LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that contains security fixes can now be installed.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that contains security fixes can now be installed.
LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.
LinuxSecurity.com: zutils version prior to version 1.8-pre2 contains a buffer overflow vulnerability in zcat which happened with some input files when the ‘-v, –show-nonprinting’ option was
security update
LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2692
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2693
Reading Time: ~2 min.Massive Customer Database Left Exposed by Data Management Firm A security researcher recently found a database containing customer information for nearly half a billion users of Veeam software on an unsecured AWS server. Most of the data was contact information spanning from 2013 to 2017 and was likely used by the Veeam […]
LinuxSecurity.com: Updated flash-player-plugin packages fix security vulnerability: Successful exploitation of the currently un-disclosed vulerability could lead to information disclosure (CVE-2018-15967).
LinuxSecurity.com: Updated ntp packages fix security vulnerability: Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6
LinuxSecurity.com: New ghostscript packages are available for Slackware 14.2 and -current to fix security issues.
LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Taking advantage of the celebration of the Day of the Programmer, we share some audit tools to evaluate the security of your code The post Programmer’s Day: Resources to audit your code appeared first on WeLiveSecurity
ESET researchers have discovered several third-party add-ons for the popular open-source media player Kodi being used to distribute Linux and Windows cryptocurrency-mining malware The post Kodi add-ons launch cryptomining campaign appeared first on WeLiveSecurity
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: USN-3747-1 introduced a regression in OpenJDK 10.
security update
security update
Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Exchange Server is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore Scripting Engine is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote privilege-escalation vulnerability; fixes are available.
Microsoft and Adobe have each shipped out their scheduled batches of patches to address security flaws in their respective software The post Patch Tuesday: Microsoft plugs zero-day hole exploited by PowerPool appeared first on WeLiveSecurity
LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has four fixes is now available.
LinuxSecurity.com: Two input sanitization failures have been found in the faxrunq and faxq binaries in mgetty. An attacker could leverage them to insert commands via shell metacharacters in jobs id and have them executed with the
LinuxSecurity.com: It was discovered that there was a denial of service and a potential arbitrary code execution vulnerability in the kamailio SIP server. A specially-crafted SIP message with an invalid “Via” header could cause a
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: Updates for rh-dotnet21 and rh-dotnet21-dotnet are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Low.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: Two input sanitization failures have been found in the faxrunq and faxq binaries in mgetty, a smart modem getty replacement. An attacker could leverage them to insert commands via shell metacharacters in jobs id and have them executed with the privilege of the faxrunq/faxq user.
