LinuxSecurity.com: Cure53 discovered that in SimpleSAMLphp, in rare circumstances an invalid signature on the SAML 2.0 HTTP Redirect binding could be considered valid.
City officials confirm that Atlanta is dealing with a cyberattack that has locked down some internal systems and is holding them hostage using ransomware The post City of Atlanta computers held hostage in ransomware attack appeared first on WeLiveSecurity
The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Zenis Ransomware Makes Resolution Problematic for Victims Researchers recently discovered a new ransomware variant named Zenis that […]
LinuxSecurity.com: An update that solves 8 vulnerabilities and has four fixes is now available.
LinuxSecurity.com: Charles Duffy discovered that the Commandline class in the utilities for the Plexus framework performs insufficient quoting of double-encoded strings, which could result in the execution of arbitrary shell commands.
LinuxSecurity.com: Alfred Farrugia and Sandro Gauci discovered an off-by-one heap overflow in the Kamailio SIP server which could result in denial of service and potentially the execution of arbitrary code.
LinuxSecurity.com: Several vulnerabilities have been discovered in the ISC DHCP client, relay and server. The Common Vulnerabilities and Exposures project identifies the following issues:
LinuxSecurity.com: Huzaifa Sidhpurwala discovered that an out-of-bounds memory write in the codebook parsing code of the Libtremor multimedia library could result in the execution of arbitrary code if a malformed Vorbis file is opened.
security update
LinuxSecurity.com: Several vulnerabilities were discovered in PolarSSL, a lightweight crypto and SSL/TLS library, that allowed a remote attacker to either cause a denial-of-service by application crash, or execute arbitrary code.
Latest ESET research strongly suggests that Glupteba is no longer tied to the infamous Operation Windigo. The post Glupteba is no longer part of Windigo appeared first on WeLiveSecurity
LinuxSecurity.com: An update is now available for Red Hat JBoss BPM Suite. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update is now available for Red Hat JBoss BRMS. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: The package lib32-libvorbis before version 1.3.6-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.
LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may lead to arbitrary code execution.
LinuxSecurity.com: Gentoo’s collectd package contains multiple vulnerabilities, the worst of which may allow local attackers to escalate privileges.
LinuxSecurity.com: An update that solves 8 vulnerabilities and has four fixes is now available.
security update
LinuxSecurity.com: Various issues were discovered in exempi, a library to parse XMP metadata that may cause a denial-of-service or may have other unspecified impact via crafted files.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0549
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0549
LinuxSecurity.com: An update for collectd is now available for RHEV 4.X RHEV-H and Agents for RHEL-7 and RHEV Engine version 4.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Since inception in late 2016, the TrickBot banking trojan has continually undergone updates and changes in attempts to stay one step ahead of defenders. While TrickBot has not always been the stealthiest trojan, its authors have remained consistent in the use of new distribution vectors and development of new features for their product. On March […]
Risk Level: Very Low. Type: Trojan.
The research confirmed that the more time the users spent on pirate sites the higher the likelihood that some type of malware would compromise their computers. The post Pirate websites expose users to more malware, study finds appeared first on WeLiveSecurity
LinuxSecurity.com: An update for rh-mariadb101-mariadb and rh-mariadb101-galera is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
In light of the publicity, panic, and lingering despair around Spectre and Meltdown, I thought this might be a good time to clear up the differences between vulnerabilities, exploits, and malware. Neither Spectre nor Meltdown are exploits or malware. They are vulnerabilities. Vulnerabilities don’t hurt people, exploits and malware do. To understand this distinction, witness […]
LinuxSecurity.com: Paramiko could be made to run programs if it received speciallycrafted network traffic.
LinuxSecurity.com: Paramiko could be made to run programs if it received speciallycrafted network traffic.
LinuxSecurity.com: This update upgrades Firefox to version 52.7.2 ESR. * Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) (CVE-2018-5146) SL6 x86_64 firefox-52.7.2-1.el6_9.x86_64.rpm firefox-debuginfo-52.7.2-1.el6_9.x86_64.rpm firefox-52.7.2-1.el6_9.i686.rpm firefox-debuginfo-52.7.2-1.el6_9.i686.rpm i386 firefox-52.7.2-1.el6_9.i686.rpm firefox-debuginfo-52.7.2-1.el6 [More…]
