Friday, July 28, 2017

​State phone-hacking plans put on ice in Austria

austria-parliament.jpg

Austria's ruling party has decided against further state surveillance powers.

Image: Getty Images

The party leading Austria's ruling coalition has effectively sunk an attempt by its junior partner to expand the surveillance of online communications services such as WhatsApp.

The plan, drawn up by the conservative ÖVP party, would have given Austrian police powers to deploy spyware into people's phones -- not only for suspects in crimes involving potential prison sentences of five years or more, but also for those people who are in contact with the suspects.

The social-democrat SPÖ party said the draft legislation went far beyond the policies described in its coalition agreement with the ÖVP. According to a Thursday report in Der Standard, SPÖ justice spokesman Hannes Jarolim said it was "absolutely unimaginable" that the proposal could go ahead, due to the large numbers of people who might be caught up in the surveillance.

And on Friday, Austrian chancellor Christian Kern said the government was committed to finding ways to more effectively tackle terrorism and crime, but the debate was "also about the basic freedoms of citizens".

The practice of hacking suspects' contacts, as well as the suspects themselves, was legalised in the Netherlands earlier this month. Last month, the German parliament authorised a significant expansion of the types of crime where a suspect's phone can be hacked. Spain and the UK also give broad hacking powers to their authorities, thanks to laws passed in 2015 and 2016 respectively.

Such moves come as a reaction to two trends: people's communications are shifting from traditional voice and SMS channels to internet-based services such as WhatsApp and Skype; and these new services increasingly employ end-to-end encryption that makes it impossible to decode messages as they flow through telecommunications networks.

By hacking into a suspect's phone, it's possible to see the decrypted messages that they see on their screen, and to log what they type before it becomes encrypted. The spyware that allows this sometimes also makes it possible to rifle through the phone's contents in search of incriminating files - Chinese authorities recently ordered everyone in the Xinjiang province to install the state's official spyware application to this end.

Under the scrapped Austrian plans, the use of the 'federal Trojan' (Bundestrojaner) would have only taken effect in August 2019, as the authorities there did not yet have the expertise to put it into action.

Last week it emerged that Germany's homegrown Trojan software should be ready for rollout by the end of this year.

The Austrian lawyers' association ÖRAK was among many critics of that country's plans, with association president Rupert Wolff calling the plan a step towards the surveillance state.

Regarding the proposed exchange of data between the police and Austrian security forces, Wolff said: "This is like in [East Germany], where one neighbour spies on the other." He also criticised the fact that the proposal went beyond modernising traditional phone-tapping, potentially exposing all the information on people's phones.



from Latest Topic for ZDNet in... http://ift.tt/2h9raGr

IBM Security Bulletin: Multiple vulnerabilities might affect IBM® SDK for Node.js™

Vulnerabilities in Node.js and the c-ares library were disclosed on July 11 2017 by the Node.js Foundation. IBM SDK for Node.js has addressed the applicable CVEs.

CVE(s): CVE-2017-11499, CVE-2017-1000381

Affected product(s) and affected version(s):

These vulnerabilities affect IBM SDK for Node.js v4.8.3 and earlier releases.
These vulnerabilities affect IBM SDK for Node.js v6.11.0.0 and earlier releases.
These vulnerabilities affect IBM SDK for Node.js v8.1.2.0 and earlier releases.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2eUcQkn
X-Force Database:
X-Force Database: http://ift.tt/2h8Xc5H

The post IBM Security Bulletin: Multiple vulnerabilities might affect IBM® SDK for Node.js™ appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2eTUpwk

IBM Security Bulletin: Multiple vulnerabilities in coreutils, sudo, jasper, bind, bash, libtirpc, nss and nss-util affect IBM SmartCloud Entry

Multiple vulnerabilities have been identified in coreutils, sudo, jasper, bind, bash, libtirpc, nss and nss-util. coreutils, sudo, jasper, bind, bash, libtirpc, nss and nss-util shipped with IBM SmartCloud Entry Appliance. IBM SmartCloud Entry Appliance has addressed the vulnerabilities.

