LinuxSecurity.com: Rebased to 1.37.0.
security update
LinuxSecurity.com: Philip Huppert discovered the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to mishandling of DTDs in the XMLTooling XML parsing library. For additional details please refer to the upstream advisory at
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves three vulnerabilities and has 5 fixes is now available.
The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst with a passion for all things security. Any questions? Just ask. Exploitable Backdoor Found in Western Digital NAS Drives Western Digital has recently released numerous patches for the vulnerabilities that were […]
LinuxSecurity.com: It was discovered that gifsicle, a tool for manipulating GIF image files, contained a flaw that could lead to arbitrary code execution. For the oldstable distribution (jessie), this problem has been fixed
The distribution of the USB sticks was halted on December 12 after some of the quiz’s successful entrants reported that their rewards had been flagged by their security software as containing malware. The post Security event in Taiwan ‘rewards’ quiz winners with malware-laden USB drives appeared first on WeLiveSecurity
LinuxSecurity.com: Security fix for CVE-2017-1000501
security update
LinuxSecurity.com: Multiple vulnerabilities have been found in icoutils, the worst of which may lead to arbitrary code execution.
LinuxSecurity.com: Multiple vulnerabilities have been found in TigerVNC, the worst of which may lead to arbitrary code execution.
LinuxSecurity.com: A vulnerability in PySAML2 might allow remote attackers to bypass authentication.
LinuxSecurity.com: The package intel-ucode before version 20180108-1 is vulnerable to access restriction bypass.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in Ming: CVE-2017-11732
Row after row of startup tech here has tiny modules designed to be mashed up into the next big thing if their founders have anything to say about it, and the trend continues. The post CES 2018: The price of tech is dropping, kids can do this! appeared first on WeLiveSecurity
LinuxSecurity.com: Stephan Zeisberg discovered that poco, a collection of open source C++ class libraries, did not correctly validate file paths in ZIP archives. An attacker could leverage this flaw to create or overwrite arbitrary files.
security update
Risk Level: Very Low. Type: Trojan.
security update
Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Outlook is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Word is prone to a memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Office is prone to a memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Access is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Outlook is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.
Risk Level: Very Low. Type: Trojan.
Bitcoin, the progenitor of the entire cryptocurrency boom and still the most popular virtual currency, experienced a truly heady run-up in value. Its price surge was punctuated with a crescendo midway through December, when a single bitcoin approached $20,000. The post Tank-traps versus trappings in virtual currencies: A cybersecurity minefield appeared first on WeLiveSecurity
LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: The system could be made to expose sensitive information.
LinuxSecurity.com: The system could be made to expose sensitive information.
LinuxSecurity.com: Microcode update for AMD cpus
LinuxSecurity.com: Security fix for CVE-2017-1000456.
LinuxSecurity.com: Security fix for CVE-2017-17784 CVE-2017-17785 CVE-2017-17786 CVE-2017-17787 CVE-2017-17788 CVE-2017-17789
Risk Level: Very Low. Type: Trojan.
