LinuxSecurity.com: Two vulnerabilities have been found in Solr, a search server based on Lucene, which could result in the execution of arbitrary code or path traversal.
LinuxSecurity.com: Kelby Ludwig and Scott Cantor discovered that the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to incorrect XML parsing. For additional details please refer to the upstream advisory at
LinuxSecurity.com: Joonun Jang discovered several problems in wavpack, an audio compression format suite. Incorrect processing of input resulted in several heap- and stack-based buffer overflows, leading to application crash or potential code execution.
LinuxSecurity.com: From upstream announcement: **Security fix: phpMyAdmin 4.7.8 is released** Welcome to phpMyAdmin 4.7.8, a security releaes also containing regular maintenance bug fixes. The security fix relates to a self-XSS vulnerability in the central columns feature that is reported as PMASA-2018-1 https://www.phpmyadmin.net/security/PMASA-2018-1/. Thanks to Mayur Udiniya
LinuxSecurity.com: A flaw was found in the AWT component of OpenJDK. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions. (CVE-2018-2641) * It was discovered that the LDAPCertStore class in the JNDI component of OpenJDK failed to securely handle LDAP referrals. An attacker could possibly use this flaw […]
LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code execution (CVE-2018-5345) SL7 x86_64 gcab-debuginfo-0.7-4.el7_4.i686.rpm gcab-debuginfo-0.7-4.el7_4.x86_64.rpm libgcab1-0.7-4.el7_4.i686.rpm libgcab1-0.7-4.el7_4.x86_64.rpm gcab-0.7-4.el7_4.x86_64.rpm libgcab1-devel-0.7-4.el7_4.i686.rpm libgcab1-devel-0.7-4.el7_4.x86 [More…]
LinuxSecurity.com: An update for gcab is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: It was discovered that there was an arbitrary command execution vulnerability in the Go programming language. The “go get” implementation did not correctly validate “import path”
Bots that traverse the internet on behalf of their human operators can fulfill both legitimate and malicious automated tasks. Statistics indicate that bot-driven internet traffic, by helper and harmful bots combined, surpasses human traffic. The post Over 40% of online login attempts are attackers trying to invade accounts appeared first on WeLiveSecurity
LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available.
The Internet of Things (IoT) can be a network of connected convenience but this should not come at the expense of safeguarding your privacy and the personal data that connected devices collect and share. The post Privacy by Design: Can you create a safe smart home? appeared first on WeLiveSecurity
LinuxSecurity.com: New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35
LinuxSecurity.com: This update updates QtWebEngine to the 5.10.1 bugfix and security release. QtWebEngine 5.10.1 is part of the Qt 5.10.1 release, but only the QtWebEngine component is included in this update. This update includes: * Security fixes from Chromium up to version 64.0.3282.140. Including: CVE-2017-15407, CVE-2017-15409, CVE-2017-15410, CVE-2017-15411, CVE-2017-15415, CVE-2017-15416,
LinuxSecurity.com: New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35
LinuxSecurity.com: CVE-2017-13194 Fix for a flaw in libvpx related to odd frame width, which may lead to a denial of service.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: Multiple vulnerabilities have been found in the Drupal content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2018-001
LinuxSecurity.com: It was discovered that there was a remote denial of service vulnerability in the imagemagick graphics library via a specially- crafted TIFF file.
LinuxSecurity.com: This update includes the changes in tzdata 2018c for the Perl bindings. For the list of changes, see DLA-1291-1. For Debian 7 “Wheezy”, these problems have been fixed in version
LinuxSecurity.com: This update includes the changes in tzdata 2018c. Notable changes are: – S?o Tom? and Pr?ncipe switched from +00 to +01. – Brazil’s DST will now start on November’s first Sunday.
LinuxSecurity.com: The package unixodbc before version 2.3.5-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package lib32-wavpack before version 5.1.0-2 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package wavpack before version 5.1.0-2 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package phpmyadmin before version 4.7.8-1 is vulnerable to cross- site scripting.
security update
security update
security update
LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. CVE-2017-5715
LinuxSecurity.com: It was discovered that there was an issue in the CUPS printer framework where remote attackers could execute arbitrary commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding.
LinuxSecurity.com: Several security issues were fixed in WavPack.
LinuxSecurity.com: This update doesn’t fix a vulnerability in GCC itself, but instead provides support for building retpoline-enabled Linux kernel updates. For the stable distribution (stretch), this problem has been fixed in
If you get sick of shopping sites sending you “I see you stared at this item, here’s some similar stuff” messages, you may be able to modify your subscriptions or notifications to make this stop. The post Six tips to help you avoid targeted marketing appeared first on WeLiveSecurity
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Hackers Run Linux OS On Nintendo Switch When gaming consoles get hacked, it’s usually by someone who […]
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: On February 22, fixes for CVE-2017-5715 were released into the Ubuntu Xenialkernel version 4.4.0-116.140. This CVE, also known as “Spectre,” is caused by flaws in the design of speculative execution hardware in the computer’sCPU, and could be used to access sensitive information in kernel memory. [More…]
LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.
security update
LinuxSecurity.com: Several vulnerabilities have been discovered in Squid3, a fully featured web proxy cache. The Common Vulnerabilities and Exposures project identifies the following issues:
LinuxSecurity.com: It was discovered that there where a number of vulnerabilities in irssi, the terminal based IRC client: – CVE-2018-7050: Null pointer dereference for an “empty” nick.
LinuxSecurity.com: An update that solves 8 vulnerabilities and has 19 fixes is now available.
LinuxSecurity.com: The package libmspack before version 1:0.6alpha-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.
