LinuxSecurity.com: A flaw was found in units. units_cur doesn’t sanitize downloaded data. This allows a maliciously intended server to execute arbitrary code remotely on the client (rhbz#1598913). References:
LinuxSecurity.com: A vulnerability was in found in PowerDNS Authoritative Server. The issue is a memory leak occurring while parsing some malformed records, due to the fact that some memory is allocated parsing a record and is not always properly released if the record is not valid. It allows an authorized user to cause a denial […]
LinuxSecurity.com: A vulnerability was in found in PowerDNS Recursor. The issue is a memory leak occurring while parsing some malformed records, due to the fact that some memory is allocated parsing a record and is not always properly released if the record is not valid. It allows a malicious auth server to cause a denial […]
LinuxSecurity.com: Eyal Itkin discovered FreeRDP incorrectly handled certain stream encodings. A malicious server could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2018-8784, CVE-2018-8785).
LinuxSecurity.com: Potential object injection vulnerability (CVE-2018-19296). References: – https://bugs.mageia.org/show_bug.cgi?id=24055 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DAZQPUD7WZXMJ2KIQY5P2I2UI545YPYO/
LinuxSecurity.com: Use-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32 (CVE-2015-6673). References: – https://bugs.mageia.org/show_bug.cgi?id=24101
LinuxSecurity.com: Several vulnerabilities were discovered in libextractor which may lead to denial of service or memory disclosure if a malformed OLE file is processed (CVE-2018-20430, CVE-2018-20431). References:
LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.
The vast trove of data was released online and disseminated via Twitter over the span of four weeks – without anybody really noticing The post Personal data of German political elite dumped online appeared first on WeLiveSecurity
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves 6 vulnerabilities and has three fixes is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves 13 vulnerabilities and has three fixes is now available.
LinuxSecurity.com: An update that solves 11 vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
LinuxSecurity.com: An update that solves 9 vulnerabilities and has four fixes is now available.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: An update that solves four vulnerabilities and has 17 fixes is now available.
LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
Reading Time: ~2 min. American Newspapers Shutdown After Ransomware Attack Nearly all news publications owned by Tribune Publishing suffered disruptions in printing or distribution after the publisher was hit by a ransomware attack. Many of the papers across the country were delivered incomplete or hours or days late. Even some papers that had been sold […]
LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available.
LinuxSecurity.com: An update for rh-perl524-perl is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for rh-perl526-perl and rh-perl526-perl-Module-CoreList is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
A reflection on how acknowledging the cumulative nature of cyber-threats and understanding its implications can benefit our digital security The post What is threat cumulativity and what does it mean for digital security? appeared first on WeLiveSecurity
LinuxSecurity.com: Multiple issues were fixed in Qt. CVE-2018-15518 A double-free or corruption during parsing of a specially crafted
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
security update
LinuxSecurity.com: This update includes the changes in tzdata 2018i for the Perl bindings. For the list of changes, see DLA-1625-1. For Debian 8 “Jessie”, this problem has been fixed in version
LinuxSecurity.com: This update includes the changes in tzdata 2018i. Notable changes are: – Qyzylorda, Kazakhstan moved from +06 to +05 on 2018-12-21. A new
LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For Debian 8 “Jessie”, this problem has been fixed in version
LinuxSecurity.com: Fix CVEs as described in related RHBZ bug.
LinuxSecurity.com: Fix CVEs as described in related RHBZ bug.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
The message starts off with the kind of information that is apt to send shivers down the spines of many binge-watchers The post This Netflix-themed scam prompts FTC to issue warning appeared first on WeLiveSecurity
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For the stable distribution (stretch), this problem has been fixed in
LinuxSecurity.com: Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment. (CVE-2018-19149) References:
LinuxSecurity.com: An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by “j a v a s c r i p t:” in Internet Explorer (CVE-2018-19787).
LinuxSecurity.com: Graphicsmagick has been updated to fix several bugs and security issues. References: – https://bugs.mageia.org/show_bug.cgi?id=23157 – http://www.graphicsmagick.org/NEWS.html#november-17-2018
LinuxSecurity.com: Possible denial of service vulnerability due to a missing check in Lib/wave.py to verify that at least one channel is provided (CVE-2017-18207). Python’s elementtree C accelerator failed to initialise Expat’s hash
LinuxSecurity.com: debian-security-support, the Debian security support coverage checker, has been updated in jessie. The jessie relevant changes are: * Mark jasperreports as end-of-life in Jessie.
Did malware disrupt newspaper deliveries in major US cities? Here’s what’s known about the incident so far and the leading suspect: Ryuk ransomware. Plus, advice on defending your organization against such attacks. The post Ransomware vs. printing press? US newspapers face “foreign cyberattack” appeared first on WeLiveSecurity
