LinuxSecurity.com: The package lib32-openssl before version 1:1.1.0.h-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package zsh before version 5.5-1 is vulnerable to arbitrary code execution.
security update
LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Multiple vulnerabilities were discovered in the implementation of the Perl programming language. The Common Vulnerabilities and Exposures project identifies the following problems:
LinuxSecurity.com: Minor update from upstream with fix for CVE-2018-9234 and other bug fixes.
LinuxSecurity.com: * Rebase to Ruby 2.5.1. * Several CVE fixes. * Conflict requirement needs to generate dependency. * Stop using –with-setjmp-type=setjmp on aarch64.
LinuxSecurity.com: harden the binaries (rhbz#1548670)
LinuxSecurity.com: Security fix for CVE-2018-1086 and CVE-2018-1079 Rebased to latest upstream sources
LinuxSecurity.com: Fix CVE-2017-11550 and CVE-2004-2779
LinuxSecurity.com: Fixes several heap-buffer-overflows, see related Bugzilla tickets!
LinuxSecurity.com: GwanYeong Kim reported that ‘pack()’ could cause a heap buffer write overflow with a large item count. For Debian 7 “Wheezy”, these problems have been fixed in version
security update
LinuxSecurity.com: python-paramiko: Authentication bypass in transport.py (CVE-2018-7750) SL6 noarch python-paramiko-1.7.5-4.el6_9.noarch.rpm – Scientific Linux Development Team
LinuxSecurity.com: USN-3621-1 caused a regression in Ruby.
LinuxSecurity.com: The package apache before version 2.4.33-1 is vulnerable to multiple issues including session hijacking, access restriction bypass, content spoofing and denial of service.
Unlike its much more malicious counterparts, this ransomware has a rather benign demand. It also provides two curious ways of recovering one’s files. The post This ransomware wants you to play, not pay appeared first on WeLiveSecurity
A closer look at Anti-Malware tests and the somewhat unreliable nature of the process. The post Anti-Malware testing needs standards, and testers need to adopt them appeared first on WeLiveSecurity
In Part 1, our roundup of some of the most notable law enforcement actions against computer crime in the first quarter of 2018 will focus on arrests and charges involving suspected cyber-crooks. The post Quarterly cybercrime digest: Part 1 appeared first on WeLiveSecurity
Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Music-Oriented YouTube Channels Hacked Within the last week, hackers have defaced multiple YouTube music […]
LinuxSecurity.com: An update that solves three vulnerabilities and has 7 fixes is now available.
LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, and Red Hat Enterprise
Type: Vulnerability. Microsoft Jet Database Engine is prone to a buffer-overflow vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton), Red Hat OpenStack Platform 11.0 (Ocata), Red Hat OpenStack Platform 12.0 (Pike), Red Hat OpenStack Platform 8.0 (Liberty), and Red Hat OpenStack Platform 9.0 (Mitaka).
LinuxSecurity.com: An update for sensu is now available for Red Hat OpenStack Platform 11.0 Operational Tools for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: This updates LibOFX to fix assorted CVEs.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Worm.
Risk Level: Very Low. Type: Worm.
LinuxSecurity.com: It was discovered that the poppler upload for the oldstable distribution (jessie), released as DSA-4079-1, did not correctly address CVE-2017-9776 and additionally caused regressions when rendering PDFs embedding JBIG2 streams. Updated packages are now available to correct
LinuxSecurity.com: This update upgrades Firefox to version 52.7.3 ESR. * firefox: Use-after-free in compositor potentially allows code execution (CVE-2018-5148) SL6 x86_64 firefox-52.7.3-1.el6_9.x86_64.rpm firefox-debuginfo-52.7.3-1.el6_9.x86_64.rpm firefox-52.7.3-1.el6_9.i686.rpm firefox-debuginfo-52.7.3-1.el6_9.i686.rpm i386 firefox-52.7.3-1.el6_9.i686.rpm firefox-debuginfo-52.7.3-1 [More…]
LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.
Type: Vulnerability. Adobe Flash Player is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.
LinuxSecurity.com: Fixes for CVE-2018-1002150.
LinuxSecurity.com: This updates LibOFX to fix assorted CVEs.
LinuxSecurity.com: Several security issues were fixed in Patch.
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update that solves 5 vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that solves three vulnerabilities and has 7 fixes is now available.
