2964-1: OpenJDK 7 vulnerabilities Ubuntu Security Notice USN-2964-1 4th May, 2016 openjdk-7 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 14.04 LTS Summary Several security issues were fixed in OpenJDK 7. Software description openjdk-7 – Open Source Java implementation Details Multiple vulnerabilities were discovered in the OpenJDK JRE related to informationdisclosure, data integrity, and availability. An attacker could exploitthese to cause a denial of service, expose sensitive data over the network,or possibly execute arbitrary code. (CVE-2016-0686, CVE-2016-0687,CVE-2016-3427) A vulnerability was discovered in the OpenJDK JRE related to informationdisclosure. An attacker could exploit this to expose sensitive data overthe network. (CVE-2016-0695) A vulnerability was discovered in the OpenJDK JRE related to availability.An attacker could exploit this to cause a denial of service.(CVE-2016-3425) Update instructions The problem can be corrected by updating your system to [ more… ]

No Image

USN-2963-1: OpenJDK 8 vulnerabilities

2016-05-05 KENNETH 0

USN-2963-1: OpenJDK 8 vulnerabilities Ubuntu Security Notice USN-2963-1 4th May, 2016 openjdk-8 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in OpenJDK 8. Software description openjdk-8 – Open Source Java implementation Details Multiple vulnerabilities were discovered in the OpenJDK JRE related toinformation disclosure, data integrity, and availability. An attackercould exploit these to cause a denial of service, expose sensitive dataover the network, or possibly execute arbitrary code. (CVE-2016-0686,CVE-2016-0687, CVE-2016-3427) Multiple vulnerabilities were discovered in the OpenJDK JRE relatedto information disclosure. An attacker could exploit this to exposesensitive data over the network. (CVE-2016-0695, CVE-2016-3426) A vulnerability was discovered in the OpenJDK JRE related to availability.An attacker could exploit this to cause a denial of service.(CVE-2016-3425) Update instructions The problem can be corrected by updating your system to the [ more… ]

No Image

USN-2961-1: Little CMS vulnerability

2016-05-05 KENNETH 0

USN-2961-1: Little CMS vulnerability Ubuntu Security Notice USN-2961-1 4th May, 2016 lcms2 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Applications using the Little CMS library could be made to crash or run programs as your login if it opened a specially crafted file. Software description lcms2 – Little CMS color management library Details It was discovered that a double free() could occur when the intent handlingcode in the Little CMS library detected an error. An attacker could usethis to specially craft a file that caused an application using the LittleCMS library to crash or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 14.04 LTS: liblcms2-utils 2.5-0ubuntu4.1 liblcms2-2 2.5-0ubuntu4.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After [ more… ]