Menu

Monthly Archives: August 2017

security update

Type: Vulnerability. Oracle Java SE is prone to a remote code execution vulnerability in Java Runtime Environment; fixes are available.

Type: Vulnerability. Oracle Java SE is prone to a remote code-execution vulnerability; fixes are available.

IBM Patches Reflected XSS in Worklight, MobileFirst

LinuxSecurity.com: Fix /tmp race conditions in libDeployPkg (CVE-2015-5191).

LinuxSecurity.com: * various security fixes (https://github.com/glpi-project/glpi/issues/2475, https://github.com/glpi-project/glpi/issues/2476, https://github.com/glpi- project/glpi/issues/2492), * fix regressions on self service portal: * self-service users should not be auto assigned as tech * type and category fields are not selectable

LinuxSecurity.com: Update to 2.48 Fixes various security issues, see http://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for more info.

LinuxSecurity.com: Update to 5.2.24: fixes XSS vulnerability CVE-2017-11503.

LinuxSecurity.com: Apache HTTP Server could be made to crash or leak sensitive information if it received specially crafted network traffic.

Android users: beware ‘Invisible Man’ malware disguised as Flash
Will The Real Security Community Please Stand Up

LinuxSecurity.com: * various security fixes (https://github.com/glpi-project/glpi/issues/2475, https://github.com/glpi-project/glpi/issues/2476, https://github.com/glpi- project/glpi/issues/2492), * fix regressions on self service portal: * self-service users should not be auto assigned as tech * type and category fields are not selectable

LinuxSecurity.com: Update to 2.48 Fixes various security issues, see http://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for more info.

Hackers hijack central Cardiff billboard to display swastikas and more…
Fake hot-babe spears businessmen on LinkedIn
HBO hackers upload Games of Thrones episodes & other data on their site
True random numbers are here – what that means for data centers
Long Live Gopher: The Techies Keeping the Text-Driven Internet Alive
UK home secretary: ‘real people’ don’t want unbreakable encryption

LinuxSecurity.com: A denial of service vulnerability was discovered in Varnish, a state of the art, high-performance web accelerator. Specially crafted HTTP requests can cause the Varnish daemon to assert and restart, clearing the cache in the process.

LinuxSecurity.com: New gnupg packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

security update

Legislation Proposed to Secure Connected IoT Devices
Email prankster tricks White House officials

LinuxSecurity.com: Fixes CVE-2017-11671. Fixed bugs (http://gcc.gnu.org/PRNNNNN): 31468, 43434, 45053, 49244, 50345, 53915, 56469, 60818, 60992, 61636, 61729, 62045, 64238, 65542, 65705, 65972, 66295, 66669, 67353, 67440, 68163, 68491, 68972, 69264, 69699, 69804, 69823, 69953, 70601, 70844, 70878, 71294, 71310, 71444, 71458, 71510, 71778, 71838, 72775, 73650, 75964, 76731, 77333, 77563, 77728, 77850,

LinuxSecurity.com: Fixes CVE-2017-11671. Fixed bugs (http://gcc.gnu.org/PRNNNNN): 31468, 43434, 45053, 49244, 50345, 53915, 56469, 60818, 60992, 61636, 61729, 62045, 64238, 65542, 65705, 65972, 66295, 66669, 67353, 67440, 68163, 68491, 68972, 69264, 69699, 69804, 69823, 69953, 70601, 70844, 70878, 71294, 71310, 71444, 71458, 71510, 71778, 71838, 72775, 73650, 75964, 76731, 77333, 77563, 77728, 77850,

LinuxSecurity.com: Fixes CVE-2017-11671. Fixed bugs (http://gcc.gnu.org/PRNNNNN): 31468, 43434, 45053, 49244, 50345, 53915, 56469, 60818, 60992, 61636, 61729, 62045, 64238, 65542, 65705, 65972, 66295, 66669, 67353, 67440, 68163, 68491, 68972, 69264, 69699, 69804, 69823, 69953, 70601, 70844, 70878, 71294, 71310, 71444, 71458, 71510, 71778, 71838, 72775, 73650, 75964, 76731, 77333, 77563, 77728, 77850,

LinuxSecurity.com: New version, security fix for CVE-2017-1000381.

News in brief: Alexa as wiretap; Prankster fools White House; Amazon suspends Blu

LinuxSecurity.com: V1.0 final release —- bump runc commit —- Update to latest release candidate

LinuxSecurity.com: Fix for multiple CVEs

LinuxSecurity.com: Security fix for CVE-2017-7525

LinuxSecurity.com: Fix for multiple CVEs

Anatomy of a privacy fail – when “Dark Data” gives away your identity
Should governments keep vulnerabilities secret?
Amazon Halts Sale of Android Blu Phone Amid Spyware Concerns
Breach at Third Party Contractor Affects 18,000 Anthem Members
Svpeng Android Banking Trojan Tweaked with Keylogger Feature
Multiple vulnerabilities found in radiation monitoring gateways
Popular Chrome extension hacked to deliver adware
Hackers could install malware on your Amazon Echo to secretly ‘wiretap’ you
Dutch Police Nabs Romanian Gang for Stealing $590K worth of iPhones
Trojan found pre-installed on Android phones being sold on Amazon
Pharmaceutical Giant Still Feeling NotPetya’s Sting

LinuxSecurity.com: New version, security fix for CVE-2017-1000381.

Copyfish Browser Extension Hijacked to Spew Spam
Why you should view torrents as a threat

Despite their popularity among users, torrents are a very risky “business”. Apart from the obvious legal trouble you could face for violating the copyright of musicians, filmmakers or software developers, there are security issues as well. The post Why you should view torrents as a threat appeared first on WeLiveSecurity

Def Con hackers showed how easily voting machines can be hacked
‘Real people’ do not want secure communications, claims UK Home Secretary Amber Rudd
How are you going to protect the next generation of your Mobile Applications?
Game of Thrones data leaked in HBO hack

LinuxSecurity.com: A security issues were fixed in Bash.

LinuxSecurity.com: Tyler Bohan of Talos discovered that FreeRDP, a free implementation of the Remote Desktop Protocol (RDP), contained several vulnerabilities that allowed a malicious remote server or a man-in-the-middle to either cause a DoS by forcibly terminating the client, or execute

HBO Hacked – Upcoming Game of Thrones Episodes and Data Leaked