LinuxSecurity.com: xen : various security flaws (#1397383) x86 null segments not always treated asunusable [XSA-191, CVE-2016-9386] x86 task switch to VM86 mode mis-handled[XSA-192, CVE-2016-9382] x86 segment base write emulation lacking canonicaladdress checks [XSA-193, CVE-2016-9385] guest 32-bit ELF symbol table loadleaking host data [XSA-194, CVE-2016-9384] x86 64-bit bit test instructionemulation broken [XSA-195, CVE-2016-9383] x86 software interrupt […]
LinuxSecurity.com: Libvirt is vulnerable to directory traversal when using Access Control Lists (ACL).
LinuxSecurity.com: Multiple vulnerabilities have been found in GD, the worst of which allows remote attackers to execute arbitrary code.
LinuxSecurity.com: A vulnerability in LinuxCIFS utils’ “cifscreds” PAM module might allow remote attackers to have an unspecified impact via unknown vectors.
Go ahead and hack your car, that’s fine now. Go ahead and hack the Department of Defense, that’s okay too under new policies. It wasn’t always this way. The post Hacking is legal again finally (sometimes) appeared first on WeLiveSecurity.
We live in a world where internet crime is rampant. Cyber criminals steal hundreds of millions of dollars each year with near impunity. For every 1 that gets caught, 10,000 go free — maybe more. For every 1 successfully prosecuted in a court of law, 100 get off scot-free or with a warning. Why is […]
ESET lifts the lid on Android ransomware – the picture doesn’t look good. It’s on the increase and extremely sophisticated. The post Android ransomware spreads further, with new methods in its toolbox appeared first on WeLiveSecurity.
David Harley, talking about child safety and security in (and yet not in) the South Atlantic. The post Child safety: An unexpected radio interview appeared first on WeLiveSecurity.
LinuxSecurity.com: A vulnerability in DavFS2 allows local users to gain root privileges.
LinuxSecurity.com: Due to a design flaw, the output of GnuPG’s Random Number Generator (RNG) is predictable.
LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294
LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294
LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]
LinuxSecurity.com: A security update that fixes Calamares bug CAL-405:https://calamares.io/bugs/browse/CAL-405 When installing with a LUKS-encrypted`/` partition, Calamares was always creating a keyfile to decode `/` and storingit in the initramfs. It did that even with an unencrypted separate `/boot`partition. As a result, the keyfile would be stored in cleartext on the `/boot`partition, and it was possible […]
LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)
LinuxSecurity.com: A security update that fixes Calamares bug CAL-405:https://calamares.io/bugs/browse/CAL-405 When installing with a LUKS-encrypted`/` partition, Calamares was always creating a keyfile to decode `/` and storingit in the initramfs. It did that even with an unencrypted separate `/boot`partition. As a result, the keyfile would be stored in cleartext on the `/boot`partition, and it was possible […]
LinuxSecurity.com: Security fix for CVE-2016-9299
LinuxSecurity.com: Security fix for CVE-2016-9299
LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Earlier this week coordinated law enforcement action took down the Avalanche fast-flux network. ESET has been assisting in the cleanup. The post Avalanche takedown: Check if you are safe appeared first on WeLiveSecurity.
Between a handful of high profile network hacks and the steady stream of ransomware attacks, the last week of November didn’t pull any punches in the constant sparring match that is cybersecurity. In the wake of headlines about a US Navy breach, large scale network outages across Germany, and more, internet users across the […]
A year ago on 2nd December 2015, a collaboration between major cybersecurity firms, law enforcement and software providers – including ESET and Microsoft – successfully managed to disrupt Dorkbot, a malware family that had been infiltrating systems worldwide for over four years. Since its detection in April 2011, Dorkbot had caused numerous problems for businesses […]
Risk Level: Very Low. Type: Trojan.
