Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Several security issues were fixed in Git.

LinuxSecurity.com: Several vulnerabilities were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service or the execution of arbitrary code if a malformed Postscript file is processed (despite the -dSAFER sandbox being enabled).

LinuxSecurity.com: Several security issues were fixed in Samba.

LinuxSecurity.com: USN-3816-1 caused a regression in systemd-tmpfiles.

LinuxSecurity.com: Several security issues were fixed in WebKitGTK+.

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: An update for rh-nginx114-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-nginx112-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-dotnet21-dotnet is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: A vulnerability in spice-gtk could allow an attacker to remotely execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Libav, the worst of which may allow a Denial of Service condition.

LinuxSecurity.com: A vulnerability in Tablib might allow remote attackers to execute arbitrary python commands.

LinuxSecurity.com: Multiple vulnerabilities have been found in Binutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for sos-collector is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for NetworkManager is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-mysql57-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-nginx110-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-nginx18-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The frustratingly simple techniques of ‘human hacking’ – and how to fight them
LinkedIn violated data protection by using 18M email addresses of non-members to buy targeted ads on

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: gnuplot5, a command-line driven interactive plotting program, has been examined with fuzzing by Tim Blazytko, Cornelius Aschermann, Sergej Schumilo and Nils Bars.

security update

DoS Vulnerabilities Found in Linux Kernel, Unpatched
Security News This Week: Amazon Won’t Say How Many Customer Emails It

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: A vulnerability in xml-security-c, a library for the XML Digital Security specification, has been found. Different KeyInfo combinations, like signatures without public key, result in incomplete DSA structures that

LinuxSecurity.com: Multiple vulnerabilities have been found in Exiv2, the worst of which could result in a Denial of Service condition.

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Thunderbird, the worst of which could lead to the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in GPL Ghostscript, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Asterisk, the worst of which could result in a Denial of Service condition.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
Mirai Evolves From IoT Devices to Linux Servers

LinuxSecurity.com: USN-3801-1 caused some minor regressions in Firefox.

LinuxSecurity.com: Two security vulnerabilities were discovered in OTRS, a Ticket Request System, that may lead to privilege escalation or arbitrary file write. CVE-2018-19141

LinuxSecurity.com: It was discovered that a buffer overflow in liveMedia, a set of C++ libraries for multimedia streaming could result in the execution of arbitrary code when parsing a malformed RTSP stream.

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: CVE-2015-5297 Numerical overflow in pointer arithmetic.

LinuxSecurity.com: mod_perl could be made to run programs contrary to expectations.

LinuxSecurity.com: The package flashplugin before version 31.0.0.153-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package webkit2gtk before version 2.22.4-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-libtiff before version 4.0.10-1 is vulnerable to multiple issues including arbitrary code execution, denial of service and information disclosure.

LinuxSecurity.com: It was discovered that there were two vulnerabilities libphp-phpmailer, an email library for the PHP programming language: * CVE-2017-5223: Local file disclosure vulnerability via relative path

LinuxSecurity.com: The ghostscript 9.26 update is focusing on security issues, including solving several (well publicised) real and potential exploits. For other fixes in this release, see the referenced News.

LinuxSecurity.com: In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. (CVE-2018-16646) An issue was discovered in Poppler 0.71.0. There is a reachable abort in

LinuxSecurity.com: A critical vulnerability in Adobe Flash Player 31.0.0.148 and earlier versions. Successful exploitation could lead to arbitrary code execution in the context of the current user. (CVE-2018-15981) References:

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, incomplete TLS identity verification, information disclosure or the execution of arbitrary code.

LinuxSecurity.com: mod_perl could be made to run programs contrary to expectations.

LinuxSecurity.com: Several security vulnerabilities were discovered in the JasPer JPEG-2000 library. CVE-2015-5203

LinuxSecurity.com: It was discovered that there was an XSS vulnerability in the ruby-rack web-server library. A malicious request could impact the HTTP/HTTPS scheme being returned

Facebook appeals ?500,000 penalty over Cambridge Analytica scandal
USPS finally fixes website flaw that exposed 60 million users’ data
Dutton leans on encryption laws committee to hurry up
Real Identity of Hacker Who Sold LinkedIn, Dropbox Databases Revealed

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: CVE-2018-0735 Samuel Weiser reported a timing vulnerability in the OpenSSL ECDSA signature generation, which might leak information to recover the

LinuxSecurity.com: The update for ceph issued as DSA-4339-1 caused a build regression for the i386 builds. Updated packages are now available to address this issue. For reference, the original advisory text follows.

LinuxSecurity.com: This is a service release to update the stable version 1.3 of Roundcube Webmail. It contains fixes to several bugs backported from the master branch including a security fix for a reported XSS vulnerability (in handling invalid style tag content) plus updates to ensure compatibility with PHP 7.3 and recent versions of Courier-IMAP, Dovecot […]

LinuxSecurity.com: An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt. (CVE-2018-18751)

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3409

LinuxSecurity.com: Red Hat OpenShift Container Platform release 3.7.72 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: It was discovered that there was a remote denial-of-service vulnerability in ruby-i18n, a I18n and localization solution for Ruby. An application crash could be engineering a situation where `:some_key` is

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 18 vulnerabilities is now available.

LinuxSecurity.com: A stack based buffer overflow vulnerability was found in liblivemedia, the LIVE555 RTSP server library. This issue might be leveraged by remote attackers to cause code execution, by sending a crafted packet.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.

security update

LinuxSecurity.com: The package grafana before version 5.3.4-1 is vulnerable to arbitrary filesystem access.

LinuxSecurity.com: Assertion failure in BPMDetect class in BPMDetect.cpp (CVE-2018-17096). Out-of-bounds heap write in WavOutFile::write() (CVE-2018-17097). Heap corruption in WavFileBase class in WavFile.cpp (CVE-2018-17098). References:

LinuxSecurity.com: mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user’s credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two characters value to allow a quick retry (for example,

LinuxSecurity.com: It was discovered that mishandled search requests in servers/slapd/search.c:do_search() in 389-ds-base allows for denial of service (CVE-2018-14648). References:

Texas hospital becomes victim of Dharma ransomware
Russian hacker arrested in Bulgaria for ad fraud of over $7 million
Security warning: UK critical infrastructure still at risk from devastating cyber attack

LinuxSecurity.com: Multiple vulnerabilities have been discovered in uriparser, an Uniform Resource Identifiers (URIs) parsing library.

LinuxSecurity.com: The package chromium before version 70.0.3538.110-1 is vulnerable to information disclosure.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec. CVE-2017-17480

LinuxSecurity.com: Red Hat OpenShift Container Platform release 3.9.51 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: systemd was found to suffer from multiple security vulnerabilities ranging from denial of service attacks to possible root privilege escalation.

LinuxSecurity.com: systemd-tmpfiles could be made to change ownership of arbitrary files.

LinuxSecurity.com: Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.1.37. Please see the MariaDB 10.1 Release Notes for further details:

Using Airport and Hotel Wi-Fi Is Much Safer Than It Used to Be

LinuxSecurity.com: An update that fixes one vulnerability is now available.