Tips on securing the Alexa service on Amazon Echo devices, notably voice purchasing, a topic brought into focus by the recent “San Diego dollhouse TV story”. The post Amazon Echo and the Alexa dollhouses: Security tips and takeaways appeared first on WeLiveSecurity
LinuxSecurity.com: Multiple vulnerabilities have been found in libTIFF, the worst of which may allow execution of arbitrary code.
A senior UK police officer has suggested that offenders of cybercrime should be penalized by being made to wear Wi-Fi jammers rather than being sent to prison. The post Cybercriminals ‘should be punished with Wi-Fi jammers’ appeared first on WeLiveSecurity
A US government probe into claims that certain heart implants are vulnerable to hacking attacks, has resulted in emergency security patches being issued for devices that cardiac patients have in their homes. The post Security scare over hackable heart implants appeared first on WeLiveSecurity
I recently had the pleasure of interviewing Dr. Leonard Adleman — the “A” in the very popular public cryptographic algorithm RSA — as part of the Association for Computing Machinery’s 50th anniversary celebration of the Turing Award. In 2002, Adleman himself won the Turing Award, often referred to at the Nobel Prize of the computing […]
LinuxSecurity.com: Multiple vulnerabilities have been found in Python, the worst of which could lead to arbitrary code execution.
LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.
Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows LSASS is prone to a local privilege-escalation vulnerability; fixes are available.
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: MinGW cross compiled libpng 1.6.27 release, fixing a potential security issue.For details, see https://sourceforge.net/p/png-mng/mailman/message/35575076/
LinuxSecurity.com: This update fixes an old NULL pointer dereference bug in png_set_text_2()discovered and patched by Patrick Keshishian (CVE-2016-10087). The potential”NULL dereference” bug has existed in libpng since version 0.71 of June 26,1995. To be vulnerable, an application has to load a text chunk into the pngstructure, then delete all text, then add another text chunk […]
LinuxSecurity.com: Update —- Update to 0.11 —- Update —- Update. **WARNING:** if youare using your own config file, add “` include /etc/sway/config.d/* “` Atthe end of it, otherwise nothing will work on Wayland
LinuxSecurity.com: MinGW cross compiled libpng 1.6.27 release, fixing a potential security issue.For details, see https://sourceforge.net/p/png-mng/mailman/message/35575076/
LinuxSecurity.com: This update fixes an old NULL pointer dereference bug in png_set_text_2()discovered and patched by Patrick Keshishian (CVE-2016-10087). The potential”NULL dereference” bug has existed in libpng since version 0.71 of June 26,1995. To be vulnerable, an application has to load a text chunk into the pngstructure, then delete all text, then add another text chunk […]
Justin Liverman, a student from North Carolina, has admitted collaborating in a harassment scheme targeting US officials and their families. The post Man pleads guilty to role in harassment scheme against senior US government officials appeared first on WeLiveSecurity
ESET’s Cameron Camp just about recovered from the sensory overload that is CES to gather his thoughts on what was another fascinating event. The post Connected car hacking: Who’s to blame? appeared first on WeLiveSecurity
security update
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: Update to Samba 4.4.9 —- Security fix for CVE-2016-2125, CVE-2016-2126
LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.6.0/releasenotes/
LinuxSecurity.com: **Version 5.4.5** (2016-12-29) * SECURITY FIX: fixed CVE-2016-10074 bydisallowing potentially unsafe shell characters Prior to 5.4.5, the mailtransport (Swift_Transport_MailTransport) was vulnerable to passing arbitraryshell arguments if the “From”, “ReturnPath” or “Sender” header came from anon-trusted source, potentially allowing Remote Code Execution * deprecatedthe mail transport
LinuxSecurity.com: **Version 5.4.5** (2016-12-29) * SECURITY FIX: fixed CVE-2016-10074 bydisallowing potentially unsafe shell characters Prior to 5.4.5, the mailtransport (Swift_Transport_MailTransport) was vulnerable to passing arbitraryshell arguments if the “From”, “ReturnPath” or “Sender” header came from anon-trusted source, potentially allowing Remote Code Execution * deprecatedthe mail transport
security update
security update
