LinuxSecurity.com: Security fix for CVE-2018-17336
LinuxSecurity.com: This is an update to Mozilla’s CA certificates list version 2.26, which has been published as part of Mozilla NSS 3.39. For additional details, please refer to the NSS 3.39 release notes: https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes
LinuxSecurity.com: libxkbcommon 0.8.2, CVE-2018-15853 through to 15864. These fix a number of memory handling issues with xkbcommon. Together with the keymap FD handling in various Wayland compositors (keymaps could be mapped rw and clients could thus replace the content) libxkbcommon’s memory issues could serve as attack vector to gain access to another client. The update […]
LinuxSecurity.com: Security fix for CVE-2018-17336
LinuxSecurity.com: Fixed some small bugs in the previous package: Initial rules now have the correct version, sought channel config is dropped (since it doesn’t exist anymore) and build / runtime deps adjusted. —- Update to 3.4.2. Fixes CVE-2017-15705, CVE-2018-11780 and CVE-2018-11781 along with many other bugfixes and improvements. See https://www.mail-
LinuxSecurity.com: **libbson 1.13.0** **Features:** * New functions to save and restore progress of a bson_iter_t: bson_iter_key_len, bson_iter_offset, and son_iter_init_from_data_at_offset Additional functions bson_iter_overwrite_date_time, bson_iter_overwrite_oid, and bson_iter_overwrite_timestamp. All fixed-length BSON values can now be
security update
LinuxSecurity.com: It was discovered that the emergency logging system in 389-ds-base (the 389 Directory Server) is affected by a race condition caused by the invalidation of the concurrently used log file file descriptor without proper locking. This issue might be triggered by remote attackers to
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2731
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2731
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2766
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2757
LinuxSecurity.com: CVE-2017-7653 As invalid UTF-8 strings are not correctly checked, an attacker could
LinuxSecurity.com: An update that contains security fixes can now be installed.
LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
security update
LinuxSecurity.com: Multiple security issues were discovered in Python: ElementTree failed to initialise Expat’s hash salt, two denial of service issues were found in difflib and poplib and a buffer overflow in PyString_DecodeEscape.
LinuxSecurity.com: This release fixes a heap-based buffer over-read when parsing a mallformed BSON document (CVE-2018-16790).
LinuxSecurity.com: Changes since 10.1.8.16: === v 10.1.9.6 handle legacy external message recipients * [XSS] Updated known HTML5 events * Better IPV6 support * UI support for protocol-only entries v 10.1.9.5
LinuxSecurity.com: Security fix for CVE-2018-10897
LinuxSecurity.com: This release fixes a heap-based buffer over-read when parsing a mallformed BSON document (CVE-2018-16790).
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
The timing of the attacks suggests that many attempts to take the networks offline may not necessarily be perpetrated by organized cybercriminal gangs The post Who’s behind DDoS attacks at UK universities? appeared first on WeLiveSecurity
Reading Time: ~2 min.Firefox Vulnerability Leads to Crash A new denial-of-service (DoS) attack has been created with the ability to cause desktop versions of the browser Firefox to freeze or crash. Upon visiting sites where the malicious script is present, the user’s browser forces download requests for a massive junk file that can cause the […]
LinuxSecurity.com: Several security issues were fixed in Mutt.
LinuxSecurity.com: CVE-2018-14404 Fix of a NULL pointer dereference which might result in a crash and thus in a denial of service.
LinuxSecurity.com: Multiple security issues were discovered in Python: ElementTree failed to initialise Expat’s hash salt, two denial of service issues were found in difflib and poplib and the shutil module was affected by a command injection vulnerability.
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty), Red Hat OpenStack Platform 9.0 (Mitaka), Red Hat OpenStack Platform 10.0 (Newton), Red Hat OpenStack Platform 12.0 (Pike), and Red Hat OpenStack Platform 13.0 (Queens).
ESET researchers have shown that the Sednit operators used different components of the LoJax malware to target a few government organizations in the Balkans as well as in Central and Eastern Europe The post LoJax: First UEFI rootkit found in the wild, courtesy of the Sednit group appeared first on WeLiveSecurity
LinuxSecurity.com: HylaFAX+ 5.6.1 vulnerabilities (18 Sep 2018)
LinuxSecurity.com: Security fix for CVE-2018-16435
LinuxSecurity.com: The 4.18.9 stable update contains a number of important fixes across the tree. —- The 4.18.8 update contains a number of important fixes across the tree
LinuxSecurity.com: Fix for CVE-2018-14630
LinuxSecurity.com: Fixed 2.1.0 update, includes security fixes and added performance fix
LinuxSecurity.com: Security fix for CVE-2017-5950.
