Menu

Category Archives: All

Everything

LinuxSecurity.com: The package systemd before version 240.0-3 is vulnerable to multiple issues including arbitrary file overwrite and information disclosure.

OXO International discloses data breach, customer data over two years impacted
What happens when the cops get hit with malware, too?
Reddit Locks Down Accounts After Security Incident
Trading site data leak sprayed out keys to users’ accounts
El Chapo was brought down by a sysadmin
No plain sailing for Anon hacktivist picked up by Disney cruise ship: 10 years in the cooler for hospital DDoS caper

LinuxSecurity.com: read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leading to an out-of-bounds read in archive_read_format_rar_read_header (CVE-2017-14502).

LinuxSecurity.com: Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe “cat README.md” command when e}pn is used. A popmedia control sequence can allow the malicious execution of executable file formats registered in the X desktop share MIME types (/usr/share/applications). The control sequence defers

LinuxSecurity.com: fix CVE-2019-3498 python-django: Content spoofing via URL path in

LinuxSecurity.com: backport anti-phishing fixes

LinuxSecurity.com: **Horde_Image 2.5.4** * [mjr] SECURITY: Fix potential RCE in the text method when using the Imagemagick backend. * [mjr] SECURITY: Sanitize image type parameter (PR: 2, Fariskhi Vidyan). * [mjr] Fix issues with escaping single and double quote characters in the text method when using the Imagemagick backend.

If you wanna learn from the IT security blunders committed by hacked hospital group, here’s some weekend reading
Dozens of .gov HTTPS certs expire, webpages offline, FBI on ice, IT security slows… Yup, it’s day 20 of Trump’s govt shutdown
Cyber-insurance shock: Zurich refuses to foot NotPetya ransomware clean-up bill – and claims it’s ‘an act of war’
At CES, Focus is On ‘Cool Factor’ Not IoT Security
You can’t delete Facebook from some Androids and people aren’t happy
Facebook violated tough new cybersecurity law, says Vietnam
Reddit locks out users with poor password hygiene after spotting ‘unusual activity’
‘Unprecedented’ DNS Hijacking Attacks Linked to Iran
Google Search Results Spoofed to Create Fake News
Update now! Microsoft and Adobe’s January 2019 Patch Tuesday is here
Supreme Court refuses to hear Fiat Chrysler appeal in Jeep hacking case
Reddit users locked out of accounts after ‘security concern’
Zerodium is paying $2 million for Apple iOS remote jailbreak
Thousands of Internet connected hot tubs vulnerable to remote attacks
NSA to release free reverse engineering tool GHIDRA at RSAConference
2018’s Top hacks and data breaches
Town of Salem data breach: Personal data of 7.6M gamers stolen
Baddies linked to Iran fingered for DNS hijacking to read Middle Eastern regimes’ emails
Face unlock on many Android smartphones falls for a photo

No 3D-printed heads or realistic masks were needed to trick even a handful of high-end handset models into unlocking their screens The post Face unlock on many Android smartphones falls for a photo appeared first on WeLiveSecurity

Reading Time: ~4 min. We live in a digital age where internet-connected devices are the norm. Our phones, our televisions, even our light bulbs are tied together in today’s tech ecosystem. For high school and college students, this degree of digital connection is the standard, and when school is in session, tech accessories are a […]

Smashing Security #110: What? You can get paid to leave Facebook?

LinuxSecurity.com: A vulnerability was found in mbedTLS which allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites (CVE-2018-19608). References:

LinuxSecurity.com: A bug in the server implementation of RTSP-over-HTTP in live could allow a denial-of-service attack. A bug in the server implementation of RTSP-over-HTTP could allow a buffer overflow, which could result in the execution of arbitrary code

LinuxSecurity.com: An authenticated user who can obtain a TGT using an older encryption type (DES, DES3, or RC4) can cause an assertion failure in the KDC by sending an S4U2Self request (CVE-2018-20217). References:

CES IoT security – do you know who your home is talking to?

There’s a digital treasure trove to be had in your home so you should take steps to protect it The post CES IoT security – do you know who your home is talking to? appeared first on WeLiveSecurity

Before you slink off to the pub, be sure to patch these 19 serious vulns in Juniper Networks kit

LinuxSecurity.com: Security fix for CVE-2018-1000532, new non-root permissions and a few smaller fixes. Fix a directory traversal issue introduced with the fix for CVE-2018-1000532, and refuses to run as setuid root or via sudo to avoid any more priviledge escalation issue. —- Security fix for CVE-2018-1000532 and a few smaller fixes

LinuxSecurity.com: libgxps 0.3.1 release. – Fix font scaling when converting xps to pdf – Handle errors returned by archive_read_data in GXPSArchive – Ensure gxps_archive_read_entry() fills the GError in case of failure – Make the pdf generated by xpstopdf to be 96 dpi – Fix OUTPUT FILE description in man pages – Clear the GError before […]

The D in SystemD stands for Dammmit… Security holes found in much-adored Linux toolkit

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: Several vulnerabilities were discovered in libcaca, a graphics library that outputs text: integer overflows, floating point exceptions or invalid memory reads may lead to a denial-of-service (application crash) if a malformed image file is processed.

Critical Flaw in Cisco’s Email Security Appliance Enables ‘Permanent DoS’
Who cracked El Chapo’s encrypted chats and brought down the Mexican drug kingpin? Er, his IT manager
ICEPick-3PC: A Sophisticated Adware That Collects Data En Masse

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

Google Play Boots 85 Malicious Adware Apps

security update

security update

Type: Vulnerability. Microsoft Skype for Android is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange Server is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Exchange is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Visual Studio is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office SharePoint is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office SharePoint is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft ASP.NET Core is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office SharePoint is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows Subsystem for Linux is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Visual Studio is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.