In the past, security awareness training for user education—i.e. empowering users to make more savvy IT decisions in their daily routines—was considered a “nice to have,” not a necessity. The decision to adopt user education was typically passed over because of budget, lack of in-house expertise, and the general lack of availability of high-quality, low-cost, […]
LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.
LinuxSecurity.com: quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code (CVE-2018-5379) SL7 x86_64 quagga-0.99.22.4-5.el7_4.i686.rpm quagga-0.99.22.4-5.el7_4.x86_64.rpm quagga-debuginfo-0.99.22.4-5.el7_4.i686.rpm quagga-debuginfo-0.99.22.4-5.el7_4.x86_64.rpm quagga-contrib-0.99.22.4-5.el7_4.x86_64. [More…]
LinuxSecurity.com: It was discovered that the Net::FTP module did not properly process filenames in combination with certain operations. A remote attacker could exploit this flaw to execute arbitrary commands by setting up a malicious FTP server and tricking a user or Ruby application into downloading files with specially crafted names using the Net::FTP module. (CVE-2017-17405) […]
security update
security update
security update
LinuxSecurity.com: An update for ruby is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: create a separate user for dnsmasq.
LinuxSecurity.com: The textbook ElGamal implementation is not secure. PyCrypto and some other implementations use the wrong algorithm, which may lead to some information disclosure simply by looking at the encrypted text. For a full description, see https://github.com/dlitz/pycrypto/issues/253 This update includes a fix for this problem backported from pycryptodome.
LinuxSecurity.com: Use default RPM build flags and configure parameters (#1539097) Remove group writable bit from some config files (#1528445)
LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
The blinding server randomly adds some nonsense code to every webpage. This ‘code obfuscation’, according to the academics, has no effect on what the actual page looks like, but it drastically changes the appearance of the underlying source file. The post Researchers unveil Veil to make ‘private browsing more private’ appeared first on WeLiveSecurity
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0350
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0349
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0349
The recent rise in cryptocurrency scams appearing on the Android platform in disguise has shown that such incidents are not exclusive to PCs and also highlight the importance of knowing what to look out for so you do not unintentionally take part. The post Cryptocurrency scams on Android: do you know what to watch out […]
LinuxSecurity.com: The package mbedtls before version 2.7.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: An update that solves 9 vulnerabilities and has 40 fixes is now available.
LinuxSecurity.com: Two vulnerabilities have been found in Solr, a search server based on Lucene, which could result in the execution of arbitrary code or path traversal.
LinuxSecurity.com: Kelby Ludwig and Scott Cantor discovered that the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to incorrect XML parsing. For additional details please refer to the upstream advisory at
LinuxSecurity.com: Joonun Jang discovered several problems in wavpack, an audio compression format suite. Incorrect processing of input resulted in several heap- and stack-based buffer overflows, leading to application crash or potential code execution.
LinuxSecurity.com: From upstream announcement: **Security fix: phpMyAdmin 4.7.8 is released** Welcome to phpMyAdmin 4.7.8, a security releaes also containing regular maintenance bug fixes. The security fix relates to a self-XSS vulnerability in the central columns feature that is reported as PMASA-2018-1 https://www.phpmyadmin.net/security/PMASA-2018-1/. Thanks to Mayur Udiniya
LinuxSecurity.com: A flaw was found in the AWT component of OpenJDK. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions. (CVE-2018-2641) * It was discovered that the LDAPCertStore class in the JNDI component of OpenJDK failed to securely handle LDAP referrals. An attacker could possibly use this flaw […]
LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code execution (CVE-2018-5345) SL7 x86_64 gcab-debuginfo-0.7-4.el7_4.i686.rpm gcab-debuginfo-0.7-4.el7_4.x86_64.rpm libgcab1-0.7-4.el7_4.i686.rpm libgcab1-0.7-4.el7_4.x86_64.rpm gcab-0.7-4.el7_4.x86_64.rpm libgcab1-devel-0.7-4.el7_4.i686.rpm libgcab1-devel-0.7-4.el7_4.x86 [More…]
LinuxSecurity.com: An update for gcab is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: It was discovered that there was an arbitrary command execution vulnerability in the Go programming language. The “go get” implementation did not correctly validate “import path”
Bots that traverse the internet on behalf of their human operators can fulfill both legitimate and malicious automated tasks. Statistics indicate that bot-driven internet traffic, by helper and harmful bots combined, surpasses human traffic. The post Over 40% of online login attempts are attackers trying to invade accounts appeared first on WeLiveSecurity
LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available.
The Internet of Things (IoT) can be a network of connected convenience but this should not come at the expense of safeguarding your privacy and the personal data that connected devices collect and share. The post Privacy by Design: Can you create a safe smart home? appeared first on WeLiveSecurity
LinuxSecurity.com: This update updates QtWebEngine to the 5.10.1 bugfix and security release. QtWebEngine 5.10.1 is part of the Qt 5.10.1 release, but only the QtWebEngine component is included in this update. This update includes: * Security fixes from Chromium up to version 64.0.3282.140. Including: CVE-2017-15407, CVE-2017-15409, CVE-2017-15410, CVE-2017-15411, CVE-2017-15415, CVE-2017-15416,
LinuxSecurity.com: New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35
LinuxSecurity.com: New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35
LinuxSecurity.com: CVE-2017-13194 Fix for a flaw in libvpx related to odd frame width, which may lead to a denial of service.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: Multiple vulnerabilities have been found in the Drupal content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2018-001
LinuxSecurity.com: It was discovered that there was a remote denial of service vulnerability in the imagemagick graphics library via a specially- crafted TIFF file.
LinuxSecurity.com: This update includes the changes in tzdata 2018c for the Perl bindings. For the list of changes, see DLA-1291-1. For Debian 7 “Wheezy”, these problems have been fixed in version
LinuxSecurity.com: This update includes the changes in tzdata 2018c. Notable changes are: – S?o Tom? and Pr?ncipe switched from +00 to +01. – Brazil’s DST will now start on November’s first Sunday.
LinuxSecurity.com: The package lib32-wavpack before version 5.1.0-2 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package unixodbc before version 2.3.5-1 is vulnerable to arbitrary code execution.
