LinuxSecurity.com: Three vulnerabilities were discovered in the Open Ticket Request System which could result in privilege escalation or denial of service. For the stable distribution (stretch), these problems have been fixed in
LinuxSecurity.com: Updated texlive packages fix security vulnerability: A buffer overflow in the handling of Type 1 fonts allowed arbitrary code execution when a malicious font is loaded by one of the vulnerable tools: pdflatex, pdftex, dvips, or luatex (CVE-2018-17407).
LinuxSecurity.com: Updated firefox packages fix security vulnerabilities: A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered
LinuxSecurity.com: joernchen of Phenoelit discovered that git is prone to an arbitrary code execution vulnerability due to insufficient validation of submodule url and path via a specially crafted .gitmodules file in a project cloned with –recurse-submodules (CVE-2018-17456).
LinuxSecurity.com: Nextcloud has been updated to 13.0.6 and fixes atleast the following security issue: A missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization
security update
security update
LinuxSecurity.com: spamassassin: Certain unclosed tags in crafted emails allow for scan timeouts and result in denial of service (CVE-2017-15705) * spamassassin: Local user code injection in the meta rule syntax (CVE-2018-11781) SL7 x86_64 spamassassin-3.4.0-4.el7_5.x86_64.rpm spamassassin-debuginfo-3.4.0-4.el7_5.x86_64.rpm – Scientific Linux Development Team
LinuxSecurity.com: This update fixes several vulnerabilities in Imagemagick, a graphical software suite. Various memory handling problems or incomplete input sanitising have been found in the coders for BMP, DIB, PICT, DCM, CUT and PSD.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in Wireshark, a network protocol analyzer which could result in denial of service or the execution of arbitrary code.
security update
LinuxSecurity.com: The package wireshark-cli before version 2.6.4-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.
Risk Level: Very Low. Type: Trojan.
Reading Time: ~2 min.Latest Windows 10 Update Removes User Files Microsoft recently pulled its latest update, version 1809, after several users complained about personal files being deleted. While some users were able to use third-party software to retrieve deleted files, users whose files wnet missing from the Documents folder are having a much trickier time […]
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that contains security fixes can now be installed.
LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.
The times they are a-changin‘, so how do you build and sharpen the skills that you need to avoid being left behind by the digital revolution? The post Tips for minding the digital skills gap appeared first on WeLiveSecurity
LinuxSecurity.com: Git could be made to run programs as your login if it recursivelyopened a malicious git repository.
LinuxSecurity.com: An update for spamassassin is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: Magnus Klaaborg Stubman discovered a NULL pointer dereference bug in net-snmp, a suite of Simple Network Management Protocol applications, allowing a remote, authenticated attacker to crash the snmpd process (causing a denial of service).
Type: Vulnerability. The Microsoft .NET Core is prone to an information-disclosure vulnerability; fixes are available.
LinuxSecurity.com: Several security issues were fixed in Tex Live.
LinuxSecurity.com: An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
ESET’s analysis of a recent backdoor used by TeleBots – the group behind the massive NotPetya ransomware outbreak – uncovers strong code similarities to the Industroyer main backdoor, revealing a rumored connection that was not previously proven The post New TeleBots backdoor: First evidence linking Industroyer to NotPetya appeared first on WeLiveSecurity
As another confusing message spreads, we look at Facebook privacy, cloning, and hacking The post Send in the clones: Facebook cloning revisited appeared first on WeLiveSecurity
LinuxSecurity.com: dnsruby is a feature-complete DNS(SEC) client for Ruby. It ships the DNS Root Key Signing Key (KSK), used as trust anchor to validate the authenticity of DNS records. This update includes the latest KSK
LinuxSecurity.com: An update that contains security fixes can now be installed.
LinuxSecurity.com: Ben Pfaff discovered that the convert_to_decimal function in the GNU Portability Library contains a heap-based buffer overflow because memory is not allocated for a trailing ‘’ character during %f processing.
Risk Level: Very Low. Type: Trojan.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
