Menu

Monthly Archives: December 2018

LinuxSecurity.com: Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment. (CVE-2018-19149) References:

LinuxSecurity.com: An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by “j a v a s c r i p t:” in Internet Explorer (CVE-2018-19787).

LinuxSecurity.com: Possible denial of service vulnerability due to a missing check in Lib/wave.py to verify that at least one channel is provided (CVE-2017-18207). Python’s elementtree C accelerator failed to initialise Expat’s hash

LinuxSecurity.com: Graphicsmagick has been updated to fix several bugs and security issues. References: – https://bugs.mageia.org/show_bug.cgi?id=23157 – http://www.graphicsmagick.org/NEWS.html#november-17-2018

LinuxSecurity.com: debian-security-support, the Debian security support coverage checker, has been updated in jessie. The jessie relevant changes are: * Mark jasperreports as end-of-life in Jessie.

Malware Attack Crippled Production of Major U.S. Newspapers
Ransomware vs. printing press? US newspapers face “foreign cyberattack”

Did malware disrupt newspaper deliveries in major US cities? Here’s what’s known about the incident so far and the leading suspect: Ryuk ransomware. Plus, advice on defending your organization against such attacks. The post Ransomware vs. printing press? US newspapers face “foreign cyberattack” appeared first on WeLiveSecurity

Cryptocurrency Wallet Hacks Spark Dustup
2018: Research highlights from ESET’s leading lights

As the curtain slowly falls on yet another eventful year in cybersecurity, let’s look back on some of the finest malware analysis by ESET researchers in 2018 The post 2018: Research highlights from ESET’s leading lights appeared first on WeLiveSecurity

Hackers pocketed $878,000 from cryptocurrency bug bounties in 2018
EU offers bounties to help find security flaws in open source tools
How to secure your Instagram account using 2FA

LinuxSecurity.com: It was discovered that there was a potential denial of service vulnerability in tar, the GNU version of the tar UNIX archiving utility.

LinuxSecurity.com: Updated to 3.3.4. Security fix by upstream: Anti-Phishing protection.. Server-provided text will not appear in user-facing GUI windows anymore. Server error messages are instead parsed and mapped to predefined strings.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Multiple vulnerabilities have been found in Rust, the worst which may allow local attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in GKSu might allow attackers to execute arbitrary commands.

Graham Cluley’s Desert Planet Picks

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves four vulnerabilities and has 17 fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

How Facebook Tracks Non-Users via Android Apps

LinuxSecurity.com: **Archive_Tar version 1.4.4** * Fix Bug #21058: Long symlinks are not supported [mrook] * Fix Bug #23782: Prevent phar:// files from being extracted [mrook] — **PEAR** * drop deprecated option used when running `pear run-tests`

LinuxSecurity.com: This update fixes CVE-2018-16646, CVE-2018-19058, CVE-2018-19059, CVE-2018-19060, CVE-2018-19149.

LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.

LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

security update

‘Snowden Refugee’ Has No Regrets for Helping Whistleblower
How to secure your Twitter account
Depressing lessons 2018’s endless data breaches taught us
Hackers steal personal info of 1,000 North Korean defectors

LinuxSecurity.com: This update fixes CVE-2017-18267, CVE-2018-13988, CVE-2018-16646, CVE-2018-19058, CVE-2018-19059, CVE-2018-19060, CVE-2018-19149

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.

LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.

LinuxSecurity.com: Security fix for fts3/4 corrupt database exploit

LinuxSecurity.com: Security fix for CVE-2018-16869

LinuxSecurity.com: Several vulnerabilities were discovered in libextractor, a library to extract arbitrary meta-data from files, which may lead to denial of service or memory disclosure if a malformed OLE file is processed.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

security update

First-Ever UEFI Rootkit Tied to Sednit APT

LinuxSecurity.com: A XML External Entity (XXE) vulnerability was discovered in c3p0, a library for JDBC connection pooling, that may be used to resolve information outside of the intended sphere of control.

LinuxSecurity.com: Multiple security issues were found in libarchive, a multi-format archive and compression library: Processing malformed RAR archives could result in denial of service or the execution of arbitrary code and malformed WARC, LHarc, ISO, Xar or CAB archives could result in denial of service.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Wireshark, a network protocol analyzer, which could result in denial of service or the execution of arbitrary code.

LinuxSecurity.com: Some vulnerabilities were discovered in ghostscript, an interpreter for the PostScript language and for PDF.