CVE(s): CVE-2017-2616, CVE-2016-0634, CVE-2016-7543, CVE-2016-9401, CVE-2017-3136, CVE-2017-3137, CVE-2017-3139, CVE-2017-5461, CVE-2015-5203, CVE-2015-5221, CVE-2016-10248, CVE-2016-10249, CVE-2016-10251, CVE-2016-1577, CVE-2016-1867, CVE-2016-2089, CVE-2016-2116, CVE-2016-8654, CVE-2016-8690, CVE-2016-8691, CVE-2016-8692, CVE-2016-8693, CVE-2016-8883, CVE-2016-8884, CVE-2016-8885, CVE-2016-9262, CVE-2016-9387, CVE-2016-9388, CVE-2016-9389, CVE-2016-9390, CVE-2016-9391, CVE-2016-9392, CVE-2016-9393, CVE-2016-9394, CVE-2016-9560, CVE-2016-9583, CVE-2016-9591, CVE-2016-9600, CVE-2017-8779, CVE-2017-7502, CVE-2017-1000367

Affected product(s) and affected version(s):

IBM SmartCloud Entry Appliance 2.3.0 through 2.3.0.4 fix pack 10,
IBM SmartCloud Entry Appliance 2.4.0 through 2.4.0.4 fix pack 10,
IBM SmartCloud Entry Appliance 3.1.0 through 3.1.0.4 fix pack 25,
IBM SmartCloud Entry Appliance 3.2.0 through 3.2.0.4 fix pack 25

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2h8WPbj
X-Force Database: http://ift.tt/2eUcpqf
X-Force Database: http://ift.tt/2mMjKr9
X-Force Database: http://ift.tt/2mkL7MQ
X-Force Database: http://ift.tt/2h99Hy7
X-Force Database: http://ift.tt/2q2NYu4
X-Force Database: http://ift.tt/2pzgwZi
X-Force Database: http://ift.tt/2t2tHHQ
X-Force Database: http://ift.tt/2h8WTrz
X-Force Database: http://ift.tt/2eTEWfG
X-Force Database: http://ift.tt/2h99Mlp
X-Force Database: http://ift.tt/2eUctGv
X-Force Database: http://ift.tt/2h8WVQd
X-Force Database: http://ift.tt/2eTEYUQ
X-Force Database: http://ift.tt/2h8WXHP
X-Force Database: http://ift.tt/2eTF0vW
X-Force Database: http://ift.tt/2h99QSb
X-Force Database: http://ift.tt/2eTF12Y
X-Force Database: http://ift.tt/2h99T0j
X-Force Database: http://ift.tt/2eUczhl
X-Force Database: http://ift.tt/2h8WZPX
X-Force Database: http://ift.tt/2eUcBWv
X-Force Database: http://ift.tt/2h99Wt1
X-Force Database: http://ift.tt/2eUcEl9
X-Force Database: http://ift.tt/2h99Xx5
X-Force Database: http://ift.tt/2eUcFpd
X-Force Database: http://ift.tt/2h8X1Y5
X-Force Database: http://ift.tt/2eUc2Mm
X-Force Database: http://ift.tt/2h99ZoH
X-Force Database: http://ift.tt/2eUcGth
X-Force Database: http://ift.tt/2h8X3PH
X-Force Database: http://ift.tt/2eUcHgP
X-Force Database: http://ift.tt/2h8X4TL
X-Force Database: http://ift.tt/2eUcI4n
X-Force Database: http://ift.tt/2h9a2kn
X-Force Database: http://ift.tt/2eUcIBp
X-Force Database: http://ift.tt/2h8X6el
X-Force Database: http://ift.tt/2eU9PR7
X-Force Database: http://ift.tt/2h9a4sv
X-Force Database: http://ift.tt/2eTsjBt
X-Force Database: http://ift.tt/2h8X71T
X-Force Database: http://ift.tt/2eUcM47

The post IBM Security Bulletin: Multiple vulnerabilities in coreutils, sudo, jasper, bind, bash, libtirpc, nss and nss-util affect IBM SmartCloud Entry appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2eT7p5y

IBM Security Bulletin: Multiple vulnerabilities in qemu-kvm and libguestfs affect SmartCloud Entry (CVE-2016-9603 CVE-2017-2633 CVE-2017-7718 CVE-2017-7980 CVE-2015-8869)

Multiple vulnerabilitieshave been identified in qemu-kvm and libguestfs. Qemu-kvm and libguestfs shipped with IBM SmartCloud Entry Appliance. IBM SmartCloud Entry Appliance has addressed the vulnerabilities.

