Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Addresses and Names of Customers Exposed by Bethesda in Support Tickets
Linux 4.19.8 Released With BLK-MQ Fix To The Recent Data Corruption Bug

security update

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves 7 vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Australia now has encryption-busting laws as Labor capitulates

security update

LinuxSecurity.com: A vulnerability in EDE could result in privilege escalation.

LinuxSecurity.com: The package jupyter-notebook before version 5.7.2-1 is vulnerable to cross-site scripting.

LinuxSecurity.com: It was discovered that incorrect processing of very high UIDs in Policykit, a framework for managing administrative policies and privileges, could result in authentication bypass.

LinuxSecurity.com: Several security issues were fixed in OpenSSL.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3760

LinuxSecurity.com: Several security issues were fixed in SpamAssassin.

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Satellite 5.6 and Red Hat Satellite 5.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Ukraine: We Blocked Major Russian Attack on Judiciary
#BHEU: How Google Aurora Attacks Changed the Consciousness of Cybersecurity

LinuxSecurity.com: An update for openstack-neutron is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: It was discovered that the ghostscript /invalidaccess checks fail under certain conditions. An attacker could possibly exploit this to bypass the – -dSAFER protection and, for example, execute arbitrary shell commands via a specially crafted PostScript document. (CVE-2018-16509) SL6 x86_64 ghostscript-8.70-24.el6_10.2.i686.rpm ghostscript-8.70-24.el6_10.2.x86_64.rpm ghostscript- [More…]

LinuxSecurity.com: ghostscript: incomplete fix for CVE-2018-16509 (CVE-2018-16863) Bug Fix(es): * Previously, the flushpage operator has been removed as part of a major clean-up of a non-standard operator. However, flushpage has been found to be used in a few specific use cases. With this update, it has been re- added to support those use cases. SL7 […]

Coalition and Labor strike deal on encryption legislation
Facebook Exposes Nonprofits to Donors-and Hackers

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform release 3.5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform release 3.6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Marriott sued hours after announcing data breach

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Some HTML emails can trick messagelib into opening a new browser window when displaying said email as HTML. This happens even if the option to allow the HTML emails to access remote servers is disabled in KMail settings. This means that the owners of the servers referred in the email can see in their […]

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in Perl.

LinuxSecurity.com: Several security issues were fixed in Perl.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may lead to arbitrary code execution.

LinuxSecurity.com: A vulnerability in Nagios allows local users to escalate privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in ConnMan, the worst of which could result in the remote execution of code.

LinuxSecurity.com: Multiple vulnerabilities have been found in PHP, the worst of which could result in a Denial of Service condition.

LinuxSecurity.com: An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: It was discovered that Requests incorrectly handled certain HTTP headers. An attacker could possibly use this issue to access sensitive information (CVE-2018-18074). References:

LinuxSecurity.com: A flaw was found in mod_perl 2.0 through 2.0.10 which allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator’s control of HTTP request processing without also permitting unprivileged users to run

A Dunkin’ Donuts Hack, a Fake FedEx Site, and More Security News This Week
Cyberwar predictions for 2019: The stakes have been raised
Dunkin’ Donuts Serves Up Data Breach Alert
Disorganized crime and state-backed hackers: How the cybercrime and cyberwar landscape is constantly

LinuxSecurity.com: The kdeconnect-kde package has been updated to version 1.3.3, which fixes an issue with modern encryption algorithms being disabled with SSH, and also fixes several bugs and updates compatibility with the Android app.

security update

security update

LinuxSecurity.com: A regression issue has been resolved in the poppler PDF rendering shared library introduced with version 0.26.5-2+deb8u5.

LinuxSecurity.com: Jayakrishna Menon and Christophe Hauser discovered an integer overflow vulnerability in Perl_my_setenv leading to a heap-based buffer overflow with attacker-controlled input.

LinuxSecurity.com: Several vulnerabilities were found in QEMU, a fast processor emulator: CVE-2016-2391

These are the worst hacks, cyberattacks, and data breaches of 2018
Marriott says 500 million Starwood guest records stolen in massive data breach

LinuxSecurity.com: Among others, Andre Heinicke from gpg4win.org found several issues of nsis, a tool for creating quick and user friendly installers for Microsoft Windows operating systems.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service or the execution of arbitrary code if malformed image files are processed.

LinuxSecurity.com: Several local side channel attacks and a denial of service via large Diffie-Hellman parameters were discovered in OpenSSL, a Secure Sockets Layer toolkit.

security update

Dell suffers security breach, reset customer passwords (but didn’t tell customers why until now)
Encryption is the best way to protect payment card transaction data

LinuxSecurity.com: A SQL injection in PostgreSQL may allow attackers to execute arbitrary SQL statements.

LinuxSecurity.com: Multiple vulnerabilities have been found in libsndfile, the worst of which might allow remote attackers to cause a Denial of Service condition. [More…]

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: Multiple security vulnerabilities were found in libarchive, a multi-format archive and compression library. Heap-based buffer over-reads, NULL pointer dereferences and out-of-bounds reads allow remote attackers to cause a denial-of-service (application crash) via

LinuxSecurity.com: An update for ruby is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Multiple vulnerabilities were discovered in the implementation of the Perl programming language. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: Several security vulnerabilities were discovered in Ghostscript, an interpreter for the PostScript language, which could result in denial of service, the creation of files or the execution of arbitrary code if a malformed Postscript file is processed (despite the dSAFER sandbox being

LinuxSecurity.com: The package samba before version 4.9.3-1 is vulnerable to multiple issues including denial of service and access restriction bypass.

LinuxSecurity.com: The package powerdns-recursor before version 4.1.8-1 is vulnerable to denial of service.

Distributing Malware By Becoming an Admin on an Open-Source Project
Pegasus gov’t spyware used to target colleague of slain drug cartel journalist

LinuxSecurity.com: An update for rh-ruby25-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-ruby24-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-ruby23-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Multiple vulnerabilities have been found in OpenSSL, the worst of which may lead to a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in RPM, the worst of which could allow a remote attacker to escalate privileges.

LinuxSecurity.com: The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.1 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file. (CVE-2017-5950)

LinuxSecurity.com: Buffer overflows in URL auth code if there is a “mount” definition that enables URL authentication. A malicious client could send long HTTP headers, leading to a buffer overflow and potential remote code execution (CVE-2018-18820).

security update

security update

Uber fined ?900,000 by UK, Dutch privacy regulators over 2016 data breach
EU Voters Worried About Election Hacking and Disinformation

LinuxSecurity.com: USN-3804-1 introduced a regression in OpenJDK.

LinuxSecurity.com: Several security issues were fixed in Git.

LinuxSecurity.com: Several vulnerabilities were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service or the execution of arbitrary code if a malformed Postscript file is processed (despite the -dSAFER sandbox being enabled).

LinuxSecurity.com: Several security issues were fixed in Samba.