LinuxSecurity.com: Among others, Andre Heinicke from gpg4win.org found several issues of nsis, a tool for creating quick and user friendly installers for Microsoft Windows operating systems.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service or the execution of arbitrary code if malformed image files are processed.
LinuxSecurity.com: Several local side channel attacks and a denial of service via large Diffie-Hellman parameters were discovered in OpenSSL, a Secure Sockets Layer toolkit.
security update
Defensive steps for Marriott Starwood guests worried their personal information may have been compromised by the massive data breach The post Marriott Starwood data breach: 5 defensive steps travelers should take now appeared first on WeLiveSecurity
A recent survey carried out by ESET has revealed that Americans are worried most about cyberattacks on the financial sector, listing it above attacks against hospitals, voting systems, or energy supply companies The post Cyberattacks on financial sector worries Americans most appeared first on WeLiveSecurity
Reading Time: ~2 min.USPS Website Leaves Personal Data Available to Anyone Within the last week, The U.S. Postal Service (USPS) has been working to resolve a vulnerability that allowed any authenticated user to view and modify the personal information for any of the other 60 million users. Fortunately, USPS was quick to fix the vulnerability […]
LinuxSecurity.com: A SQL injection in PostgreSQL may allow attackers to execute arbitrary SQL statements.
LinuxSecurity.com: Multiple vulnerabilities have been found in libsndfile, the worst of which might allow remote attackers to cause a Denial of Service condition. [More…]
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.
LinuxSecurity.com: Multiple security vulnerabilities were found in libarchive, a multi-format archive and compression library. Heap-based buffer over-reads, NULL pointer dereferences and out-of-bounds reads allow remote attackers to cause a denial-of-service (application crash) via
LinuxSecurity.com: An update for ruby is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: Multiple vulnerabilities were discovered in the implementation of the Perl programming language. The Common Vulnerabilities and Exposures project identifies the following problems:
LinuxSecurity.com: Several security vulnerabilities were discovered in Ghostscript, an interpreter for the PostScript language, which could result in denial of service, the creation of files or the execution of arbitrary code if a malformed Postscript file is processed (despite the dSAFER sandbox being
LinuxSecurity.com: The package samba before version 4.9.3-1 is vulnerable to multiple issues including denial of service and access restriction bypass.
LinuxSecurity.com: The package powerdns-recursor before version 4.1.8-1 is vulnerable to denial of service.
The hacking and extortion scheme took place over a 34-month period with the SamSam ransomware affecting over 200 organizations in the US and Canada The post US indicts two over SamSam ransomware attacks appeared first on WeLiveSecurity
LinuxSecurity.com: An update for rh-ruby25-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for rh-ruby24-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for rh-ruby23-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Multiple vulnerabilities have been found in RPM, the worst of which could allow a remote attacker to escalate privileges.
LinuxSecurity.com: Multiple vulnerabilities have been found in OpenSSL, the worst of which may lead to a Denial of Service condition.
LinuxSecurity.com: Buffer overflows in URL auth code if there is a “mount” definition that enables URL authentication. A malicious client could send long HTTP headers, leading to a buffer overflow and potential remote code execution (CVE-2018-18820).
LinuxSecurity.com: The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.1 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file. (CVE-2017-5950)
security update
security update
LinuxSecurity.com: USN-3804-1 introduced a regression in OpenJDK.
LinuxSecurity.com: Several security issues were fixed in Git.
LinuxSecurity.com: Several vulnerabilities were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service or the execution of arbitrary code if a malformed Postscript file is processed (despite the -dSAFER sandbox being enabled).
Reading Time: ~4 min.At Webroot, we stay ahead of cybersecurity trends in order to keep our customers up-to-date and secure. As the end of the year approaches, our team of experts has gathered their top cybersecurity predictions for 2019. What threats and changes should you brace for? General Data Protection Regulation Penalties “A large US-based […]
International law enforcement swoops on fake ad viewing outfit The post 3ve – Major online ad fraud operation disrupted appeared first on WeLiveSecurity
LinuxSecurity.com: Several security issues were fixed in Samba.
LinuxSecurity.com: USN-3816-1 caused a regression in systemd-tmpfiles.
