LinuxSecurity.com: Several vulnerabilities have been discovered in the ISC DHCP client, relay and server. The Common Vulnerabilities and Exposures project identifies the following issues:
LinuxSecurity.com: Kernel: KVM: MMU potential stack buffer overrun during page walks (CVE-2017-12188, Important) * Kernel: KVM: debug exception via syscall emulation (CVE-2017-7518, Moderate) SL7 x86_64 kernel-3.10.0-693.21.1.el7.x86_64.rpm kernel-debug-3.10.0-693.21.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-693.21.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-693.21.1.el7.x86_64.rpm ke [More…]
LinuxSecurity.com: libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula (CVE-2018-6871) SL7 x86_64 libreoffice-base-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-calc-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-core-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-debuginfo-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-draw-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-emailmerge-5.0.6. [More…]
LinuxSecurity.com: php: Buffer over-read from unitialized data in gdImageCreateFromGifCtx function (CVE-2017-7890) SL7 x86_64 php-5.4.16-43.el7_4.1.x86_64.rpm php-bcmath-5.4.16-43.el7_4.1.x86_64.rpm php-cli-5.4.16-43.el7_4.1.x86_64.rpm php-common-5.4.16-43.el7_4.1.x86_64.rpm php-dba-5.4.16-43.el7_4.1.x86_64.rpm php-debuginfo-5.4.16-43.el7_4.1.x86_64.rpm php-devel-5.4.16-43.el7_4.1. [More…]
LinuxSecurity.com: 389-ds-base: remote Denial of Service (DoS) via search filters in SetUnicodeStringFromUTF_8 in collate.c (CVE-2018-1054) * 389-ds-base: Authentication bypass due to lack of size check in slapi_ct_memcmp function in ch_malloc.c (CVE-2017-15135) Bug Fix(es): * Previously, if an administrator configured an index for an attribute with a specific matching rule in the “nsMatchingRule” parameter, [More…]
LinuxSecurity.com: A vulnerability in Go might allow remote attackers to execute arbitrary commands during source code build.
LinuxSecurity.com: A vulnerability was discovered in util-linux, which could potentially lead to the execution of arbitrary code.
First thing’s first—I’d like to introduce myself. I’m senior security analyst Randy Abrams, and I’m delighted to be part of the Webroot team and our online community. Prior to joining the team, I was a research director responsible for analyzing and reporting the test results of antimalware products. I also helped create test methodologies and […]
While Denial of Service attacks amplified by the use of networks of bot-compromised PCs were becoming a notable problem by the turn of the century, DDoS extortion threats have accelerated in parallel (if less dramatically) with the rise in ransomware in the past few years. The post Trends 2018: The ransomware revolution appeared first on […]
LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Different flaws have been found in leptonlib, an image processing library.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update for libreoffice is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for php is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: The package python2-django before version 1.11.11-1 is vulnerable to denial of service.
LinuxSecurity.com: The package python2-django before version 1.11.11-1 is vulnerable to denial of service.
LinuxSecurity.com: The package python-django before version 1.11.11-1 is vulnerable to denial of service.
LinuxSecurity.com: Updated kernel packages that fix six bugs are now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Tools for mining cryptocurrencies also fall into this category, as in many cases the websites cannot warn users since they have been compromised themselves, hence even the administrators may not be aware that they are contributing to mining for the benefit of an attacker. The post Cryptojacking: the result of the “cryptocurrency rush” appeared first […]
LinuxSecurity.com: PostgreSQL could be made to execute arbitrary code.
LinuxSecurity.com: Twisted could be made to run programs if it received specially crafted network traffic.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, informations leaks or privilege escalation.
LinuxSecurity.com: An update that solves 10 vulnerabilities and has two fixes is now available.
More than three dozen cybercrime and digital forensics experts from 23 countries have investigated a simulated attack on a bank that had been carried out through an IoT device. The post Global police test their cyber-chops in simulated IoT attack appeared first on WeLiveSecurity
LinuxSecurity.com: The package mkinitcpio-busybox before version 1.28.1-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package busybox before version 1.28.1-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: It was discovered that there was a potential XML External Entity (XXE) attack in libjgraphx-java, a diagramming library for Java applications. For Debian 7 “Wheezy”, this issue has been fixed in libjgraphx-java version
security update
security update
security update
security update
security update
LinuxSecurity.com: Fix: Multiple vulnerabilities in RubyGems https://www.ruby- lang.org/en/news/2018/02/17/multiple-vulnerabilities-in-rubygems/
LinuxSecurity.com: The security update announced as DSA-4120-1 caused regressions on the powerpc kernel architecture (random programs segfault, data corruption). Updated packages are now available to correct this issue.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
