Menu

Monthly Archives: January 2019

LinuxSecurity.com: The package python2-django before version 1.11.18-1 is vulnerable to content spoofing.

LinuxSecurity.com: The package python-django before version 2.1.5-1 is vulnerable to content spoofing.

security update

LinuxSecurity.com: Due to kernel issue there is a way to reuse start_time of a process. This allows to duplicate process authorized by polkit. This update mitigates polkit issue #75 (slowfork): https://gitlab.freedesktop.org/polkit/polkit/issues/75

It only takes a Skype Call to Unlock an Android Handset
Kaspersky tipped off US about the contractor who stole NSA data
9 million users installed 85 adware infected apps from Play Store
Aussie govt emergency service hacked to send fake warning alerts
WhatsApp Gold Scam is Back with Malware Payload
Hacker ‘BestBuy’ sentenced to prison for operating Mirai DDoS botnet
Facebook staff discussed cashing in on user data, reports say

LinuxSecurity.com: An integer underflow was discovered in the CAF demuxer of the VLC media player. For the stable distribution (stretch), this problem has been fixed in

Facebooker swatted, Kaspersky snares an NSA thief, NASA server exposed, and more

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: Resolves CVE-2018-16869

LinuxSecurity.com: Resolves CVE-2018-16869

*taps on glass* Hellooo, IRS? Anyone in? Anyone guarding taxpayers’ data from crooks? Hellooo?
AT&T, Sprint, Verizon, T-Mobile US pledge, again, to not sell your location to shady geezers. Sorry, we don’t believe them

LinuxSecurity.com: New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Pre-Installed Android App Impacts Millions with Slew of Malicious Activity
Anonymous hacker jailed for 10 years over hospital DDoS attacks

security update

TA505 Crime Gang Debuts Brand-New ServHelper Backdoor
Unprotected MongoDB leaks resumes of 202M Chinese job seekers
U.S. Government Shutdown Leaves Dozens of .Gov Websites Vulnerable
Yet Another Bypass: Is 2FA Broken? Authentication Experts Weigh In
Medical advice app Your.MD could have been tampered with by anyone, alleges ex-veep
Huawei sales director nicked in Poland on suspicion of ‘spying’

Reading Time: ~2 min. Malicious Apps Get Millions of Installs Google recently removed 85 apps from the Play Store after they were found to contain predatory adware. With over nine million combined downloads, the apps were mostly fake games or utility apps that began pushing a constant stream of full-screen ads to users until the […]

Old tweets reveal hidden secrets
2FA codes can be phished by new pentest tool

LinuxSecurity.com: The package wireshark-cli before version 2.6.6-1 is vulnerable to multiple issues including information disclosure and denial of service.

LinuxSecurity.com: The package systemd before version 240.0-3 is vulnerable to multiple issues including arbitrary file overwrite and information disclosure.

OXO International discloses data breach, customer data over two years impacted
What happens when the cops get hit with malware, too?
Reddit Locks Down Accounts After Security Incident
Trading site data leak sprayed out keys to users’ accounts
El Chapo was brought down by a sysadmin
No plain sailing for Anon hacktivist picked up by Disney cruise ship: 10 years in the cooler for hospital DDoS caper

LinuxSecurity.com: Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe “cat README.md” command when e}pn is used. A popmedia control sequence can allow the malicious execution of executable file formats registered in the X desktop share MIME types (/usr/share/applications). The control sequence defers

LinuxSecurity.com: read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leading to an out-of-bounds read in archive_read_format_rar_read_header (CVE-2017-14502).

LinuxSecurity.com: fix CVE-2019-3498 python-django: Content spoofing via URL path in

LinuxSecurity.com: **Horde_Image 2.5.4** * [mjr] SECURITY: Fix potential RCE in the text method when using the Imagemagick backend. * [mjr] SECURITY: Sanitize image type parameter (PR: 2, Fariskhi Vidyan). * [mjr] Fix issues with escaping single and double quote characters in the text method when using the Imagemagick backend.

