LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: Firefox could be made to crash or run programs as your login if it opened a malicious website.
security update
LinuxSecurity.com: pixman could be made to crash or run programs if it processed specially crafted instructions.
LinuxSecurity.com: pixman could be made to crash or run programs if it processed specially crafted instructions.
LinuxSecurity.com: The package openssl-1.0 before version 1.0.2.q-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package lib32-openssl-1.0 before version 1.0.2.q-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package lib32-openssl before version 1:1.1.1.a-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package openssl before version 1.1.1.a-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package texlive-bin before version 2018.48691-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package wireshark-cli before version 2.6.5-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.
LinuxSecurity.com: The package chromium before version 71.0.3578.80-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, information disclosure and insufficient validation.
LinuxSecurity.com: CUPS could be made to expose sensitive information.
LinuxSecurity.com: lxml could allow cross-site scripting (XSS) attacks.
LinuxSecurity.com: lxml could allow cross-site scripting (XSS) attacks.
LinuxSecurity.com: This is the one-Month notification for the retirement of Red Hat Enterprise Linux 6.6 Telco Update Service (TUS). This notification applies only to those customers subscribed to the Telco Update Service (TUS) channel for Red Hat Enterprise Linux 6.6.
LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 7.3 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.3.
LinuxSecurity.com: This is the one-Month notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.
There is no evidence that the flaw was misused during the six days it was alive, said the tech giant The post Google+ to shut earlier as new bug exposed data of 52.5 million users appeared first on WeLiveSecurity
ESET researchers discovered a new Android Trojan using a novel Accessibility-abusing technique that targets the official PayPal app, and is capable of bypassing PayPal’s two-factor authentication The post Android Trojan steals money from PayPal accounts even with 2FA on appeared first on WeLiveSecurity
Risk Level: Very Low. Type: Trojan, Virus, Worm.
LinuxSecurity.com: Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: The EXIF module was susceptible to denial of service/information disclosure when parsing malformed images, the Apache module allowed cross-site-scripting via the body of a
LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.
Risk Level: Very Low. Type: Trojan.
The “evolution” of these markets is making cybercrime easier than ever before The post Next Generation Dark Markets? Think Amazon or eBay for criminals appeared first on WeLiveSecurity
LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: It was discovered that there was a XSS injection vulnerability in the LXML HTML/XSS manipulation library for Python. LXML did not remove “javascript:” URLs that used escaping such as
LinuxSecurity.com: An update for rh-git218-git is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service (CVE-2018-1336). The defaults settings for the CORS filter are insecure and enable
LinuxSecurity.com: An update that fixes 27 vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
security update
LinuxSecurity.com: Use after free flaw enabling arbitrary code execution. (CVE-2018-15982) Insecure Library Loading (DLL hijacking) flaw enabling privilege escalation. (CVE-2018-15983)
LinuxSecurity.com: The HTML thumbnailer was incorrectly accessing some content of remote URLs listed in HTML files. This meant that the owners of the servers referred in HTML files in your system could have seen in their access logs your IP address every time the thumbnailer tried to create the thumbnail (CVE-2018-19120).
security update
Type: Vulnerability. Adobe Flash Player is prone to an unspecified remote code-execution vulnerability; fixes are available.
