Type: Vulnerability. Multiple CPU Hardwares are prone to an information-disclosure vulnerability; fixes are available.
LinuxSecurity.com: Rebase `osc` and `osc-source_validator` to new versions for security fixes for CVE-2017-9274
LinuxSecurity.com: Rebase `osc` and `osc-source_validator` to new versions for security fixes for CVE-2017-9274
The attackers gained access to a range of customer data such as names, addresses, phone numbers, dates of birth, and marital status. Making matters worse, the historical payment card details of some 18,000 customers were also compromised. The post Carphone Warehouse faces hefty fine for 2015 breach appeared first on WeLiveSecurity
The first obvious candidate was banking, a sector that has been hard at work trying to implement blockchain to secure the vast troves of digital transactions that happen every microsecond of every day. The post CES 2018: Blockchain will solve everything appeared first on WeLiveSecurity
LinuxSecurity.com: Multiple vulnerabilities have been found in rsync, the worst of which could allow remote attackers to bypass access restrictions.
security update
LinuxSecurity.com: An update for microcode_ctl is now available for Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red
LinuxSecurity.com: The Check Point Research Team discovered that the XBMC media center allows arbitrary file write when a malicious subtitle file is downloaded in zip format. This update requires the new dependency libboost-regex1.49.
LinuxSecurity.com: An update for linux-firmware is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions, and Red Hat Enterprise Linux 7.3
LinuxSecurity.com: Jayachandran Palanisamy of Cygate AB reported that BIND, a DNS server implementation, was improperly sequencing cleanup operations, leading in some cases to a use-after-free error, triggering an assertion failure and crash in named.
LinuxSecurity.com: An update that solves 14 vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: Transmission could be made to run arbitraty code.
LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
LinuxSecurity.com: Qtpass password generation had a bug where only a 1000 different passwords where possible https://github.com/IJHack/QtPass/issues/338 —- Upstream release
LinuxSecurity.com: Qtpass password generation had a bug where only a 1000 different passwords where possible https://github.com/IJHack/QtPass/issues/338
LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.
LinuxSecurity.com: An update that solves 7 vulnerabilities and has three fixes is now available.
Risk Level: Very Low. Type: Trojan.
It’s easier to have scruples about how you earn your living when you’re not one of millions of people chasing just a few thousand jobs. The post Scammers and jobhunters appeared first on WeLiveSecurity
LinuxSecurity.com: This release does a complete update of the CA list. This includes removing the StartCom and WoSign certificates to as they are now untrusted by the major browser vendors.
LinuxSecurity.com: New kernel packages are available for Slackware 14.0 and 14.2 to fix security issues.
LinuxSecurity.com: A vulnerability has been discovered in GraphicsMagick, a collection of image processing tools, which may result in a denial of service.
LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: It was discovered that multiple integer overflows in the GIF image loader in the GDK Pixbuf library may result in denial of service and potentially the execution of arbitrary code if a malformed image file is opened.
security update
LinuxSecurity.com: Several security issues were fixed in GDK-PixBuf.
LinuxSecurity.com: David Sopas discovered that Kohana, a PHP framework, was vulnerable to a Cross-site scripting (XSS) attack that allowed remote attackers to inject arbitrary web script or HTML by bypassing the strip_image_tags protection mechanism in system/classes/Kohana/Security.php. This issue
One side effect of slower than expected uptake of VR is that virtual reality application developers have been slow to invest in creating content. In this sort of chicken-and-egg cycle, growth tends to be slow, not explosive. The post CES 2018: Why doesn’t everyone use VR already? appeared first on WeLiveSecurity
LinuxSecurity.com: Multiple vulnerabilities have been found in PolarSSL, the worst of which may allow remote attackers to execute arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which could allow for privilege escalation.
LinuxSecurity.com: Philip Huppert discovered the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to mishandling of DTDs in the XMLTooling XML parsing library. For additional details please refer to the upstream advisory at
LinuxSecurity.com: The package qtpass before version 1.2.1-1 is vulnerable to private key recovery.
security update
LinuxSecurity.com: Tavis Ormandy discovered a vulnerability in the Transmission BitTorrent client; insecure RPC handling between the Transmission daemon and the client interface(s) may result in the execution of arbitrary code if a user visits a malicious website while Transmission is running.
