========================================================================== Ubuntu Security Notice USN-1661-1 December 11, 2012 linux vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.04 LTS Summary: The system's firewall could be bypassed by a remote attacker. Software Description: - linux: Linux kernel Details: Zhang Zuotao discovered a bug in the Linux kernel's handling of overlapping fragments in ipv6. A remote attacker could exploit this flaw to bypass firewalls and initial new network connections that should have been blocked by the firewall. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.04 LTS: linux-image-2.6.32-45-386 2.6.32-45.101 linux-image-2.6.32-45-generic 2.6.32-45.101 linux-image-2.6.32-45-generic-pae 2.6.32-45.101 linux-image-2.6.32-45-ia64 2.6.32-45.101 linux-image-2.6.32-45-lpia 2.6.32-45.101 linux-image-2.6.32-45-powerpc 2.6.32-45.101 linux-image-2.6.32-45-powerpc-smp 2.6.32-45.101 linux-image-2.6.32-45-powerpc64-smp 2.6.32-45.101 linux-image-2.6.32-45-preempt 2.6.32-45.101 linux-image-2.6.32-45-server 2.6.32-45.101 linux-image-2.6.32-45-sparc64 2.6.32-45.101 linux-image-2.6.32-45-sparc64-smp 2.6.32-45.101 linux-image-2.6.32-45-versatile 2.6.32-45.101 linux-image-2.6.32-45-virtual 2.6.32-45.101 After a standard system update you need to reboot your computer to make all the necessary changes. References: http://www.ubuntu.com/usn/usn-1661-1 CVE-2012-4444 Package Information: https://launchpad.net/ubuntu/+source/linux/2.6.32-45.101
Spotlight

The security of WordPress plugins
Posted on 18 June 2013. | Checkmarx’s research lab identified that more than 20% of the 50 most popular WordPress plugins are vulnerable to common Web attacks, such as SQL Injection.

Information security executives need to be strategic thinkers
Posted on 17 June 2013. | George Baker, the Director of Information Security at Exostar, talks about the challenges in working in a dynamic threat landscape, offers tips for aspiring infosec leaders, and more.

Large orgs in denial about own security breaches?
Posted on 14 June 2013. | Over two thirds (66%) of large organizations said they either had not experienced a security incident in the last 12-18 months or were unsure if they had.

Vulnerability scanning with PureCloud
Posted on 12 June 2013. | nCircle PureCloud is a cloud-based network security scanning product built upon the companies' vulnerability and risk management system IP360.

Reactions from the security community to the NSA spying scandal
Posted on 11 June 2013. | Read on for comments on this scandal that Help Net Security received from a variety of security professionals and analysts.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.


