Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

security update

Several security issues were fixed in PHP.

– https://www.drupal.org/project/link/releases/7.x-1.6 – https://www.drupal.org/sa-contrib-2019-020 – https://www.drupal.org/sa- core-2019-003 – https://www.drupal.org/project/link/releases/7.x-1.5 – https://www.drupal.org/project/link/releases/7.x-1.5-beta3

## 1.7.1 – #475: “Loose” lists will now contain paragraphs in all items, not just some. – #433: Links will no longer be double nested – #525: The info- string when beginning a code block may now contain non-word characters (e.g. `c++`) – #561: The `mbstring` extension (which we already depend on) has been added […]

Fixes: CVE-2018-6358, CVE-2018-7867, CVE-2018-7868, CVE-2018-7870, CVE-2018-7871, CVE-2018-7872, CVE-2018-7875, CVE-2018-9165.

– bugfix {foreach} using new style property access like {$item@property} on Smarty 2 style named foreach loop could produce errors https://github.com/smarty-php/smarty/issues/484 31.08.2018 – bugfix some custom left and right delimiters like ‘{^’ ‘^}’ did not work

Bump to ignition-dracut 2c69925 * support platform configs and user configs in /boot ^ https://github.com/coreos/ignition-dracut/pull/43 * Add ability to parse config.ign file on boot ^ https://github.com/coreos/ignition-dracut/pull/42

You’ve Invested in an Email Security Solution… Why your Email may be in Danger, Regardless
Linux and Open Source FAQs: Common Myths and Misconceptions Addressed
New & Improved LinuxSecurity Site Coming Soon!
As Trump and Kim Met, North Korean Hackers Hit Over 100 Targets in U.S. and Ally Nations
Hackers have started attacks on Cisco RV110, RV130, and RV215 routers
Revealed: Facebooks global lobbying against data privacy laws

LinuxSecurity.com: An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for vdsm is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rhvm-appliance is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Vulnerabilities have been discovered in nss, the Mozilla Network Security Service library.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: One of the fixes in USN-3885-1 was incomplete.

LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: This is the six-month notification for the retirement of Red Hat Enterprise Linux 7.4 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.4.

LinuxSecurity.com: The package lib32-openssl-1.0 before version 1.0.2.r-1 is vulnerable to information disclosure.

LinuxSecurity.com: The package file before version 5.36-1 is vulnerable to multiple issues including information disclosure and denial of service.

LinuxSecurity.com: The package pcre before version 8.43-1 is vulnerable to denial of service.

LinuxSecurity.com: The package gdm before version 3.30.3-1 is vulnerable to access restriction bypass.

LinuxSecurity.com: The package openssl-1.0 before version 1.0.2.r-1 is vulnerable to information disclosure.

LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 6.4 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 6.4.

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: The package chromium before version 72.0.3626.121-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: Update to 4.01. Fixes lots of security bugs (and non-security bugs).

LinuxSecurity.com: It was found that a security update (DSA-4387-1) of OpenSSH, an implementation of the SSH protocol suite, was incomplete. This update did not completely fix CVE-2019-6111, an arbitrary file overwrite vulnerability in the scp client implementing the SCP protocol.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: gdm 3.30.3 release. – Screen lock bypass fix (when timed login is enabled) (CVE-2019-3825) – Translation updates

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: Restrict default configuration to localhost.

LinuxSecurity.com: fix for CVE-2018-5704 (RHBZ 1534844)

LinuxSecurity.com: Restrict default configuration to localhost.

LinuxSecurity.com: This release fixes various buffer overflows when parsing or processing damaged Waveform audio and BMP image files.

LinuxSecurity.com: fix for CVE-2018-5704 (RHBZ 1534844)

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

security update

security update

security update

security update

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 5 fixes is now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 33 fixes is now available.

LinuxSecurity.com: A vulnerability was discovered in uw-imap, the University of Washington IMAP Toolkit, that might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a

Latest container exploit (runc) can be blocked by SELinux
A year in review: 2018 Product Security Risk Report

LinuxSecurity.com: Garming Sam reported an out-of-bounds read in the ldb_wildcard_compare() function of ldb, a LDAP-like embedded database, resulting in denial of service.

LinuxSecurity.com: Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform various Cross-Side Scripting (XSS) and PHP injections attacks, delete files, leak potentially sensitive data, create posts of unauthorized types, or

security update

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Several security issues were fixed in GD.

LinuxSecurity.com: ultiple vulnerabilities have been discovered in SoX (Sound eXchange), a sound processing program: CVE-2017-15370

LinuxSecurity.com: An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Several vulnerabilities were found in QEMU, a fast processor emulator: CVE-2018-12617

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update that solves two vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An information leak issue was discovered in phpMyAdmin. An attacker can read any file on the server that the web server’s user can access. This is related to the mysql.allow_local_infile PHP

LinuxSecurity.com: A regression was introduced in the previous chromium security update. The browser would always crash when launched in headless mode. This update fixes this problem.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 7 fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 7 fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: New openssl packages are available for Slackware 14.2 to fix a security issue.

LinuxSecurity.com: Security fix for CVE-2018-16741,CVE-2018-16744,CVE-2018-16745

LinuxSecurity.com: The package logstash before version 6.6.1-1 is vulnerable to information disclosure.

LinuxSecurity.com: The package elasticsearch before version 6.6.1-1 is vulnerable to privilege escalation.

LinuxSecurity.com: An update for polkit is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: GNOME Keyring could be made to expose sensitive information.

LinuxSecurity.com: USN-3866-2 introduced a regression in Ghostscript.

LinuxSecurity.com: LDB could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: ultiple vulnerabilities have been discovered in liblivemedia, the LIVE555 RTSP server library: CVE-2019-6256

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 7 vulnerabilities is now available.

LinuxSecurity.com: The package kibana before version 6.6.1-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: Several security issues were fixed in Bind.

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: A newer version of waagent is needed for several features of the Azure platform. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: The package msmtp before version 1.8.3-1 is vulnerable to certificate verification bypass.