LinuxSecurity.com: backport anti-phishing fixes

If you wanna learn from the IT security blunders committed by hacked hospital group, here’s some weekend reading
Dozens of .gov HTTPS certs expire, webpages offline, FBI on ice, IT security slows… Yup, it’s day 20 of Trump’s govt shutdown
Cyber-insurance shock: Zurich refuses to foot NotPetya ransomware clean-up bill – and claims it’s ‘an act of war’
At CES, Focus is On ‘Cool Factor’ Not IoT Security
You can’t delete Facebook from some Androids and people aren’t happy
Facebook violated tough new cybersecurity law, says Vietnam
Reddit locks out users with poor password hygiene after spotting ‘unusual activity’
‘Unprecedented’ DNS Hijacking Attacks Linked to Iran
Google Search Results Spoofed to Create Fake News
Update now! Microsoft and Adobe’s January 2019 Patch Tuesday is here
Supreme Court refuses to hear Fiat Chrysler appeal in Jeep hacking case
Reddit users locked out of accounts after ‘security concern’
Zerodium is paying $2 million for Apple iOS remote jailbreak
Thousands of Internet connected hot tubs vulnerable to remote attacks
NSA to release free reverse engineering tool GHIDRA at RSAConference
2018’s Top hacks and data breaches
Town of Salem data breach: Personal data of 7.6M gamers stolen
Baddies linked to Iran fingered for DNS hijacking to read Middle Eastern regimes’ emails
Face unlock on many Android smartphones falls for a photo

No 3D-printed heads or realistic masks were needed to trick even a handful of high-end handset models into unlocking their screens The post Face unlock on many Android smartphones falls for a photo appeared first on WeLiveSecurity

Reading Time: ~4 min. We live in a digital age where internet-connected devices are the norm. Our phones, our televisions, even our light bulbs are tied together in today’s tech ecosystem. For high school and college students, this degree of digital connection is the standard, and when school is in session, tech accessories are a […]

Smashing Security #110: What? You can get paid to leave Facebook?

LinuxSecurity.com: An authenticated user who can obtain a TGT using an older encryption type (DES, DES3, or RC4) can cause an assertion failure in the KDC by sending an S4U2Self request (CVE-2018-20217). References:

LinuxSecurity.com: A bug in the server implementation of RTSP-over-HTTP in live could allow a denial-of-service attack. A bug in the server implementation of RTSP-over-HTTP could allow a buffer overflow, which could result in the execution of arbitrary code

LinuxSecurity.com: A vulnerability was found in mbedTLS which allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites (CVE-2018-19608). References:

CES IoT security – do you know who your home is talking to?

There’s a digital treasure trove to be had in your home so you should take steps to protect it The post CES IoT security – do you know who your home is talking to? appeared first on WeLiveSecurity

Before you slink off to the pub, be sure to patch these 19 serious vulns in Juniper Networks kit

LinuxSecurity.com: libgxps 0.3.1 release. – Fix font scaling when converting xps to pdf – Handle errors returned by archive_read_data in GXPSArchive – Ensure gxps_archive_read_entry() fills the GError in case of failure – Make the pdf generated by xpstopdf to be 96 dpi – Fix OUTPUT FILE description in man pages – Clear the GError before […]

LinuxSecurity.com: Security fix for CVE-2018-1000532, new non-root permissions and a few smaller fixes. Fix a directory traversal issue introduced with the fix for CVE-2018-1000532, and refuses to run as setuid root or via sudo to avoid any more priviledge escalation issue. —- Security fix for CVE-2018-1000532 and a few smaller fixes

The D in SystemD stands for Dammmit… Security holes found in much-adored Linux toolkit

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: Several vulnerabilities were discovered in libcaca, a graphics library that outputs text: integer overflows, floating point exceptions or invalid memory reads may lead to a denial-of-service (application crash) if a malformed image file is processed.

Critical Flaw in Cisco’s Email Security Appliance Enables ‘Permanent DoS’
Who cracked El Chapo’s encrypted chats and brought down the Mexican drug kingpin? Er, his IT manager
ICEPick-3PC: A Sophisticated Adware That Collects Data En Masse

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

Google Play Boots 85 Malicious Adware Apps

security update

security update

Type: Vulnerability. Microsoft Skype for Android is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote privilege-escalation vulnerability; fixes are available.