Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
LinuxSecurity.com: Django could be made to expose spoofed information over the network.
LinuxSecurity.com: Several security issues were fixed in NSS.
What’s in store for automotive security once cars morph into mobile living rooms and working spaces? And how about transportation at large? The post CES – singularity and securing the car appeared first on WeLiveSecurity
LinuxSecurity.com: Updates for rh-dotnet21-dotnet and rh-dotnet22-dotnet are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file (CVE-2018-11468). DISCOUNT through version 2.2.3a is vulnerable to a Heap-based
LinuxSecurity.com: Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-muscle.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact (CVE-2018-16391).
LinuxSecurity.com: Jeffrey Altman reported that the backup tape controller (butc) process does accept incoming RPCs but does not require (or allow for) authentication of those RPCs, allowing an unauthenticated attacker to perform volume operations with administrator credentials (CVE-2018-16947).
LinuxSecurity.com: It was found that when a retry task in ansible run with -vvv fails, it will log the raw return code, stdout and stderr from ssh which could have contained sensitive data (CVE-2018-16876). References:
LinuxSecurity.com: A leaky data conversion exposing a manager oracle (CVE-2018-16869). References: – https://bugs.mageia.org/show_bug.cgi?id=24080 – https://lists.opensuse.org/opensuse-updates/2018-12/msg00120.html
LinuxSecurity.com: A flaw was found in GNU Coreutils through 8.29 in chown-core.c. The functions chown and chgrp do not prevent replacement of a plain file with a symlink during use of the POSIX “-R -L” options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition (CVE-2017-18018).
LinuxSecurity.com: Double free in QXmlStreamReader (CVE-2018-15518). Denial of Service on malformed BMP file in QBmpHandler (CVE-2018-19873). References:
LinuxSecurity.com: The avidemux package has been updated to version 2.7.1. Avidemux includes a bundled copy of the ffmpeg libraries, which have been updated from version 3.3.3 to version 3.3.9, fixing several security issues and other bugs.
LinuxSecurity.com: It was discovered that ruby-loofah, a general library for manipulating and transforming HTML/XML documents and fragments, performed insufficient sanitising of SVG elements.
LinuxSecurity.com: It was discovered that malformed URLs could spoof the content of the default 404 page of Django, a Python web development framework. For the stable distribution (stretch), this problem has been fixed in
LinuxSecurity.com: The package elfutils before version 0.175-1 is vulnerable to denial of service.
Risk Level: Very Low.
In case there are some blank entries in your laundry list of New Year’s resolutions, we have a few tips for a bit of cybersecurity ‘soul searching’. Here’s the first batch, looking at how you can fix your good ol’ passwords. The post New Year’s resolutions: Get your passwords shipshape appeared first on WeLiveSecurity
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
LinuxSecurity.com: A NULL pointer dereference flaw was found in the way dcraw processed images. An attacker could potentially use this flaw to crash dcraw by tricking it into processing crafted images (CVE-2018-5801). References:
LinuxSecurity.com: A flaw was found in libao. The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 can cause a denial of service(memory corruption) via a crafted mp3 file (CVE-2017-11548). References:
LinuxSecurity.com: NULL pointer dereference in the function aubio_source_avcodec_readframe which may lead to DoS when playing a crafted audio file (CVE-2017-17554). A crash in aubio_pitch_set_unit (CVE-2018-14522).
Risk Level: Very Low.
The program with a prize pool of almost US$1 million aims to leverage the ‘power of the crowd’ in order to prevent another Heartbleed The post EU offers bug bounties on popular open source software appeared first on WeLiveSecurity
Reading Time: ~3 min. SMBs are overconfident about their cybersecurity posture. A survey of SMBs conducted by 451 Research found that in the preceding 24 months, 71% of respondents experienced a breach or attack that resulted in operational disruption, reputational damage, significant financial losses or regulatory penalties. At the same time, 49% of the SMBs […]
LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 6.6 Telco Update Service (TUS). This notification applies only to those customers subscribed to the Telco Update Service (TUS) channel for Red Hat Enterprise Linux 6.6.
LinuxSecurity.com: It was discovered that there was a content-spoofing vulnerability in the default 404 pages in the Django web development framework. For more information, please see:
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2019:0022
LinuxSecurity.com: This release (4.3.1) contains bug fixes only: – Fix checkspell detected typos (#531) – Heap overflow packet2tree and get_l2len (#530) This is Tcpreplay suite 4.3.0 This release contains several bug fixes and enhancements: – Fix maxOS TOS checksum failure (#524) – TCP sequence edits seeding (#514) – Fix issues identifed by Codacy (#493) – […]
LinuxSecurity.com: This release (4.3.1) contains bug fixes only: – Fix checkspell detected typos (#531) – Heap overflow packet2tree and get_l2len (#530) This is Tcpreplay suite 4.3.0 This release contains several bug fixes and enhancements: – Fix maxOS TOS checksum failure (#524) – TCP sequence edits seeding (#514) – Fix issues identifed by Codacy (#493) – […]
LinuxSecurity.com: Since version 1.19 Wget stores the URL and in certain cases the ‘Referer’ URL within extended attributes (xattrs) of the file system – by default. This includes username + password and other credentials or private data *if* those have been used within the URLs. Anyone with read access to
LinuxSecurity.com: Florian Stuelpner discovered that Samba is vulnerable to infinite query recursion caused by CNAME loops, resulting in denial of service (CVE-2018-14629). Alex MacCuish discovered that a user with a valid certificate or smart
