security update
LinuxSecurity.com: **PHP version 7.1.15** (01 Mar 2018) **Apache2Handler:** * Fixed bug php#75882 (a simple way for segfaults in threadsafe php just with configuration). (Anatol) **Date:** * Fixed bug php#75857 (Timezone gets truncated when formatted). (carusogabriel) * Fixed bug php#75928 (Argument 2 for `DateTimeZone::listIdentifiers()` should accept `null`). (Pedro Lacerda) * Fixed
LinuxSecurity.com: Bjorn Bosselmann discovered that the umount bash completion from util-linux does not properly handle embedded shell commands in a mountpoint name. An attacker with rights to mount filesystems can take advantage of this flaw for privilege escalation if a user (in particular
LinuxSecurity.com: It was discovered that there were multiple vulnerabilities in the “zsh” shell: * CVE-2014-10070: Fix a privilege-elevation issue if the
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0378
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0377
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0414
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0406
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0418
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0395
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0469
LinuxSecurity.com: Several security issues were fixed in ClamAV.
LinuxSecurity.com: Several security issues were fixed in Zsh.
Since being founded in 2003, the Italian spyware vendor Hacking Team gained notoriety for selling surveillance tools to governments and their agencies across the world. The capabilities of its flagship product, the Remote Control System (RCS), include extracting files from a targeted device, intercepting emails and instant messaging, as well as remotely activating a device’s […]
The problem was particularly acute among provider organizations, as opposed to payer organizations (21% vs. 12%). Also, and perhaps counterintuitively, staff with more frequent cybersecurity training were more inclined to such practices. The post One in five healthcare employees willing to sell patient data, study finds appeared first on WeLiveSecurity
LinuxSecurity.com: An update for dhcp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: The system could be made to expose sensitive information.
The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. MoviePass Subscription Service Tracks More Than Your Viewing Habits The CEO of MoviePass recently revealed the full […]
LinuxSecurity.com: dhcp: Buffer overflow in dhclient possibly allowing code execution triggered by malicious server (CVE-2018-5732) * dhcp: Reference count overflow in dhcpd allows denial of service (CVE-2018-5733) SL6 x86_64 dhclient-4.1.1-53.P1.el6_9.3.x86_64.rpm dhcp-4.1.1-53.P1.el6_9.3.x86_64.rpm dhcp-common-4.1.1-53.P1.el6_9.3.x86_64.rpm dhcp-debuginfo-4.1.1-53.P1.el6_9.3.i686.rpm dh [More…]
LinuxSecurity.com: An update that solves 10 vulnerabilities and has four fixes is now available.
security update
LinuxSecurity.com: Several functions were extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in several regular expressions.
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 3.1 for RHEL 6 and Red Hat JBoss Web Server 3.1 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 3.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
DDoS mitigation service Arbor Networks has announced that an undisclosed US company has suffered an attack fueled by internet-facing Memcached servers that clocked in at 1.7 terabits per second (Tbps), beating the previous record of 1.35 Tbps. The post New DDoS attack method breaks record again, adds extortion appeared first on WeLiveSecurity