CVE(s): CVE-2017-2633, CVE-2017-7718, CVE-2017-7980, CVE-2015-8869

Affected product(s) and affected version(s):

IBM SmartCloud Entry Appliance 3.1.0 through 3.1.0.4 fix pack 25,
IBM SmartCloud Entry Appliance 3.2.0 through 3.2.0.4 fix pack 25

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2eT7tSQ
X-Force Database: http://ift.tt/2h9lFYx
X-Force Database: http://ift.tt/2eTEs9m
X-Force Database: http://ift.tt/2h9apLQ
X-Force Database: http://ift.tt/2eT7w0Y

The post IBM Security Bulletin: Multiple vulnerabilities in qemu-kvm and libguestfs affect SmartCloud Entry (CVE-2016-9603 CVE-2017-2633 CVE-2017-7718 CVE-2017-7980 CVE-2015-8869) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2h8WwNH

IBM Security Bulletin: IBM i is affected by an OSPF vulnerability (CVE-2017-1460)

Jul 28, 2017 11:03 am EDT | High Severity

Multiple vulnerabilities have been identified in coreutils, sudo, jasper, bind, bash, libtirpc, nss and nss-util. coreutils, sudo, jasper, bind, bash, libtirpc, nss and nss-util shipped with IBM SmartCloud Entry Appliance. IBM SmartCloud Entry Appliance has addressed the vulnerabilities. CVE(s): CVE-2017-2616, CVE-2016-0634, CVE-2016-7543, CVE-2016-9401, CVE-2017-3136, CVE-2017-3137, CVE-2017-3139, CVE-2017-5461, CVE-2015-5203, CVE-2015-5221, CVE-2016-10248, CVE-2016-10249, CVE-2016-10251, CVE-2016-1577, CVE-2016-1867, CVE-2016-2089, ...read more



from IBM Product Security Incident Response Team http://ift.tt/2eT7pCA

IBM Security Bulletin: The BigFix Platform has a vulnerability that can cause denial of service

Under certain conditions the size or amount of memory resources that are requested or influenced by an actor is not restricted. This can be used to consume more resources than reasonably intended, resulting in a crash or segmentation fault.

CVE(s): CVE-2017-1227

Affected product(s) and affected version(s):

BigFix Platform 9.1

BigFix Platform 9.2

BigFix Platform 9.5

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2eTI6QP
X-Force Database: http://ift.tt/2h98Ayf

The post IBM Security Bulletin: The BigFix Platform has a vulnerability that can cause denial of service appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2eT7lmk

IBM Security Bulletin: IBM InfoSphere Master Data Management is vulnerable to a X-Frame-Options Header ClickJacking attack (CVE-2016-9719 )

IBM InfoSphere Master Data Management is vulnerable to a X-Frame-Options Header ClickJacking attack a remote attacker could exploit this vulnerability to hijack the victim’s click actions and possibly launch further attacks against the victim.

CVE(s): CVE-2016-9719

Affected product(s) and affected version(s):

This vulnerability is known to affect the following offerings:

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2eT7juI
X-Force Database: http://ift.tt/2h98x5x

The post IBM Security Bulletin: IBM InfoSphere Master Data Management is vulnerable to a X-Frame-Options Header ClickJacking attack (CVE-2016-9719 ) appeared first on IBM PSIRT Blog.

Affected IBM InfoSphere Master Data Management Server Affected Versions
IBM InfoSphere Master Data Management 10.1
IBM InfoSphere Master Data Management 11.0
IBM InfoSphere Master Data Management 11.3
IBM InfoSphere Master Data Management 11.4
IBM InfoSphere Master Data Management 11.5
IBM InfoSphere Master Data Management 11.6


from IBM Product Security Incident Response Team http://ift.tt/2eU5Dkq