LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: It was discovered that PHP5 was vulnerable to a reflected cross-site scripting (XSS) attack on the PHAR 404 error page by manipulating the URI of a request for a .phar file. This issue is only exploitable if the web server is configured to handle phar files using PHP5.
“How to buy Bitcoin” dominated Google how-to searches in 2017, ranking third overall. With the hype surrounding cryptocurrency at a palpably all-time high, now is a better time than ever to cover the essentials of keeping cryptocurrencies safe. If you are just getting into the crypto space or you’ve known what ‘HODL’ means for a […]
security update
Type: Vulnerability. Microsoft Office for MAC is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.
The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any questions? Just ask. Hospital Pays Ransom to Restore Systems, Despite Having Backups In the first cyberattack of 2018 to hit […]
LinuxSecurity.com: It was discovered that there was a denial-of-service attack in the libgd2 image library. A corrupt file could have exploited a signedness confusion leading to an infinite loop.
LinuxSecurity.com: It was discovered that there was an injection vulnerability in the rsync file-copying tool. For Debian 7 “Wheezy”, this issue has been fixed in rsync version
Granted, not all that glitters is gold, and mobiles also come with some drawbacks in terms of the protection of information. There are a number of risks that users may face when trying to secure their information on mobiles and tablets. The post Are mobile devices insecure by nature? appeared first on WeLiveSecurity
LinuxSecurity.com: The cPanel Security Team discovered that awstats, a log file analyzer, was vulnerable to path traversal attacks. A remote unauthenticated attacker could leverage that to perform arbitrary code execution.
security update
LinuxSecurity.com: Tavis Ormandy discovered a vulnerability in the Transmission BitTorrent client; insecure RPC handling between the Transmission daemon and the client interface(s) may result in the execution of arbitrary code if a user visits a malicious website while Transmission is running.
LinuxSecurity.com: The package bind before version 9.11.2.P1-1 is vulnerable to denial of service.
LinuxSecurity.com: The package perl-xml-libxml before version 2.0130-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package nrpe before version 3.2.1-3 is vulnerable to arbitrary command execution.
LinuxSecurity.com: The package transmission-cli before version 2.92-8 is vulnerable to arbitrary command execution.
LinuxSecurity.com: The package irssi before version 1.0.6-1 is vulnerable to denial of service.
LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Fix permissions on rootsh log directory to limit it to root.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0094
LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0093
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0093
LinuxSecurity.com:
LinuxSecurity.com: This is new version of irssi. It contains security fixes for CVE-2018-5205 CVE-2018-5206 CVE-2018-5207 CVE-2018-5208 .
LinuxSecurity.com: – Resolves: #1510351 – CVE-2017-14992 – built docker @projectatomic/docker-1.13.1 commit 584d391 – built docker-novolume-plugin commit 385ec70 – built rhel-push-plugin commit af9107b – built docker-lvm-plugin commit 8647404 – built docker-runc @projectatomic/docker-1.13.1 commit 1c91122 – built docker-containerd @projectatomic/docker-1.13.1 commit 62a9c60 – built
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan.
Not content anymore to just have a bed made of soft plushy stuff, now you can adjust everything about the bed, from electronically sitting up in bed to the lighting surrounding your nap: connected digital technology everywhere. The post CES 2018 cybersecurity: Now in every single ‘whatchamacallit’ appeared first on WeLiveSecurity
The depth of data collected from our online habits could easily allow profiles to be constructed, showing what may be considered extremely personal interests, drawing on information that we don’t realize someone is collecting. The post Trends 2018: Personal data in the new age of technology and legislation appeared first on WeLiveSecurity
LinuxSecurity.com: Security fix for CVE-2018-5702 (Mitigate dns rebinding attacks against daemon)
LinuxSecurity.com: – Update to 52.5.3 – Patched for mozilla bug-1427870 (spectre mitigation)
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: – Update to 52.5.3 – Patched for mozilla bug-1427870 (spectre mitigation)
LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.
LinuxSecurity.com: It was discovered that multiple encryption key classes in the Librariescomponent of OpenJDK did not properly synchronize access to their internaldata. This could possibly cause a multi-threaded Java application to applyweak encryption to data because of the use of a key that was zeroed out.(CVE-2018-2579)Note: If the web browser plug-in provided by the icedtea-web […]
security update
