Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: The package python-mysql-connector before version 8.0.15-1 is vulnerable to authentication bypass.

Setting up a Django application on RHEL 8 Beta

security update

security update

security update

security update

Consistent security by crypto policies in Red Hat Enterprise Linux 8
It starts with Linux: How Red Hat is helping to counter Linux container security flaws
Understanding the Red Hat Enterprise Linux random number generator interface
Hardening ELF binaries using Relocation Read-Only (RELRO)
What data privacy means and how to guard it in 2019
Preparing for Identity Management in Red Hat Enterprise Linux 8
Red Hat Global Customer Tech Outlook 2019: Automation, cloud, & security lead funding priorities
The Kubernetes privilege escalation flaw: Innovation still needs IT security expertise
Understanding the critical Kubernetes privilege escalation flaw in OpenShift 3
Security embargoes at Red Hat

security update

security update

security update

The package python2-django before version 1.11.19-1 is vulnerable to denial of service.

The package python-django before version 2.1.6-1 is vulnerable to denial of service.

The package lib32-curl before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package lib32-libcurl-compat before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package lib32-libcurl-gnutls before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package libcurl-gnutls before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package curl before version 7.64.0-1 is vulnerable to arbitrary code execution.

security update

The package aubio before version 0.4.9-1 is vulnerable to denial of service.

The package libu2f-host before version 1.1.7-1 is vulnerable to arbitrary code execution.

The package spice before version 0.14.0-3 is vulnerable to arbitrary code execution.

The package chromium before version 72.0.3626.81-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, content spoofing and insufficient validation.

security update

The package firefox before version 65.0-1 is vulnerable to multiple issues including arbitrary code execution, privilege escalation and access restriction bypass.

The package dovecot before version 2.3.4.1-1 is vulnerable to authentication bypass.

security update

EU Parliament Clears a Path to Give Snowden Asylum
Still fuming over HTTPS mishap, Google makes Symantec an offer it can
Teen Who Hacked CIA Director
Vint Cerf and 260 experts give FCC a plan to secure Wi-Fi routers
Journalist convicted of helping Anonymous hack the LA Times
Security awareness is our shared responsibility
10 cutting-edge security threats
CSOs could see 7% raise next year
Arrest of 14-Year-Old Student for Making a Clock: the Fruits of Sustained Fearmongering and Anti-Mus

security update

security update

security update

security update

security update

security update

security update

security update

LinuxSecurity.com: A remote code execution vulnerability exists in PHP’s built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being

LinuxSecurity.com: Bug fixes for binutils including one that is preventing Yocot/oe-core from building properly

LinuxSecurity.com: New mariadb packages are available for Slackware 14.1 and 14.2 to fix security issues.

LinuxSecurity.com: Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.0.38. Please see the MariaDB 10.0 Release Notes for further details:

LinuxSecurity.com: The 4.20.5 stable kernel update contains a number of important fixes across the tree.

security update

security update

security update

LinuxSecurity.com: Several security issues were fixed in Avahi.

LinuxSecurity.com: The package ghostscript before version 9.26-2 is vulnerable to sandbox escape.

security update

LinuxSecurity.com: New mozilla-firefox packages are available for 14.2 and -current to fix security issues.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Security fix for CVE-2019-6706.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several issues in wireshark, a network traffic analyzer, have been found. Dissectors of – ISAKMP, a Internet Security Association and Key Management Protocol

LinuxSecurity.com: Several issues were discovered in qtbase-opensource-src, a cross-platform C++ application framework, which could lead to denial-of-service via application crash. Additionally, this update fixes a problem affecting vlc, where it would start without a GUI.

LinuxSecurity.com: Multiple vulnerabilities were discovered in coTURN, a TURN and STUN server for VoIP. CVE-2018-4056

security update

security update

LinuxSecurity.com: Tavis Ormandy discovered a vulnerability in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service or the execution of arbitrary code if a malformed Postscript file is processed (despite the -dSAFER sandbox being enabled).

LinuxSecurity.com: The package nasm before version 2.14.02-1 is vulnerable to denial of service.

LinuxSecurity.com: The package haproxy before version 1.9.0-1 is vulnerable to denial of service.

LinuxSecurity.com: The package matrix-synapse before version 0.34.1.1-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package powerdns-recursor before version 4.1.9-1 is vulnerable to multiple issues including insufficient validation and access restriction bypass.

LinuxSecurity.com: The package apache before version 2.4.38-1 is vulnerable to multiple issues including denial of service and insufficient validation.

LinuxSecurity.com: The package go before version 2:1.11.5-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package go before version 2:1.11.5-1 is vulnerable to private key recovery.

LinuxSecurity.com: New version 2.6.6. Security fix for CVE-2019-5716, CVE-2019-5717, CVE-2019-5718, CVE-2019-5719

security update

LinuxSecurity.com: krb5, a MIT Kerberos implementation, had several flaws in LDAP DN checking, which could be used to circumvent a DN containership check by supplying special parameters to some calls.

LinuxSecurity.com: The PostgreSQL project has release a new minor release of the 9.4 branch. For Debian 8 “Jessie”, this has been uploaded as version

LinuxSecurity.com: New Version

LinuxSecurity.com: Ghostscript could be made to crash, access files, or run programs if it opened a specially crafted file.

LinuxSecurity.com: Several security issues were fixed in MySQL.

LinuxSecurity.com: A vulnerability in the HTML_QuickForm package has been found which potentially allows remote code execution. References: – https://bugs.mageia.org/show_bug.cgi?id=24185

LinuxSecurity.com: It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service (CVE-2018-20544). It was discovered that libcaca incorrectly handled certain images. An

LinuxSecurity.com: An issue has been found in PowerDNS Recursor where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua (CVE-2019-3806).