LinuxSecurity.com: Several vulnerabilities have been found in OpenSSH, a free implementation of the SSH protocol suite:
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: Several heap-based buffer over-reads were found in discount, an implementation of the Markdown markup language in C, that allowed remote attackers to cause a denial-of-service via specially crafted files.
security update
security update
security update
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: It was discovered that there was a an integer overflow vulnerability in curl, a command line tool for transferring data over HTTP, etc. For more information, please see:
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.
LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.
LinuxSecurity.com:
LinuxSecurity.com: Tavis Ormandy discovered multiple vulnerabilites in Ghostscript, an interpreter for the PostScript language, which could result in denial of service, the creation of files or the execution of arbitrary code if a malformed Postscript file is processed (despite the dSAFER sandbox being
LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and use-after-frees may lead to the execution of arbitrary code or denial of service.
LinuxSecurity.com: transfig could be made to execute arbitrary code if it received a specially crafted FIG file.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, informations leaks or privilege escalation.
Reading Time: ~2 min.Banking Trojans Still Appearing in Google Play Store Multiple security researchers recently discovered a handful of banking trojans that have still managed to make their way into the Google Play app store, despite Google having increased its security to detect such apps. Many of the apps are disguised as astrology/horoscope software, but […]
LinuxSecurity.com: Updated libxkbcommon packages fix security vulnerabilities: Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation
LinuxSecurity.com: Updated wireshark packages fix security vulnerabilities: Bluetooth Attribute Protocol dissector crash (CVE-2018-16056). Radiotap dissector crash (CVE-2018-16057).
LinuxSecurity.com: Updated sleuthkit packages fix security vulnerabilities: In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libtskfs.a, as demonstrated by fls (CVE-2017-13755).
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: Firefox could be made to crash or run programs as your login if it opened a malicious website.
LinuxSecurity.com: Several vulnerabilities were found in qemu, a fast processor emulator: CVE-2015-8666
security update
security update
LinuxSecurity.com: Several security issues were fixed in libtirpc.
LinuxSecurity.com: Several security issues were fixed in libtirpc.
Risk Level: Very Low. Type: Trojan.
Far-fetched though it may sound, the answer is yes, according to researchers, who show that electrical grids and smart home appliances could make for a dangerous mix The post Could home appliances knock down power grids? appeared first on WeLiveSecurity
LinuxSecurity.com: It was discovered that there was an integer overflow vulnerability in the “Little CMS 2” colour management library. A specially-crafted input file could lead to a heap-based buffer overflow.
LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.2 to fix security issues.
LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.
LinuxSecurity.com: New ghostscript packages are available for Slackware 14.2 and -current to fix security issues.
Reading Time: ~4 min.If you saw a file called eicar.com on your computer, you might think it was malware. But, you would be wrong. Readers, if you haven’t yet met the EICAR test file, allow me to introduce you to it. If you have used the EICAR test file, let’s get a bit cozier with […]
LinuxSecurity.com: Zhaoyang Wu discovered that cURL, an URL transfer library, contains a buffer overflow in the NTLM authentication code triggered by passwords that exceed 2GB in length on 32bit systems.
security update