Guardzilla Home Cameras Open to Anyone Wanting to Watch Their Footage
How to protect your Facebook account: a walkthrough
Hijacking Online Accounts Via Hacked Voicemail Systems
35C3 Day One: Security, Art and Hacking

Reading Time: ~2 min. Amazon User Receives Thousands of Alexa-Recorded Messages Upon requesting all his user data from Amazon, one user promptly received over 1,700 recorded messages from an Alexa device. Unfortunately, the individual didn’t own such a device. The messages were from a device belonging to complete stranger, and some of them could have easily […]

Analysis of the latest Emotet propagation campaign

An analysis of the workings of this new Emotet campaign, which has affected various countries in Latin America by taking advantage of Microsoft Office files to hide its malicious activity The post Analysis of the latest Emotet propagation campaign appeared first on WeLiveSecurity

LinuxSecurity.com: A flaw was found in the i18n gem before 0.8.0 for Ruby. The Hash#slice in lib/i18n/core_ext/hash.rb allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash (CVE-2014-10077).

LinuxSecurity.com: Fixed a stack-based buffer over-read in the print_prefix function (CVE-2018-19519). References: – https://bugs.mageia.org/show_bug.cgi?id=24077

FTC issues warning about a Netflix phishing scam
The most interesting and important hacks of 2018
GDPR’s impact was too soft in 2018, but next year will be different

LinuxSecurity.com: A possible regression was found in the recent security update for libphp-phpmailer, announced as DLA 1591-1. During backporting a new variable have accidentally introduced to a conditional statement from

LinuxSecurity.com: Security fix for CVE-2018-16737, CVE-2018-16738, CVE-2018-16758

LinuxSecurity.com: Update to new upstream version 1.5.5 (rhbz#1660413, rhbz#1660414)

FTC Warns of Netflix Phishing Scam Making Rounds
It’s the end of 2018, and this is your year in security

LinuxSecurity.com: The Shopify Application Security Team discovered that ruby-sanitize, a whitelist-based HTML sanitizer, is prone to a HTML injection vulnerability. A specially crafted HTML fragment can cause to allow non- whitelisted attributes to be used on a whitelisted HTML element.

What should you do with your old devices

Disposal of old tech requires thought and effort and the need to cleanse the device of any personal data is just one of the concerns The post What should you do with your old devices appeared first on WeLiveSecurity

Over 19,000 Orange modems are leaking WiFi credentials
Two-factor authentication can save you from hackers

LinuxSecurity.com: Kaspersky Lab discovered several vulnerabilities in libvncserver, a C library to implement VNC server/client functionalities.

LinuxSecurity.com: Security fix for CVE-2018-16737, CVE-2018-16738, CVE-2018-16758

LinuxSecurity.com: Update to new upstream version 1.5.5 (rhbz#1660413, rhbz#1660414)

LinuxSecurity.com: The updated packages fix several bugs and some security issues. References: – https://bugs.mageia.org/show_bug.cgi?id=24041 – https://www.thunderbird.net/en-US/thunderbird/60.4.0/releasenotes/

LinuxSecurity.com: There is a use-after-free in monit that shows up if you run it for a while on an active system with address sanitizer enabled. References: – https://bugs.mageia.org/show_bug.cgi?id=24049

LinuxSecurity.com: A security issue fixed upstream in sqlite3 has been announced: https://www.openwall.com/lists/oss-security/2018/12/21/1 The issue is fixed in 3.25.3. References:

security update

19K Orange Livebox Modems Open to Attack
Top 2018 Security and Privacy Stories
Congress approves act that opens US government data to the public
Hacker steals ten years worth of data from San Diego school district

LinuxSecurity.com: Multiple vulnerabilities have been found in libsndfile, the library for reading and writing files containing sampled sound. CVE-2017-8361

2019: The Year Ahead in Cybersecurity
Over 500K School Staff and Students Hit by Breach
Facebook let Netflix, Spotify read your private messages
What is ransomware? How these attacks work and how to recover from them
Could you speak up a bit? I didn’t catch your password

LinuxSecurity.com: This update fixes multiple security vulnerabilities: CVE-2018-5783, CVE-2018-11254, CVE-2018-11255, CVE-2018-11256, CVE-2018-12982, CVE-2018-14320, CVE-2018-19532

LinuxSecurity.com: This update fixes multiple security vulnerabilities: CVE-2018-5783, CVE-2018-11254, CVE-2018-11255, CVE-2018-11256, CVE-2018-12982, CVE-2018-14320, CVE-2018-19532

LinuxSecurity.com: – Fix double-free in CEmuopl::~CEmuopl() (#1635881, CVE-2018-17825)

LinuxSecurity.com: – Fix double-free in CEmuopl::~CEmuopl() (#1635881, CVE-2018-17825)

LinuxSecurity.com: Several issues were corrected in nagios3, a monitoring and management system for hosts, services and networks. CVE-2018-18245

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3833

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3831

Critical Bug Patched in Schneider Electric Vehicle Charging Station
San Diego School District Data Breach Hits 500k Students
2018: A Banner Year for Breaches