LinuxSecurity.com: The package chromium before version 67.0.3396.79-1 is vulnerable to access restriction bypass.
LinuxSecurity.com: The package krb5 before version 1.16.1-1 is vulnerable to insufficient validation.
security update
security update
security update
security update
LinuxSecurity.com: This update fixes CVE-2016-10040, a stack overflow in QXmlSimpleReader due to a too lenient entityCharacterLimit in our version of the patch for CVE-2013-4549. (The limit was increased from the upstream 1024 to 65536 to address QTBUG-35459, an issue where the security fix was breaking existing real-world XML files. Unfortunately, that is too much to […]
LinuxSecurity.com: Security fix for CVE-2018-8013. Updated to upstream release 1.10.
LinuxSecurity.com: Alexander Peslyak discovered that insufficient input sanitising of RFB packets in LibVNCServer could result in the disclosure of memory contents.
LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.
LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.
LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.
LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.
LinuxSecurity.com: Ivan Fratric discovered a buffer overflow in the Skia graphics library used by Firefox, which could result in the execution of arbitrary code. For the oldstable distribution (jessie), this problem has been fixed
LinuxSecurity.com: New gnupg2 packages are available for Slackware 13.37, 14.0, 14.1, 14.2, and – -current to fix a security issue.
LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Satellite 5.6 and Red Hat Satellite 5.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. 92 Million Genealogy Site Accounts Compromised Earlier this week, genealogy and DNA testing site […]
LinuxSecurity.com: DWARF5 and split dwarf, including GNU DebugFission, support.
LinuxSecurity.com: Remove essentially unused pre_release tagging in spec file Fixup Makefile patch to include LDFLAGS in all linking commands
The security implications of devices connecting and sharing data The post Interred in the Internet of Everything appeared first on WeLiveSecurity
LinuxSecurity.com: Several vulnerabilities were discovered in jruby, a Java implementation of the Ruby programming language. They would allow an attacker to use specially crafted gem files to mount cross-site scripting attacks, cause denial of service through an infinite loop,
LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available.
security update
LinuxSecurity.com: A security issue was fixed in Unbound.
LinuxSecurity.com: The package radare2 before version 2.6.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.
LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Risk Level: Very Low.
The city has spent $5 million to restore files, rebuild impacted systems, and harden its cyber-defenses The post Atlanta’s ransomware attack: Police dashcam video archives lost forever appeared first on WeLiveSecurity
Hunting for secrets from high-profile targets while staying in the shadows The post InvisiMole: surprisingly equipped spyware, undercover since 2013 appeared first on WeLiveSecurity
LinuxSecurity.com: 8u171 update
LinuxSecurity.com: Security fix for CVE-2017-13685 CVE-2017-15286
LinuxSecurity.com: 8u171 update
New research into VPNFilter finds more devices hit by malware that’s nastier than first thought, making rebooting and remediating of routers more urgent. The post VPNFilter update: More bad news for routers appeared first on WeLiveSecurity
LinuxSecurity.com: Several security issues were fixed in procps-ng.
Reading Time: ~3 min.GDPR represents a massive paradigm shift for global businesses. Every organization that handles data belonging to European residents must now follow strict security guidelines and businesses are now subject to hefty fines if data breaches are not disclosed. Organizations around the world have been busy preparing to comply with these new regulations, […]
