LinuxSecurity.com: Jesse Schwartzentruber discovered a use-after-free vulnerability in Firefox, which could be exploited to trigger an application crash or arbitrary code execution.
security update
LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:
LinuxSecurity.com: It was discovered that a use-after-free in the compositor of Firefox can result in the execution of arbitrary code. For the oldstable distribution (jessie), this problem has been fixed
LinuxSecurity.com: An update that solves 9 vulnerabilities and has four fixes is now available.
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
security update
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0592
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: A vulnerability in PLIB may allow remote attackers to execute arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in BusyBox, the worst of which could allow remote attackers to execute arbitrary code.
LinuxSecurity.com: It was discovered that there was an issue in the irssi IRC client where certain nick names could result in out-of-bounds access when printing theme strings.
LinuxSecurity.com: It was discovered that there was a heap corruption vulnerability in the net-snmp framework which exchanges server management information in a network.
LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: The package bchunk before version 1.2.2-4 is vulnerable to denial of service.
Using the strategies and procedures we present in our paper could help prevent an attacker from taking control of your computer The post The Last Windows XP Security White Paper appeared first on WeLiveSecurity
LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.
The oil and gas industry is the target of as much as one-half of all cyberattacks in the Middle East The post Oil & gas industry in Middle East found lagging in security appeared first on WeLiveSecurity
ATM jackpot gang is thought to have infiltrated over 100 financial firms in 40 countries costing banks more than one billion dollars. The post Police arrest members of cybercrime gang appeared first on WeLiveSecurity
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: Richard Zhu and Huzaifa Sidhpurwala discovered that an out-of-bounds memory write when playing Vorbis media files could result in the execution of arbitrary code.
LinuxSecurity.com: slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution (CVE-2018-8088) SL7 noarch slf4j-1.7.4-4.el7_4.noarch.rpm slf4j-javadoc-1.7.4-4.el7_4.noarch.rpm slf4j-manual-1.7.4-4.el7_4.noarch.rpm – Scientific Linux Development Team
LinuxSecurity.com: Bas van Schaik and Kevin Backhouse discovered a stack-based buffer overflow vulnerability in librelp, a library providing reliable event logging over the network, triggered while checking x509 certificates from a peer. A remote attacker able to connect to rsyslog can take
LinuxSecurity.com: An update for slf4j is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: The package thunderbird before version 52.7.0-1 is vulnerable to multiple issues including arbitrary code execution and access restriction bypass.
WeLiveSecurity sat down with David Harley to get a better understanding of Critical Infrastructure and the role he has played in the area throughout his career. The post Critical Infrastructure Interview with David Harley appeared first on WeLiveSecurity
LinuxSecurity.com: An update for rh-ruby23-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for rh-mysql57-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for rh-ruby24-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for rh-ruby22-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for rh-maven35-slf4j is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
LinuxSecurity.com: Daniel P. Berrange and Peter Krempa of Red Hat discovered a flaw in libvirt, a virtualization API. A lack of restriction for the amount of data read by QEMU Monitor socket can lead to a denial of service by exhaustion of memory resources.
security update
LinuxSecurity.com: Wojciech Regu?a discovered that Freeplane, a program for working with mind maps, was affected by a XML External Entity (XXE) vulnerability in its mindmap loader that could compromise a user’s machine by opening a specially crafted mind map file.
LinuxSecurity.com: Samba could be made to crash if it received specially crafted input.
LinuxSecurity.com: An update that solves 10 vulnerabilities and has 70 fixes is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
security update
security update
LinuxSecurity.com: Sharutils could be made to execute arbitrary code if it opened a specially crafted file.
LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.
LinuxSecurity.com: It was discovered that there was a server-side request forgery exploit in adminer, a web-based database administration tool. Adminer allowed unauthenticated connections to be initiated to arbitrary
